Support Fluentbit to CloudWatch logs (#140)

* Import and customize fluenbit add-on

* Enable fluent bit logs

* Bump helm addon version

* Dropping account id as it seems to create scraping errors

* Create separate log groups per namespace

* Apply pre-commit

* Remove conflicting global label

* Add config object for logs

* Enable logs in examples

* Add logs docs

* Fix broken link

* Add screenshots

* Update docs

* Typos
This commit is contained in:
Rodrigue Koffi
2023-03-30 15:48:40 +02:00
committed by GitHub
parent c358008f92
commit 4019db6cd7
20 changed files with 386 additions and 36 deletions
+40 -21
View File
@@ -4,13 +4,14 @@
Welcome to the AWS Observability Accelerator for Terraform! Welcome to the AWS Observability Accelerator for Terraform!
The AWS Observability Accelerator for Terraform is a set of opinionated modules to The AWS Observability Accelerator for Terraform is a set of opinionated modules
help you set up observability for your AWS environments with to help you set up observability for your AWS environments with
AWS-managed observability services such as Amazon Managed Service for Prometheus, AWS-managed observability services such as Amazon Managed Service for Prometheus,
Amazon Managed Grafana and AWS Distro for OpenTelemetry (ADOT). Amazon Managed Grafana, AWS Distro for OpenTelemetry (ADOT) and Amazon CloudWatch.
We provide curated metrics, traces collection, alerting rules and Grafana dashboards We provide curated metrics, logs, traces collection, alerting rules and Grafana
for your EKS infrastructure, Java/JMX, NGINX based workloads and custom applications. dashboards for your EKS infrastructure, Java/JMX, NGINX based workloads and
your custom applications.
You also can monitor your Amazon Managed Service for Prometheus workspaces ingestion, You also can monitor your Amazon Managed Service for Prometheus workspaces ingestion,
costs, active series with [this module](./modules/managed-prometheus-monitoring). costs, active series with [this module](./modules/managed-prometheus-monitoring).
@@ -42,18 +43,20 @@ v2+ releases introduces couple of breaking changes compared to previous versions
### Base Module ### Base Module
The base module allows you to configure the AWS Observability services for your cluster and The base module allows you to configure the AWS Observability services for your
the AWS Distro for OpenTelemetry (ADOT) Operator as the signals collection mechanism. cluster and the AWS Distro for OpenTelemetry (ADOT) Operator as the signals
collection mechanism.
This is the minimum configuration to have a new Amazon Managed Service for Prometheus Workspace This is the minimum configuration to have a new Amazon Managed Service for
and ADOT Operator deployed for you and ready to receive your data. Prometheus Workspace and ADOT Operator deployed for you and ready to receive
The base module serve as an anchor to the workload modules and cannot run on its own. your data. The base module serve as an anchor to the workload modules and
cannot run on its own.
```hcl ```hcl
module "aws_observability_accelerator" { module "aws_observability_accelerator" {
# use release tags and check for the latest versions # use release tags and check for the latest versions
# https://github.com/aws-observability/terraform-aws-observability-accelerator/releases # https://github.com/aws-observability/terraform-aws-observability-accelerator/releases
source = "github.com/aws-observability/terraform-aws-observability-accelerator?ref=v1.6.1" source = "github.com/aws-observability/terraform-aws-observability-accelerator?ref=v2.1.0"
aws_region = "eu-west-1" aws_region = "eu-west-1"
eks_cluster_id = "my-eks-cluster" eks_cluster_id = "my-eks-cluster"
@@ -70,7 +73,7 @@ You can optionally reuse an existing Amazon Managed Servce for Prometheus Worksp
module "aws_observability_accelerator" { module "aws_observability_accelerator" {
# use release tags and check for the latest versions # use release tags and check for the latest versions
# https://github.com/aws-observability/terraform-aws-observability-accelerator/releases # https://github.com/aws-observability/terraform-aws-observability-accelerator/releases
source = "github.com/aws-observability/terraform-aws-observability-accelerator?ref=v1.6.1" source = "github.com/aws-observability/terraform-aws-observability-accelerator?ref=v2.1.0"
aws_region = "eu-west-1" aws_region = "eu-west-1"
eks_cluster_id = "my-eks-cluster" eks_cluster_id = "my-eks-cluster"
@@ -91,13 +94,13 @@ View all the configuration options in the module documentation below.
