logging: leave image and runtime log rotation to kubelet
This commit is contained in:
parent
103e20645e
commit
7e96995866
@ -7,8 +7,6 @@ resources:
|
||||
- opensearch-dashboards-objects.yaml
|
||||
- opensearch-observability-objects.yaml
|
||||
- node-log-rotation-serviceaccount.yaml
|
||||
- node-image-gc-rpi4-serviceaccount.yaml
|
||||
- node-image-prune-rpi5-serviceaccount.yaml
|
||||
- vault-serviceaccount.yaml
|
||||
- secretproviderclass.yaml
|
||||
- opensearch-pvc.yaml
|
||||
@ -23,8 +21,6 @@ resources:
|
||||
- opensearch-prune-cronjob.yaml
|
||||
- fluent-bit-helmrelease.yaml
|
||||
- node-log-rotation-daemonset.yaml
|
||||
- node-image-gc-rpi4-daemonset.yaml
|
||||
- node-image-prune-rpi5-daemonset.yaml
|
||||
- oauth2-proxy.yaml
|
||||
- vault-sync-deployment.yaml
|
||||
- ingress.yaml
|
||||
@ -36,18 +32,6 @@ configMapGenerator:
|
||||
- node_log_rotation.sh=scripts/node_log_rotation.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: node-image-gc-rpi4-script
|
||||
namespace: logging
|
||||
files:
|
||||
- node_image_gc_rpi4.sh=scripts/node_image_gc_rpi4.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: node-image-prune-rpi5-script
|
||||
namespace: logging
|
||||
files:
|
||||
- node_image_prune_rpi5.sh=scripts/node_image_prune_rpi5.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: opensearch-prune-script
|
||||
namespace: logging
|
||||
files:
|
||||
|
||||
@ -1,49 +0,0 @@
|
||||
# services/logging/node-image-gc-rpi4-daemonset.yaml
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: node-image-gc-rpi4
|
||||
namespace: logging
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: node-image-gc-rpi4
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: node-image-gc-rpi4
|
||||
spec:
|
||||
serviceAccountName: node-image-gc-rpi4
|
||||
tolerations:
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
effect: NoSchedule
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
effect: NoSchedule
|
||||
nodeSelector:
|
||||
hardware: rpi4
|
||||
containers:
|
||||
- name: node-image-gc-rpi4
|
||||
image: bitnami/kubectl@sha256:554ab88b1858e8424c55de37ad417b16f2a0e65d1607aa0f3fe3ce9b9f10b131
|
||||
command: ["/usr/bin/env", "bash"]
|
||||
args: ["/scripts/node_image_gc_rpi4.sh"]
|
||||
securityContext:
|
||||
privileged: true
|
||||
runAsUser: 0
|
||||
volumeMounts:
|
||||
- name: host-root
|
||||
mountPath: /host
|
||||
- name: script
|
||||
mountPath: /scripts
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: host-root
|
||||
hostPath:
|
||||
path: /
|
||||
- name: script
|
||||
configMap:
|
||||
name: node-image-gc-rpi4-script
|
||||
defaultMode: 0555
|
||||
@ -1,6 +0,0 @@
|
||||
# services/logging/node-image-gc-rpi4-serviceaccount.yaml
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: node-image-gc-rpi4
|
||||
namespace: logging
|
||||
@ -1,49 +0,0 @@
|
||||
# services/logging/node-image-prune-rpi5-daemonset.yaml
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: node-image-prune-rpi5
|
||||
namespace: logging
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: node-image-prune-rpi5
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: node-image-prune-rpi5
|
||||
spec:
|
||||
serviceAccountName: node-image-prune-rpi5
|
||||
tolerations:
|
||||
- key: node-role.kubernetes.io/control-plane
