如何正确配置Fluentd默认端口的容器健康检查?
问题原因
原有配置失效是三个核心问题导致的:
- Fluentd默认在24224端口监听的是
forward协议输入插件,不响应HTTP请求,直接用curl请求该端口的HTTP地址必然返回失败 - 配置中depends_on的健康状态条件写错,
container_healthy不是合法值,不会触发等待逻辑 - 报错
Error response from daemon: failed to initialize logging driver: dial tcp [::1]:24224: connect: connection refused本质是Fluentd未完成启动、24224端口未开始监听时,Docker daemon就尝试初始化下游容器的Fluentd日志驱动,连接被拒绝。
可行配置方案
方案1:按需求使用curl做HTTP健康检查
需要先给Fluentd配置独立的HTTP监听端口用于健康检查,不要占用24224的forward协议端口:
- 在Fluentd主配置文件(通常为
fluent.conf)中添加HTTP输入源配置:
<source> @type http port 9880 bind 0.0.0.0 <parse> @type none </parse> </source>
- 修改docker-compose配置,注意选择自带curl的Fluentd镜像(debian版本默认带curl,alpine版本需要自行安装curl),修正健康检查和依赖条件:
version: "3.3" services: fluentd: image: fluent/fluentd:v1.16-debian-1 ports: - "24224:24224" - "24224:24224/udp" - "9880:9880" volumes: - ./fluent.conf:/fluentd/etc/fluent.conf healthcheck: test: ["CMD-SHELL", "curl --fail -s http://localhost:9880/ || exit 1"] interval: 10s timeout: 5s retries: 3 start_period: 15s sample: depends_on: fluentd: condition: service_healthy logging: driver: fluentd options: fluentd-address: tcp://fluentd:24224
方案2:无额外配置的TCP端口检测(更轻量)
如果不需要强制用curl,可以直接通过bash内置的TCP能力检测24224端口是否处于监听状态,不需要修改Fluentd配置、不需要额外安装curl,适合精简镜像场景,健康检查配置替换为如下内容即可:
healthcheck: test: ["CMD-SHELL", "echo > /dev/tcp/localhost/24224 || exit 1"] interval: 10s timeout: 5s retries: 3 start_period: 15s
注意事项
- 不要直接对24224端口发HTTP请求,该端口默认走Fluentd私有forward协议,无法响应HTTP请求
- 依赖条件必须写
service_healthy,旧的container_healthy写法不会触发健康状态等待逻辑 - 如果使用alpine版本的Fluentd镜像,默认不带bash和curl,需要在自定义Dockerfile中安装对应依赖后才能使用上述健康检查命令
内容的提问来源于stack exchange,提问作者Fallenreaper
相关产品推荐
相关产品推荐