### Workload modules ### Workload modules
[Workloads modules](./modules) are provided, which essentially provide curated [Workloads modules](./modules) are provided, which essentially provide curated
metrics collection, alerting rules and Grafana dashboards. metrics, logs, traces collection, alerting rules and Grafana dashboards.
#### Infrastructure monitoring #### Amazon EKS monitoring
```hcl ```hcl
module "workloads_infra" { module "eks_monitoring" {
source = "aws-observability/terraform-aws-observability-accelerator/workloads/infra" source = "github.com/aws-observability/terraform-aws-observability-accelerator//modules/eks-monitoring?ref=v2.1.0"
eks_cluster_id = module.eks_observability_accelerator.eks_cluster_id eks_cluster_id = module.eks_observability_accelerator.eks_cluster_id
@@ -106,6 +109,9 @@ module "workloads_infra" {
managed_prometheus_workspace_endpoint = module.eks_observability_accelerator.managed_prometheus_workspace_endpoint managed_prometheus_workspace_endpoint = module.eks_observability_accelerator.managed_prometheus_workspace_endpoint
managed_prometheus_workspace_region = module.eks_observability_accelerator.managed_prometheus_workspace_region managed_prometheus_workspace_region = module.eks_observability_accelerator.managed_prometheus_workspace_region
enable_logs = true
enable_tracing = true
} }
``` ```
@@ -118,17 +124,30 @@ Check the the [complete example](./examples/existing-cluster-with-base-and-infra
## Motivation ## Motivation
Kubernetes is a powerful and extensible container orchestration technology that allows you to deploy and manage containerized applications at scale. The extensible nature of Kubernetes also allows you to use a wide range of popular open-source tools, commonly referred to as add-ons, in Kubernetes clusters. With such a large number of tools and design choices available, building a tailored EKS cluster that meets your application’s specific needs can take a significant amount of time. It involves integrating a wide range of open-source tools and AWS services and requires deep expertise in AWS and Kubernetes. To gain deep visibility into your workloads and environments, AWS proposes a
set of secure, scalable, highly available, production-grade managed open
source services such as Amazon Managed Service for Prometheus, Amazon Managed
Grafana and Amazon OpenSearch.
AWS customers have asked for best-practices and guidance to collect metrics, logs
and traces from their containerized applications and microservices with ease of
deployment. Customers can use the AWS Observability Accelerator to configure their
metrics and traces collection, leveraging [AWS Distro for OpenTelemetry](https://aws-otel.github.io/),
to have opinionated dashboards and alerts available in only minutes.
AWS customers have asked for examples that demonstrate how to integrate the landscape of Kubernetes tools and make it easy for them to provision complete, opinionated EKS clusters that meet specific application requirements. Customers can use AWS Observability Accelerator to configure and deploy purpose built EKS clusters, and start onboarding workloads in days, rather than months.
## Support & Feedback ## Support & Feedback
AWS Observability Accelerator for Terraform is maintained by AWS Solution Architects. It is not part of an AWS service and support is provided best-effort by the AWS Observability Accelerator community. AWS Observability Accelerator for Terraform is maintained by AWS Solution
Architects. It is not part of an AWS service and support is provided best-effort
by the AWS Observability Accelerator community.
To post feedback, submit feature ideas, or report bugs, please use the [Issues](https://github.com/aws-observability/terraform-aws-observability-accelerator/issues) section of this GitHub repo. To post feedback, submit feature ideas, or report bugs, please use the
[Issues](https://github.com/aws-observability/terraform-aws-observability-accelerator/issues)
section of this GitHub repo.
If you are interested in contributing, see the [Contribution guide](https://github.com/aws-observability/terraform-aws-observability-accelerator/blob/main/CONTRIBUTING.md). If you are interested in contributing, see the
[Contribution guide](https://github.com/aws-observability/terraform-aws-observability-accelerator/blob/main/CONTRIBUTING.md).
--- ---
+3 -1
View File
@@ -123,4 +123,6 @@ classDiagram
## Getting started with AWS Observability services ## Getting started with AWS Observability services
If you are new to AWS Observability services, or want to dive deeper into them, check our [One Observability Workshop](https://catalog.workshops.aws/observability/) for a hands-on experience in a self-paced environement or at an AWS venue. If you are new to AWS Observability services, or want to dive deeper into them,
check our [One Observability Workshop](https://catalog.workshops.aws/observability/)
for a hands-on experience in a self-paced environement or at an AWS venue.
+67
View File
@@ -0,0 +1,67 @@
# Viewing Logs
By default, we deploy a FluentBit daemon set in the cluster to collect worker
logs for all namespaces. Logs collection can be disabled with
`enable_logs = false`. Logs are collected and exported to Amazon CloudWatch Logs,
which enables you to centralize the logs from all of your systems, applications,
and AWS services that you use, in a single, highly scalable service.