|
||||
operator: Exists
|
||||
effect: NoSchedule
|
||||
- key: node-role.kubernetes.io/master
|
||||
operator: Exists
|
||||
effect: NoSchedule
|
||||
nodeSelector:
|
||||
hardware: rpi5
|
||||
containers:
|
||||
- name: node-image-prune-rpi5
|
||||
image: bitnami/kubectl@sha256:554ab88b1858e8424c55de37ad417b16f2a0e65d1607aa0f3fe3ce9b9f10b131
|
||||
command: ["/usr/bin/env", "bash"]
|
||||
args: ["/scripts/node_image_prune_rpi5.sh"]
|
||||
securityContext:
|
||||
privileged: true
|
||||
runAsUser: 0
|
||||
volumeMounts:
|
||||
- name: host-root
|
||||
mountPath: /host
|
||||
- name: script
|
||||
mountPath: /scripts
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: host-root
|
||||
hostPath:
|
||||
path: /
|
||||
- name: script
|
||||
configMap:
|
||||
name: node-image-prune-rpi5-script
|
||||
defaultMode: 0555
|
||||
@ -1,6 +0,0 @@
|
||||
# services/logging/node-image-prune-rpi5-serviceaccount.yaml
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: node-image-prune-rpi5
|
||||
namespace: logging
|
||||
@ -1,36 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
changed=0
|
||||
k3s_changed=0
|
||||
k3s_agent_changed=0
|
||||
|
||||
k3s_dropin="/host/etc/systemd/system/k3s.service.d/98-image-gc.conf"
|
||||
k3s_agent_dropin="/host/etc/systemd/system/k3s-agent.service.d/98-image-gc.conf"
|
||||
|
||||
if [ -f "/host/etc/systemd/system/k3s.service" ] && [ ! -f "${k3s_dropin}" ]; then
|
||||
mkdir -p "$(dirname "${k3s_dropin}")"
|
||||
printf "[Service]\nEnvironment=\"K3S_KUBELET_ARG=image-gc-high-threshold=70\"\nEnvironment=\"K3S_KUBELET_ARG=image-gc-low-threshold=60\"\nEnvironment=\"K3S_KUBELET_ARG=image-gc-minimum-available=5Gi\"\n" > "${k3s_dropin}"
|
||||
changed=1
|
||||
k3s_changed=1
|
||||
fi
|
||||
|
||||
if [ -f "/host/etc/systemd/system/k3s-agent.service" ] && [ ! -f "${k3s_agent_dropin}" ]; then
|
||||
mkdir -p "$(dirname "${k3s_agent_dropin}")"
|
||||
printf "[Service]\nEnvironment=\"K3S_KUBELET_ARG=image-gc-high-threshold=70\"\nEnvironment=\"K3S_KUBELET_ARG=image-gc-low-threshold=60\"\nEnvironment=\"K3S_KUBELET_ARG=image-gc-minimum-available=5Gi\"\n" > "${k3s_agent_dropin}"
|
||||
changed=1
|
||||
k3s_agent_changed=1
|
||||
fi
|
||||
|
||||
if [ "${changed}" -eq 1 ]; then
|
||||
sleep "$(( (RANDOM % 300) + 10 ))"
|
||||
chroot /host /bin/systemctl daemon-reload
|
||||
if [ "${k3s_changed}" -eq 1 ]; then
|
||||
chroot /host /bin/systemctl restart k3s
|
||||
fi
|
||||
if [ "${k3s_agent_changed}" -eq 1 ]; then
|
||||
chroot /host /bin/systemctl restart k3s-agent
|
||||
fi
|
||||
fi
|
||||
|
||||
sleep infinity
|
||||
@ -1,26 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
threshold=70
|
||||
|
||||
sleep "$(( (RANDOM % 300) + 10 ))"
|
||||
|
||||
while true; do
|
||||
usage=$(df -P /host | awk 'NR==2 {gsub(/%/,"",$5); print $5}')
|
||||
if [ -z "${usage}" ]; then
|
||||
sleep 1800
|
||||
continue
|
||||
fi
|
||||
|
||||
if [ "${usage}" -ge "${threshold}" ]; then
|
||||
chroot /host /bin/sh -c '
|
||||
if command -v crictl >/dev/null 2>&1; then
|
||||
crictl --runtime-endpoint=unix:///run/k3s/containerd/containerd.sock rmi --prune || true
|
||||
elif [ -x /usr/local/bin/crictl ]; then
|
||||
/usr/local/bin/crictl --runtime-endpoint=unix:///run/k3s/containerd/containerd.sock rmi --prune || true
|
||||
fi
|
||||
'
