无需SSH:Elastic Beanstalk上AWS Kinesis Agent的安装配置问询
Awesome question! You can absolutely set up the AWS Kinesis Agent on Elastic Beanstalk without ever SSHing into your instances—Elastic Beanstalk's .ebextensions configuration files are perfect for this. Let's walk through exactly how to do it:
First, make a new folder named .ebextensions at the root of your application source code (don't forget the leading dot—it's a hidden directory). This is where Elastic Beanstalk looks for custom configuration scripts.
Inside the .ebextensions folder, create a file called kinesis-agent-setup.config (the name doesn't matter as long as it ends with .config). Paste the following content into it, and adjust the values to match your setup:
# Install the AWS Kinesis Agent via YUM packages: yum: aws-kinesis-agent: [] # Deploy the agent's configuration file files: "/etc/aws-kinesis/agent.json": mode: "000644" owner: root group: root content: | { "cloudwatch.emitMetrics": true, "flows": [ { "filePattern": "/var/log/httpd/access_log", "deliveryStream": "YOUR-KINESIS-STREAM-NAME", "dataProcessingOptions": [ { "optionName": "LOGTOJSON", "logFormat": "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" } ] } ] } # Ensure the Kinesis Agent service runs automatically services: sysvinit: aws-kinesis-agent: enabled: true ensureRunning: true files: - "/etc/aws-kinesis/agent.json"
Key Adjustments You Need to Make:
- Replace
YOUR-KINESIS-STREAM-NAMEwith the actual name of your Kinesis Data Stream. - Update
filePatternto point to the log file or directory you want the agent to monitor (e.g.,/var/log/nginx/access.logfor Nginx, or a custom application log path). - Modify the
logFormatto match the format of your log files—this ensures the agent parses logs correctly into JSON.
Package your application source code (including the .ebextensions directory) into a ZIP file, then deploy it to your Elastic Beanstalk environment.
When Elastic Beanstalk spins up (or updates) your instances, it will automatically:
- Install the AWS Kinesis Agent via YUM.
- Copy your custom
agent.jsonconfiguration file to the correct location. - Start the Kinesis Agent service and set it to run on boot.
- IAM Permissions: Make sure your Elastic Beanstalk instance's IAM role has permissions to write to your Kinesis Data Stream. At minimum, it needs
kinesis:PutRecordandkinesis:PutRecordspermissions. You can attach the managed policyAmazonKinesisFullAccess(for quick testing) or create a custom policy with least-privilege access. - Amazon Linux 2 vs. Amazon Linux AMI: If you're using the older Amazon Linux AMI (not Amazon Linux 2), adjust the
servicessection to usesystemdinstead ofsysvinit:services: systemd: aws-kinesis-agent: enabled: true ensureRunning: true files: - "/etc/aws-kinesis/agent.json" - Multiple Log Flows: You can add more entries to the
flowsarray inagent.jsonto monitor multiple log files or send data to different Kinesis streams.
内容的提问来源于stack exchange,提问作者AJ222