Further configuration options are available in the [module documentation](https://github.com/aws-observability/terraform-aws-observability-accelerator/tree/main/modules/eks-monitoring#inputs).
This guide shows how you can leverage CloudWatch Logs in Amazon Managed Grafana
for your cluster and application logs.
## Using CloudWatch Logs as data source in Grafana
Follow [the documentation](https://docs.aws.amazon.com/grafana/latest/userguide/using-amazon-cloudwatch-in-AMG.html)
to enable Amazon CloudWatch as a data source. Make sure to provide permissions.
!!! tip
If you created your workspace with our [provided example](https://aws-observability.github.io/terraform-aws-observability-accelerator/helpers/managed-grafana/),
Amazon CloudWatch data source has already been setup for you.
All logs are delivered in the following CloudWatch Log groups naming pattern:
`/aws/eks/observability-accelerator/{cluster-name}/{namespace}`. Log streams
follow `{container-name}.{pod-name}`. In Grafana, querying and analyzing logs
is done with [CloudWatch Logs Insights](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AnalyzingLogData.html)
### Example - ADOT collector logs
Select one or many log groups and run the following query. The example below,
queries AWS Distro for OpenTelemetry (ADOT) logs
```console
fields @timestamp, log
| order @timestamp desc
| limit 100
```
<img width="1987" alt="Screenshot 2023-03-27 at 19 08 35" src="https://user-images.githubusercontent.com/10175027/228037030-95005f47-ff46-4f7a-af74-d31809c52fcd.png">
### Example - Using time series visualizations
[CloudWatch Logs syntax](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CWL_QuerySyntax.html)
provide powerful functions to extract data from your logs. The `stats()`
function allows you to calculate aggregate statistics with log field values.
This is useful to have visualization on non-metric data from your applications.
In the example below, we use the following query to graph the number of metrics
collected by the ADOT collector
```console
fields @timestamp, log
| parse log /"#metrics": (?<metrics_count>\d+)}/
| stats avg(metrics_count) by bin(5m)
| limit 100
```
!!! tip
You can add logs in your dashboards with logs panel types or time series
depending on your query results type.
<img width="2056" alt="image" src="https://user-images.githubusercontent.com/10175027/228037186-12691590-0bfe-465b-a83b-5c4f583ebf96.png">
!!! warning
Querying CloudWatch logs will incur costs per GB scanned. Use small time
windows and limits in your queries. Checkout the CloudWatch
[pricing page](https://aws.amazon.com/cloudwatch/pricing/) for more infos.
+13 -9
View File
@@ -5,32 +5,36 @@ Welcome to the AWS Observability Accelerator for Terraform!
The AWS Observability Accelerator for Terraform is a set of opinionated modules to The AWS Observability Accelerator for Terraform is a set of opinionated modules to
help you set up observability for your AWS environments with help you set up observability for your AWS environments with
AWS-managed observability services such as Amazon Managed Service for Prometheus, AWS-managed observability services such as Amazon Managed Service for Prometheus,
Amazon Managed Grafana and AWS Distro for OpenTelemetry (ADOT). Amazon Managed Grafana, AWS Distro for OpenTelemetry (ADOT) and Amazon CloudWatch.
We provide curated metrics, traces collection, alerting rules and Grafana dashboards We provide curated metrics, logs, traces collection, alerting rules and Grafana
for your EKS infrastructure, Java/JMX, NGINX based workloads and custom applications. dashboards for your EKS infrastructure, Java/JMX, NGINX based workloads and
your custom applications.
You also can monitor your Amazon Managed Service for Prometheus workspaces ingestion,
costs, active series with [this module](https://aws-observability.github.io/terraform-aws-observability-accelerator/workloads/managed-prometheus/).
