You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Kubernetes集群中配置作为Agent的Filebeat

Kubernetes 集群中Filebeat作为集群Agent的配置说明

一、先搞懂“Filebeat集群Agent”到底是什么

在K8s环境里,所谓“集群Agent模式”的Filebeat,本质是用DaemonSet部署:

  • K8s的每个节点上都会跑一个Filebeat Pod
  • 这个Pod负责采集该节点上所有业务容器的日志(默认读/var/log/containers下的日志文件)
  • 不需要给每个业务Pod单独塞Filebeat,属于集群统一的日志采集方案,资源利用率更高

二、集群Agent模式的配置步骤(重点:不用改你的项目Pod)

这种模式下,你不需要把filebeat.yml加到自己的项目里,而是要单独部署集群级的Filebeat实例,步骤如下:

  1. 把filebeat.yml转成K8s ConfigMap
    把你写好的配置存入ConfigMap,方便后续修改和挂载:
    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: filebeat-config
      namespace: logging # 建议单独建个日志用的命名空间
    data:
      filebeat.yml: |-
        # 你的配置示例,按需调整
        filebeat.inputs:
          - type: container
            paths:
              - /var/log/containers/*.log
            # 可加标签过滤,只采集你的项目日志
            processors:
              - add_kubernetes_metadata:
                  in_cluster: true
                  namespace: "your-project-namespace" # 替换成你的项目命名空间
        output.logstash:
          hosts: ["logstash-service.logging.svc.cluster.local:5044"] # Logstash的集群内部地址
    
  2. 部署Filebeat DaemonSet
    编写DaemonSet的YAML,挂载ConfigMap和节点上的日志目录:
    apiVersion: apps/v1
    kind: DaemonSet
    metadata:
      name: filebeat
      namespace: logging
      labels:
        app: filebeat
    spec:
      selector:
        matchLabels:
          app: filebeat
      template:
        metadata:
          labels:
            app: filebeat
        spec:
          serviceAccountName: filebeat # 需先创建权限足够的ServiceAccount
          terminationGracePeriodSeconds: 30
          containers:
          - name: filebeat
            image: docker.elastic.co/beats/filebeat:8.10.0 # 版本要和你的ELK栈匹配
            args: [
              "-c", "/etc/filebeat/filebeat.yml",
              "-e", # 输出日志到控制台,方便调试
            ]
            securityContext:
              runAsUser: 0 # 需要root权限读取节点上的日志文件
            volumeMounts:
              - name: config
                mountPath: /etc/filebeat/filebeat.yml
                subPath: filebeat.yml
              - name: varlogcontainers
                mountPath: /var/log/containers
              - name: varlogpods
                mountPath: /var/log/pods
              - name: varlibdockercontainers
                mountPath: /var/lib/docker/containers
          volumes:
            - name: config
              configMap:
                name: filebeat-config
            - name: varlogcontainers
              hostPath:
                path: /var/log/containers
            - name: varlogpods
              hostPath:
                path: /var/log/pods
            - name: varlibdockercontainers
              hostPath:
                path: /var/lib/docker/containers
    
  3. 配置K8s权限
    给Filebeat创建ServiceAccount和对应的RBAC权限,让它能读取K8s的Pod、节点元数据(给日志打标签用):
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: filebeat
      namespace: logging
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRole
    metadata:
      name: filebeat
    rules:
    - apiGroups: [""]
      resources: ["namespaces", "pods", "nodes"]
      verbs: ["get", "list", "watch"]
    ---
    apiVersion: rbac.authorization.k8s.io/v1
    kind: ClusterRoleBinding
    metadata:
      name: filebeat
    subjects:
    - kind: ServiceAccount
      name: filebeat
      namespace: logging
    roleRef:
      kind: ClusterRole
      name: filebeat
      apiGroup: rbac.authorization.k8s.io
    
  4. 部署验证
    依次执行kubectl apply -f以上三个YAML文件,然后用kubectl get pods -n logging -o wide查看每个节点是否都有Filebeat Pod在运行,再用kubectl logs -n logging <filebeat-pod-name>检查日志是否正常发送到Logstash。

三、如果是给单个项目加Filebeat(Sidecar模式)

要是你想给自己的项目Pod单独配置Filebeat(非集群级Agent),才需要修改项目的Deployment:

  • 在Deployment的containers中添加一个Filebeat容器
  • 挂载业务容器的日志目录到Filebeat容器,同时挂载filebeat.yml(用ConfigMap或本地文件均可)
  • 这种模式每个业务Pod都带一个Filebeat,适合需要单独定制采集规则的场景,但资源消耗比集群Agent模式高

总结

  • 公司说的“集群Agent”是DaemonSet模式,不用把filebeat.yml加到你的项目Pod里,要单独部署集群级的Filebeat实例
  • 若只是给单个项目加Filebeat,那是Sidecar模式,需要修改项目的Deployment配置,加入Filebeat容器和对应的配置挂载

内容的提问来源于stack exchange,提问作者fbm fatma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 21:30:47