You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Fluentd从Azure Vault读取MongoDB凭证并注入配置文件?

从Azure Vault提取凭证注入Fluentd配置的方案

方案1:利用Fluentd原生环境变量插值

Fluentd支持在配置文件中直接引用环境变量,无需额外插件,步骤如下:

  1. 从Azure Vault拉取凭证并导出为环境变量(需提前完成Azure认证,生产环境建议用托管身份):
    export MONGO_HOST=$(az keyvault secret show --name mongo-host --vault-name 你的密钥库名称 --query value -o tsv)
    export MONGO_PORT=$(az keyvault secret show --name mongo-port --vault-name 你的密钥库名称 --query value -o tsv)
    export MONGO_DB=$(az keyvault secret show --name mongo-db --vault-name 你的密钥库名称 --query value -o tsv)
    export MONGO_COLLECTION=$(az keyvault secret show --name mongo-collection --vault-name 你的密钥库名称 --query value -o tsv)
    export MONGO_AUTH_DB=$(az keyvault secret show --name mongo-auth-db --vault-name 你的密钥库名称 --query value -o tsv)
    export MONGO_USER=$(az keyvault secret show --name mongo-user --vault-name 你的密钥库名称 --query value -o tsv)
    export MONGO_PASSWORD=$(az keyvault secret show --name mongo-password --vault-name 你的密钥库名称 --query value -o tsv)
    
  2. 修改fluent.conf,用环境变量替换占位符:
    <source>
      @type forward
      port 24224
      bind 0.0.0.0
    </source>
    
    <match mongo.**>
      @type copy
      <store>
        @type mongo
        host "#{ENV['MONGO_HOST']}"
        port "#{ENV['MONGO_PORT']}"
        database "#{ENV['MONGO_DB']}"
        collection "#{ENV['MONGO_COLLECTION']}"
        auth_source "#{ENV['MONGO_AUTH_DB']}"
    
        # authentication
        user "#{ENV['MONGO_USER']}"
        password "#{ENV['MONGO_PASSWORD']}"
    
        <inject>
        # key name of timestamp
          time_key time
        </inject>
    
        <buffer>
        # flush
        flush_interval 10s
        </buffer>
      </store>
    
    </match>
    
  3. 把环境变量导出命令和Fluentd启动命令写在同一个脚本中执行,确保变量生效:
    #!/bin/bash
    # 导出凭证到环境变量
    export MONGO_HOST=$(az keyvault secret show --name mongo-host --vault-name 你的密钥库名称 --query value -o tsv)
    # 其他变量导出命令...
    # 启动Fluentd
    fluentd -c /path/to/fluent.conf
    

方案2:预先生成填充好凭证的配置文件

如果不想依赖环境变量,可以在Fluentd启动前用脚本完成凭证替换:

  1. 创建fluent.conf.template模板文件,保留原占位符:
    <source>
      @type forward
      port 24224
      bind 0.0.0.0
    </source>
    
    <match mongo.**>
      @type copy
      <store>
        @type mongo
        host [host]
        port [port]
        database [db]
        collection [collection]
        auth_source [auth db]
    
        # authentication
        user [user]
        password [password]
    
        <inject>
        # key name of timestamp
          time_key time
        </inject>
    
        <buffer>
        # flush
        flush_interval 10s
        </buffer>
      </store>
    
    </match>
    
  2. 编写初始化脚本init_fluentd.sh:
    #!/bin/bash
    VAULT_NAME="你的密钥库名称"
    
    # 从Vault拉取凭证
    MONGO_HOST=$(az keyvault secret show --name mongo-host --vault-name $VAULT_NAME --query value -o tsv)
    MONGO_PORT=$(az keyvault secret show --name mongo-port --vault-name $VAULT_NAME --query value -o tsv)
    MONGO_DB=$(az keyvault secret show --name mongo-db --vault-name $VAULT_NAME --query value -o tsv)
    MONGO_COLLECTION=$(az keyvault secret show --name mongo-collection --vault-name $VAULT_NAME --query value -o tsv)
    MONGO_AUTH_DB=$(az keyvault secret show --name mongo-auth-db --vault-name $VAULT_NAME --query value -o tsv)
    MONGO_USER=$(az keyvault secret show --name mongo-user --vault-name $VAULT_NAME --query value -o tsv)
    MONGO_PASSWORD=$(az keyvault secret show --name mongo-password --vault-name $VAULT_NAME --query value -o tsv)
    
    # 替换模板生成最终配置
    sed -e "s/\[host\]/$MONGO_HOST/g" \
        -e "s/\[port\]/$MONGO_PORT/g" \
        -e "s/\[db\]/$MONGO_DB/g" \
        -e "s/\[collection\]/$MONGO_COLLECTION/g" \
        -e "s/\[auth db\]/$MONGO_AUTH_DB/g" \
        -e "s/\[user\]/$MONGO_USER/g" \
        -e "s/\[password\]/$MONGO_PASSWORD/g" \
        /path/to/fluent.conf.template > /path/to/fluent.conf
    
    # 启动Fluentd
    fluentd -c /path/to/fluent.conf
    
  3. 执行该脚本启动Fluentd即可。

方案3:使用Fluentd Azure Vault插件(进阶)

使用第三方插件直接在配置中读取Vault凭证,需注意插件维护状态:

  1. 安装插件:
    gem install fluent-plugin-azure-keyvault
    
  2. 修改fluent.conf直接读取Vault:
    <source>
      @type forward
      port 24224
      bind 0.0.0.0
    </source>
    
    <match mongo.**>
      @type copy
      <store>
        @type mongo
        host "#{AzureKeyVault.get('你的密钥库名称', 'mongo-host')}"
        port "#{AzureKeyVault.get('你的密钥库名称', 'mongo-port')}"
        database "#{AzureKeyVault.get('你的密钥库名称', 'mongo-db')}"
        collection "#{AzureKeyVault.get('你的密钥库名称', 'mongo-collection')}"
        auth_source "#{AzureKeyVault.get('你的密钥库名称', 'mongo-auth-db')}"
    
        # authentication
        user "#{AzureKeyVault.get('你的密钥库名称', 'mongo-user')}"
        password "#{AzureKeyVault.get('你的密钥库名称', 'mongo-password')}"
    
        <inject>
        # key name of timestamp
          time_key time
        </inject>
    
        <buffer>
        # flush
        flush_interval 10s
        </buffer>
      </store>
    
    </match>
    
    需确保Fluentd进程拥有访问Azure Vault的权限,Azure环境中推荐使用托管身份。

注意事项

  • 生产环境优先使用Azure托管身份访问Vault,避免硬编码认证凭证。
  • 容器化场景(Docker/K8s)可结合Azure AD Pod Identity或Secrets Store CSI Driver,将Vault凭证直接挂载为环境变量或文件后再使用上述方案。

内容的提问来源于stack exchange,提问作者slifer2015

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 05:04:56