<img width="1501" alt="image" src="images/dark-o11y-accelerator-amp-xray.png"> <img width="1501" alt="image" src="images/dark-o11y-accelerator-amp-xray.png">
## Getting started ## Getting started
This project provides a set of Terraform modules to enable metrics and traces collection, This project provides a set of Terraform modules to enable metrics, logs and
dashboards and alerts for monitoring: traces collection, dashboards and alerts for monitoring:
- Amazon EKS clusters infrastructure - Amazon EKS clusters infrastructure and applications
- NGINX workloads (running on Amazon EKS) - NGINX workloads (running on Amazon EKS)
- Java/JMX workloads (running on Amazon EKS) - Java/JMX workloads (running on Amazon EKS)
- Amazon Managed Service for Prometheus workspaces with Amazon CloudWatch - Amazon Managed Service for Prometheus workspaces with Amazon CloudWatch
These modules can be directly configured in your existing Terraform configurations or ready These modules can be directly configured in your existing Terraform
to be deployed in our packaged configurations or ready to be deployed in our packaged
[examples](https://github.com/aws-observability/terraform-aws-observability-accelerator/tree/main/examples) [examples](https://github.com/aws-observability/terraform-aws-observability-accelerator/tree/main/examples)
!!! tip !!! tip
We have supporting examples for quick setup such as: We have supporting examples for quick setup such as:
- Creating a new Amazon EKS cluster and a VPC - Creating a new Amazon EKS cluster and a VPC
- Creating and configure an Amazon Managed Grafana workspace with SSO (coming soon) - Creating and configure an Amazon Managed Grafana workspace with SSO
## Motivation ## Motivation
+2
View File
@@ -84,6 +84,8 @@ module "eks_monitoring" {
scrape_sample_limit = 2000 scrape_sample_limit = 2000
} }
enable_logs = true
tags = local.tags tags = local.tags
depends_on = [ depends_on = [
+2
View File
@@ -73,6 +73,8 @@ module "eks_monitoring" {
managed_prometheus_workspace_endpoint = module.aws_observability_accelerator.managed_prometheus_workspace_endpoint managed_prometheus_workspace_endpoint = module.aws_observability_accelerator.managed_prometheus_workspace_endpoint
managed_prometheus_workspace_region = module.aws_observability_accelerator.managed_prometheus_workspace_region managed_prometheus_workspace_region = module.aws_observability_accelerator.managed_prometheus_workspace_region
enable_logs = true
tags = local.tags tags = local.tags
depends_on = [ depends_on = [
@@ -89,6 +89,8 @@ module "eks_monitoring" {
global_scrape_timeout = "15s" global_scrape_timeout = "15s"
} }
enable_logs = true
tags = local.tags tags = local.tags
depends_on = [ depends_on = [
+1
View File
@@ -29,6 +29,7 @@ nav:
- Infrastructure monitoring: eks/index.md - Infrastructure monitoring: eks/index.md
- Java/JMX: eks/java.md - Java/JMX: eks/java.md
- Nginx: eks/nginx.md - Nginx: eks/nginx.md
- Viewing logs: eks/logs.md
- Teardown: eks/destroy.md - Teardown: eks/destroy.md
- Monitoring Managed Service for Prometheus Workspaces: workloads/managed-prometheus.md - Monitoring Managed Service for Prometheus Workspaces: workloads/managed-prometheus.md
- Supporting Examples: - Supporting Examples:
+7 -3
View File
@@ -2,11 +2,12 @@
This module provides EKS cluster monitoring with the following resources: This module provides EKS cluster monitoring with the following resources:
- AWS Distro For OpenTelemetry Operator and Collector - AWS Distro For OpenTelemetry Operator and Collector for Metrics and Traces
- Logs with [AWS for FluentBit](https://github.com/aws/aws-for-fluent-bit)
- AWS Managed Grafana Dashboard and data source - AWS Managed Grafana Dashboard and data source
- Alerts and recording rules with AWS Managed Service for Prometheus - Alerts and recording rules with AWS Managed Service for Prometheus
This module is inspired from the open source [kube-prometheus-stack](https://github.com/prometheus-community/helm-charts/tree/main/charts/kube-prometheus-stack) This module makes use of the open source [kube-prometheus-stack](https://github.com/prometheus-community/helm-charts/tree/main/charts/kube-prometheus-stack)
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK --> <!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
## Requirements ## Requirements
@@ -32,7 +33,8 @@ This module is inspired from the open source [kube-prometheus-stack](https://git