|
||||
fi
|
||||
|
||||
sleep 21600
|
||||
done
|
||||
@ -1,102 +1,18 @@
|
||||
#!/usr/bin/env bash
|
||||
# Kubelet owns image and container-log rotation; this guard only protects
|
||||
# constrained log mounts and caps the host journal. It never restarts k3s.
|
||||
set -euo pipefail
|
||||
|
||||
changed=0
|
||||
journald_changed=0
|
||||
k3s_changed=0
|
||||
k3s_agent_changed=0
|
||||
|
||||
journald_dropin="/host/etc/systemd/journald.conf.d/99-logging.conf"
|
||||
k3s_dropin="/host/etc/systemd/system/k3s.service.d/99-logging.conf"
|
||||
k3s_agent_dropin="/host/etc/systemd/system/k3s-agent.service.d/99-logging.conf"
|
||||
k3s_image_gc_dropin="/host/etc/systemd/system/k3s.service.d/98-image-gc.conf"
|
||||
k3s_agent_image_gc_dropin="/host/etc/systemd/system/k3s-agent.service.d/98-image-gc.conf"
|
||||
|
||||
ensure_dropin() {
|
||||
local path="$1"
|
||||
local owner="$2"
|
||||
local new_content="$3"
|
||||
local current=""
|
||||
if [ -f "${path}" ]; then
|
||||
current="$(cat "${path}" || true)"
|
||||
fi
|
||||
if [ "${current}" != "${new_content}" ]; then
|
||||
mkdir -p "$(dirname "${path}")"
|
||||
printf "%s\n" "${new_content}" > "${path}"
|
||||
changed=1
|
||||
case "${owner}" in
|
||||
journald)
|
||||
journald_changed=1
|
||||
;;
|
||||
k3s)
|
||||
k3s_changed=1
|
||||
;;
|
||||
k3s-agent)
|
||||
k3s_agent_changed=1
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
}
|
||||
|
||||
ensure_dropin \
|
||||
"${journald_dropin}" \
|
||||
"journald" \
|
||||
"[Journal]
|
||||
expected="[Journal]
|
||||
Storage=volatile
|
||||
RuntimeMaxUse=200M
|
||||
RuntimeKeepFree=512M
|
||||
MaxFileSec=1h"
|
||||
|
||||
if [ -f "/host/etc/systemd/system/k3s.service" ]; then
|
||||
ensure_dropin \
|
||||
"${k3s_dropin}" \
|
||||
"k3s" \
|
||||
"[Service]
|
||||
Environment=\"K3S_KUBELET_ARG=container-log-max-size=10Mi\"
|
||||
Environment=\"K3S_KUBELET_ARG=container-log-max-files=2\""
|
||||
fi
|
||||
|
||||
if [ -f "/host/etc/systemd/system/k3s.service" ]; then
|
||||
ensure_dropin \
|
||||
"${k3s_image_gc_dropin}" \
|
||||
"k3s" \
|
||||
"[Service]
|
||||
Environment=\"K3S_KUBELET_ARG=image-gc-high-threshold=65\"
|
||||
Environment=\"K3S_KUBELET_ARG=image-gc-low-threshold=50\"
|
||||
Environment=\"K3S_KUBELET_ARG=image-gc-minimum-available=8Gi\""
|
||||
fi
|
||||
|
||||
if [ -f "/host/etc/systemd/system/k3s-agent.service" ]; then
|
||||
ensure_dropin \
|
||||
"${k3s_agent_dropin}" \
|
||||
"k3s-agent" \
|
||||
"[Service]
|
||||
Environment=\"K3S_KUBELET_ARG=container-log-max-size=10Mi\"
|
||||
Environment=\"K3S_KUBELET_ARG=container-log-max-files=2\""
|
||||
fi
|
||||
|
||||
if [ -f "/host/etc/systemd/system/k3s-agent.service" ]; then
|
||||
ensure_dropin \
|
||||
"${k3s_agent_image_gc_dropin}" \
|
||||
"k3s-agent" \
|
||||
"[Service]
|
||||
Environment=\"K3S_KUBELET_ARG=image-gc-high-threshold=65\"
|
||||
Environment=\"K3S_KUBELET_ARG=image-gc-low-threshold=50\"
|
||||
Environment=\"K3S_KUBELET_ARG=image-gc-minimum-available=8Gi\""
|
||||
fi
|
||||
|
||||
if [ "${changed}" -eq 1 ]; then
|
||||
sleep "$(( (RANDOM % 300) + 10 ))"
|
||||
chroot /host /bin/systemctl daemon-reload
|
||||
if [ "${journald_changed}" -eq 1 ]; then
|
||||
chroot /host /bin/systemctl restart systemd-journald
|
||||
fi
|
||||
if [ "${k3s_changed}" -eq 1 ]; then
|
||||
chroot /host /bin/systemctl restart k3s
|
||||
fi
|
||||
if [ "${k3s_agent_changed}" -eq 1 ]; then
|
||||
chroot /host /bin/systemctl restart k3s-agent
|
||||
fi
|
||||
if [[ ! -f "$journald_dropin" ]] || [[ $(cat "$journald_dropin") != "$expected" ]]; then
|
||||
mkdir -p "$(dirname "$journald_dropin")"
|
||||
printf '%s\n' "$expected" > "$journald_dropin"
|
||||
chroot /host /bin/systemctl restart systemd-journald
|
||||
fi
|
||||
|
||||
trim_constrained_pod_logs() {
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user