| Name | Source | Version | | Name | Source | Version |
|------|--------|---------| |------|--------|---------|
| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/helm-addon | v4.13.1 | | <a name="module_fluentbit_logs"></a> [fluentbit\_logs](#module\_fluentbit\_logs) | ./add-ons/aws-for-fluentbit | n/a |
| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/helm-addon | v4.26.0 |
| <a name="module_java_monitoring"></a> [java\_monitoring](#module\_java\_monitoring) | ./patterns/java | n/a | | <a name="module_java_monitoring"></a> [java\_monitoring](#module\_java\_monitoring) | ./patterns/java | n/a |
| <a name="module_nginx_monitoring"></a> [nginx\_monitoring](#module\_nginx\_monitoring) | ./patterns/nginx | n/a | | <a name="module_nginx_monitoring"></a> [nginx\_monitoring](#module\_nginx\_monitoring) | ./patterns/nginx | n/a |
| <a name="module_operator"></a> [operator](#module\_operator) | ./add-ons/adot-operator | n/a | | <a name="module_operator"></a> [operator](#module\_operator) | ./add-ons/adot-operator | n/a |
@@ -70,6 +72,7 @@ This module is inspired from the open source [kube-prometheus-stack](https://git
| <a name="input_enable_dashboards"></a> [enable\_dashboards](#input\_enable\_dashboards) | Enables or disables curated dashboards | `bool` | `true` | no | | <a name="input_enable_dashboards"></a> [enable\_dashboards](#input\_enable\_dashboards) | Enables or disables curated dashboards | `bool` | `true` | no |
| <a name="input_enable_java"></a> [enable\_java](#input\_enable\_java) | Enable Java workloads monitoring, alerting and default dashboards | `bool` | `false` | no | | <a name="input_enable_java"></a> [enable\_java](#input\_enable\_java) | Enable Java workloads monitoring, alerting and default dashboards | `bool` | `false` | no |
| <a name="input_enable_kube_state_metrics"></a> [enable\_kube\_state\_metrics](#input\_enable\_kube\_state\_metrics) | Enables or disables Kube State metrics exporter. Disabling this might affect some data in the dashboards | `bool` | `true` | no | | <a name="input_enable_kube_state_metrics"></a> [enable\_kube\_state\_metrics](#input\_enable\_kube\_state\_metrics) | Enables or disables Kube State metrics exporter. Disabling this might affect some data in the dashboards | `bool` | `true` | no |
| <a name="input_enable_logs"></a> [enable\_logs](#input\_enable\_logs) | Using AWS For FluentBit to collect cluster and application logs to Amazon CloudWatch | `bool` | `true` | no |
| <a name="input_enable_nginx"></a> [enable\_nginx](#input\_enable\_nginx) | Enable NGINX workloads monitoring, alerting and default dashboards | `bool` | `false` | no | | <a name="input_enable_nginx"></a> [enable\_nginx](#input\_enable\_nginx) | Enable NGINX workloads monitoring, alerting and default dashboards | `bool` | `false` | no |
| <a name="input_enable_node_exporter"></a> [enable\_node\_exporter](#input\_enable\_node\_exporter) | Enables or disables Node exporter. Disabling this might affect some data in the dashboards | `bool` | `true` | no | | <a name="input_enable_node_exporter"></a> [enable\_node\_exporter](#input\_enable\_node\_exporter) | Enables or disables Node exporter. Disabling this might affect some data in the dashboards | `bool` | `true` | no |
| <a name="input_enable_tracing"></a> [enable\_tracing](#input\_enable\_tracing) | (Experimental) Enables tracing with AWS X-Ray. This changes the deploy mode of the collector to daemon set. Requirement: adot add-on <= 0.58-build.0 | `bool` | `false` | no | | <a name="input_enable_tracing"></a> [enable\_tracing](#input\_enable\_tracing) | (Experimental) Enables tracing with AWS X-Ray. This changes the deploy mode of the collector to daemon set. Requirement: adot add-on <= 0.58-build.0 | `bool` | `false` | no |
@@ -78,6 +81,7 @@ This module is inspired from the open source [kube-prometheus-stack](https://git
| <a name="input_irsa_iam_role_path"></a> [irsa\_iam\_role\_path](#input\_irsa\_iam\_role\_path) | IAM role path for IRSA roles | `string` | `"/"` | no | | <a name="input_irsa_iam_role_path"></a> [irsa\_iam\_role\_path](#input\_irsa\_iam\_role\_path) | IAM role path for IRSA roles | `string` | `"/"` | no |
| <a name="input_java_config"></a> [java\_config](#input\_java\_config) | Configuration object for Java/JMX monitoring | <pre>object({<br> enable_alerting_rules = bool<br> scrape_sample_limit = number<br> })</pre> | <pre>{<br> "enable_alerting_rules": true,<br> "scrape_sample_limit": 1000<br>}</pre> | no | | <a name="input_java_config"></a> [java\_config](#input\_java\_config) | Configuration object for Java/JMX monitoring | <pre>object({<br> enable_alerting_rules = bool<br> scrape_sample_limit = number<br> })</pre> | <pre>{<br> "enable_alerting_rules": true,<br> "scrape_sample_limit": 1000<br>}</pre> | no |
| <a name="input_ksm_config"></a> [ksm\_config](#input\_ksm\_config) | Kube State metrics configuration | <pre>object({<br> create_namespace = bool<br> k8s_namespace = string<br> helm_chart_name = string<br> helm_chart_version = string<br> helm_release_name = string<br> helm_repo_url = string<br> helm_settings = map(string)<br> helm_values = map(any)<br><br> scrape_interval = string<br> scrape_timeout = string<br> })</pre> | <pre>{<br> "create_namespace": true,<br> "helm_chart_name": "kube-state-metrics",<br> "helm_chart_version": "4.24.0",<br> "helm_release_name": "kube-state-metrics",<br> "helm_repo_url": "https://prometheus-community.github.io/helm-charts",<br> "helm_settings": {},<br> "helm_values": {},<br> "k8s_namespace": "kube-system",<br> "scrape_interval": "60s",<br> "scrape_timeout": "15s"<br>}</pre> | no | | <a name="input_ksm_config"></a> [ksm\_config](#input\_ksm\_config) | Kube State metrics configuration | <pre>object({<br> create_namespace = bool<br> k8s_namespace = string<br> helm_chart_name = string<br> helm_chart_version = string<br> helm_release_name = string<br> helm_repo_url = string<br> helm_settings = map(string)<br> helm_values = map(any)<br><br> scrape_interval = string<br> scrape_timeout = string<br> })</pre> | <pre>{<br> "create_namespace": true,<br> "helm_chart_name": "kube-state-metrics",<br> "helm_chart_version": "4.24.0",<br> "helm_release_name": "kube-state-metrics",<br> "helm_repo_url": "https://prometheus-community.github.io/helm-charts",<br> "helm_settings": {},<br> "helm_values": {},<br> "k8s_namespace": "kube-system",<br> "scrape_interval": "60s",<br> "scrape_timeout": "15s"<br>}</pre> | no |
| <a name="input_logs_config"></a> [logs\_config](#input\_logs\_config) | Configuration object for logs collection | <pre>object({<br> cw_log_retention_days = number<br> })</pre> | <pre>{<br> "cw_log_retention_days": 90<br>}</pre> | no |
| <a name="input_managed_prometheus_workspace_endpoint"></a> [managed\_prometheus\_workspace\_endpoint](#input\_managed\_prometheus\_workspace\_endpoint) | Amazon Managed Prometheus Workspace Endpoint | `string` | `""` | no | | <a name="input_managed_prometheus_workspace_endpoint"></a> [managed\_prometheus\_workspace\_endpoint](#input\_managed\_prometheus\_workspace\_endpoint) | Amazon Managed Prometheus Workspace Endpoint | `string` | `""` | no |
| <a name="input_managed_prometheus_workspace_id"></a> [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | Amazon Managed Prometheus Workspace ID | `string` | `null` | no | | <a name="input_managed_prometheus_workspace_id"></a> [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | Amazon Managed Prometheus Workspace ID | `string` | `null` | no |
| <a name="input_managed_prometheus_workspace_region"></a> [managed\_prometheus\_workspace\_region](#input\_managed\_prometheus\_workspace\_region) | Amazon Managed Prometheus Workspace's Region | `string` | `null` | no | | <a name="input_managed_prometheus_workspace_region"></a> [managed\_prometheus\_workspace\_region](#input\_managed\_prometheus\_workspace\_region) | Amazon Managed Prometheus Workspace's Region | `string` | `null` | no |
@@ -0,0 +1,54 @@
# AWS for Fluent Bit
Fluent Bit is an open source Log Processor and Forwarder which allows you to collect any data like metrics and logs from different sources, enrich them with filters and send them to multiple destinations.
AWS provides a Fluent Bit image with plugins for CloudWatch Logs, Kinesis Data Firehose, Kinesis Data Stream and Amazon OpenSearch Service.
This add-on is configured to stream the worker node logs to CloudWatch Logs by default. It can be configured to stream the logs to additional destinations like Kinesis Data Firehose, Kinesis Data Streams and Amazon OpenSearch Service by passing the custom `values.yaml`.
See this [Helm Chart](https://github.com/aws/eks-charts/tree/master/stable/aws-for-fluent-bit) for more details.
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
## Requirements
| Name | Version |
|------|---------|
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.0.0 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 3.72 |
## Providers
| Name | Version |
|------|---------|
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 3.72 |
## Modules
| Name | Source | Version |
|------|--------|---------|
| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/helm-addon | v4.26.0 |
## Resources
| Name | Type |
|------|------|
| [aws_iam_policy.aws_for_fluent_bit](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy) | resource |
| [aws_iam_policy_document.irsa](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source |
## Inputs
| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_addon_context"></a> [addon\_context](#input\_addon\_context) | Input configuration for the addon | <pre>object({<br> aws_caller_identity_account_id = string<br> aws_caller_identity_arn = string<br> aws_eks_cluster_endpoint = string<br> aws_partition_id = string<br> aws_region_name = string<br> eks_cluster_id = string<br> eks_oidc_issuer_url = string<br> eks_oidc_provider_arn = string<br> tags = map(string)<br> irsa_iam_role_path = string<br> irsa_iam_permissions_boundary = string<br> })</pre> | n/a | yes |
| <a name="input_cw_log_retention_days"></a> [cw\_log\_retention\_days](#input\_cw\_log\_retention\_days) | FluentBit CloudWatch Log group retention period | `number` | `90` | no |
| <a name="input_helm_config"></a> [helm\_config](#input\_helm\_config) | Helm provider config aws\_for\_fluent\_bit. | `any` | `{}` | no |
| <a name="input_irsa_policies"></a> [irsa\_policies](#input\_irsa\_policies) | Additional IAM policies for a IAM role for service accounts | `list(string)` | `[]` | no |
| <a name="input_manage_via_gitops"></a> [manage\_via\_gitops](#input\_manage\_via\_gitops) | Determines if the add-on should be managed via GitOps. | `bool` | `false` | no |
## Outputs
| Name | Description |
|------|-------------|
| <a name="output_irsa_arn"></a> [irsa\_arn](#output\_irsa\_arn) | IAM role ARN for the service account |
| <a name="output_irsa_name"></a> [irsa\_name](#output\_irsa\_name) | IAM role name for the service account |
| <a name="output_release_metadata"></a> [release\_metadata](#output\_release\_metadata) | Map of attributes of the Helm release metadata |
| <a name="output_service_account"></a> [service\_account](#output\_service\_account) | Name of Kubernetes service account |
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
@@ -0,0 +1,21 @@
data "aws_iam_policy_document" "irsa" {
statement {
sid = "PutLogEvents"
effect = "Allow"
resources = ["arn:${var.addon_context.aws_partition_id}:logs:${var.addon_context.aws_region_name}:${var.addon_context.aws_caller_identity_account_id}:log-group:*:log-stream:*"]
actions = ["logs:PutLogEvents"]
}
statement {
sid = "CreateCWLogs"
effect = "Allow"
resources = ["arn:${var.addon_context.aws_partition_id}:logs:${var.addon_context.aws_region_name}:${var.addon_context.aws_caller_identity_account_id}:log-group:*"]
actions = [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:DescribeLogGroups",
"logs:DescribeLogStreams",
]
}
}
@@ -0,0 +1,47 @@
locals {
name = "aws-for-fluent-bit"
service_account = try(var.helm_config.service_account, "${local.name}-sa")
set_values = [
{
name = "serviceAccount.name"
value = local.service_account
},
{
name = "serviceAccount.create"
value = false
}
]
# https://github.com/aws/eks-charts/blob/master/stable/aws-for-fluent-bit/Chart.yaml
default_helm_config = {
name = local.name
chart = local.name
repository = "https://aws.github.io/eks-charts"
version = "0.1.24"
namespace = local.name
values = local.default_helm_values
description = "aws-for-fluentbit Helm Chart deployment configuration"
}
helm_config = merge(
local.default_helm_config,
var.helm_config
)
default_helm_values = [templatefile("${path.module}/values.yaml", {
aws_region = var.addon_context.aws_region_name
cluster_name = var.addon_context.eks_cluster_id
log_retention_days = var.cw_log_retention_days
service_account = local.service_account
})]
irsa_config = {
kubernetes_namespace = local.helm_config["namespace"]
kubernetes_service_account = local.service_account
create_kubernetes_namespace = try(local.helm_config["create_namespace"], true)
create_kubernetes_service_account = true
create_service_account_secret_token = try(local.helm_config["create_service_account_secret_token"], false)
irsa_iam_policies = concat([aws_iam_policy.aws_for_fluent_bit.arn], var.irsa_policies)
}
}
@@ -0,0 +1,15 @@
module "helm_addon" {
source = "github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/helm-addon?ref=v4.26.0"
manage_via_gitops = var.manage_via_gitops
set_values = local.set_values
helm_config = local.helm_config
irsa_config = local.irsa_config
addon_context = var.addon_context
}
resource "aws_iam_policy" "aws_for_fluent_bit" {
name = "${var.addon_context.eks_cluster_id}-fluentbit"
description = "IAM Policy for AWS for FluentBit"
policy = data.aws_iam_policy_document.irsa.json
tags = var.addon_context.tags
}
@@ -0,0 +1,19 @@
output "release_metadata" {
description = "Map of attributes of the Helm release metadata"
value = module.helm_addon.release_metadata
}
output "irsa_arn" {
description = "IAM role ARN for the service account"
value = module.helm_addon.irsa_arn
}
output "irsa_name" {
description = "IAM role name for the service account"
value = module.helm_addon.irsa_name
}
output "service_account" {
description = "Name of Kubernetes service account"
value = module.helm_addon.service_account
}
@@ -0,0 +1,16 @@
serviceAccount:
create: false
name: ${service_account}
cloudWatch:
enabled: false
cloudWatchLogs:
enabled: true
region: ${aws_region}
# logGroupName is a fallback to failed parsing
logGroupName: /aws/eks/observability-accelerator/workloads
logGroupTemplate: /aws/eks/observability-accelerator/${cluster_name}/$kubernetes['namespace_name']
logStreamTemplate: $kubernetes['container_name'].$kubernetes['pod_name']
log_key: log
log_retention_days: ${log_retention_days}
@@ -0,0 +1,40 @@
variable "helm_config" {
description = "Helm provider config aws_for_fluent_bit."
type = any
default = {}
}
variable "cw_log_retention_days" {
description = "FluentBit CloudWatch Log group retention period"
type = number
default = 90
}
variable "manage_via_gitops" {
type = bool
description = "Determines if the add-on should be managed via GitOps."
default = false
}
variable "irsa_policies" {
description = "Additional IAM policies for a IAM role for service accounts"
type = list(string)
default = []
}
variable "addon_context" {
description = "Input configuration for the addon"
type = object({
aws_caller_identity_account_id = string
aws_caller_identity_arn = string
aws_eks_cluster_endpoint = string
aws_partition_id = string
aws_region_name = string
eks_cluster_id = string
eks_oidc_issuer_url = string
eks_oidc_provider_arn = string
tags = map(string)
irsa_iam_role_path = string
irsa_iam_permissions_boundary = string
})
}
@@ -0,0 +1,10 @@
terraform {
required_version = ">= 1.0.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 3.72"
}
}
}
+9 -1
View File
@@ -44,7 +44,7 @@ resource "helm_release" "prometheus_node_exporter" {
} }
module "helm_addon" { module "helm_addon" {
source = "github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/helm-addon?ref=v4.13.1" source = "github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/helm-addon?ref=v4.26.0"
helm_config = merge( helm_config = merge(
{ {
@@ -169,3 +169,11 @@ module "nginx_monitoring" {
enable_alerting_rules = var.nginx_config.enable_alerting_rules enable_alerting_rules = var.nginx_config.enable_alerting_rules
dashboards_folder_id = var.dashboards_folder_id dashboards_folder_id = var.dashboards_folder_id
} }
module "fluentbit_logs" {
source = "./add-ons/aws-for-fluentbit"
count = var.enable_logs ? 1 : 0
cw_log_retention_days = var.logs_config.cw_log_retention_days
addon_context = local.context
}
@@ -40,7 +40,6 @@ spec:
scrape_timeout: {{ .Values.globalScrapeTimeout }} scrape_timeout: {{ .Values.globalScrapeTimeout }}
external_labels: external_labels:
cluster: {{ .Values.ekscluster }} cluster: {{ .Values.ekscluster }}
account_id: {{ .Values.accountId }}
region: {{ .Values.region }} region: {{ .Values.region }}
scrape_configs: scrape_configs:
- job_name: 'kubernetes-kubelet' - job_name: 'kubernetes-kubelet'
+18
View File
@@ -247,3 +247,21 @@ variable "nginx_config" {
prometheus_metrics_endpoint = "metrics" prometheus_metrics_endpoint = "metrics"
} }
} }
variable "enable_logs" {
description = "Using AWS For FluentBit to collect cluster and application logs to Amazon CloudWatch"
type = bool
default = true
}
variable "logs_config" {
description = "Configuration object for logs collection"
type = object({
cw_log_retention_days = number
})
default = {
# Valid values are [1, 3, 5, 7, 14, 30, 60, 90, 120, 150, 180, 365, 400, 545, 731, 1827, 3653]
cw_log_retention_days = 90
}
}