The process for deploying cluster Logging to OpenShift Container Platform involves:

Installing the Cluster Logging and Elasticsearch Operators

You can use the OpenShift Container Platform console to install cluster logging, by deploying, the Cluster Logging and Elasticsearch Operators. The Cluster Logging Operator creates and manages the components of the logging stack. The Elasticsearch Operator creates and manages the Elasticsearch cluster used by cluster logging.

The OpenShift Container Platform cluster logging solution requires that you install both the Cluster Logging Operator and Elasticsearch Operator. There is no use case in OpenShift Container Platform for installing the operators individually. You must install the Elasticsearch Operator using the CLI following the directions below. You can install the Cluster Logging Operator using the web console or CLI.

Prerequisites

Ensure that you have the necessary persistent storage for Elasticsearch. Note that each Elasticsearch node requires its own storage volume.

+ Elasticsearch is a memory-intensive application. Each Elasticsearch node needs 16G of memory for both memory requests and CPU limits. The initial set of OpenShift Container Platform nodes might not be large enough to support the Elasticsearch cluster. You must add additional nodes to the OpenShift Container Platform cluster to run with the recommended or higher memory. Each Elasticsearch node can operate with a lower memory setting though this is not recommended for production deployments.

You must install the Elasticsearch Operator using the CLI following the directions below. You can install the Cluster Logging Operator using the web console or CLI.

Procedure
  1. Install the Elasticsearch Operator using the CLI to ensure the necessary values are set:

    1. Create a Namespace for the Elasticsearch operator (for example, eo-project.yaml):

      apiVersion: v1
      kind: Namespace
      metadata:
        name: openshift-operators-redhat (1)
        annotations:
          openshift.io/node-selector: ""
        labels:
          openshift.io/cluster-logging: "true"
          openshift.io/cluster-monitoring: "true"
      1 You must specify the openshift-operators-redhat namespace.
    2. Create the Namespace object:

      $ oc create -f eo-project.yaml
    3. Create an Operator Group object YAML file (for example, eo-og.yaml) for the Elasticsearch operator:

      apiVersion: operators.coreos.com/v1
      kind: OperatorGroup
      metadata:
        name: openshift-operators-redhat
        namespace: openshift-operators-redhat (1)
      spec: {}
      1 You must specify the openshift-operators-redhat namespace.
    4. Create the Operator Group object:

      $ oc create -f eo-og.yaml
    5. Create a CatalogSourceConfig object YAML file (for example, eo-csc.yaml) to enable the Elasticsearch Operator on the cluster.

      Example CatalogSourceConfig
      apiVersion: "operators.coreos.com/v1"
      kind: "CatalogSourceConfig"
      metadata:
        name: "elasticsearch"
        namespace: "openshift-marketplace"
      spec:
        targetNamespace: "openshift-operators-redhat" (1)
        packages: "elasticsearch-operator"
      1 You must specify the openshift-operators-redhat namespace.

      The Operator generates a CatalogSource from your CatalogSourceConfig in the namespace specified in targetNamespace.

    6. Create the CatalogSourceConfig object:

      $ oc create -f eo-csc.yaml
    7. Use the following commands to get the channel and currentCSV values required for the next step.

      $ oc get packagemanifest elasticsearch-operator -n openshift-marketplace -o jsonpath='{.status.channels[].name}'
      
      preview
      
      $ oc get packagemanifest elasticsearch-operator -n openshift-marketplace -o jsonpath='{.status.channels[].currentCSV}'
      
      elasticsearch-operator.v4.1.0
    8. Create a Subscription object YAML file (for example, eo-sub.yaml) to subscribe a Namespace to an Operator.

      Example Subscription
      apiVersion: operators.coreos.com/v1alpha1
      kind: Subscription
      metadata:
        generateName: "elasticsearch-"
        namespace: "openshift-operators-redhat" (1)
      spec:
        channel: "preview" (2)
        installPlanApproval: "Automatic"
        source: "elasticsearch"
        sourceNamespace: "openshift-operators-redhat" (1)
        name: "elasticsearch-operator"
        startingCSV: "elasticsearch-operator.v4.1.0" (3)
      1 You must specify the openshift-operators-redhat namespace for namespace and sourceNameSpace.
      2 Specify the .status.channels[].name value from the previous step.
      3 Specify the .status.channels[].currentCSV value from the previous step.
    9. Create the Subscription object:

      $ oc create -f eo-sub.yaml
    10. Change to the openshift-operators-redhat project:

      $ oc project openshift-operators-redhat
      
      Now using project "openshift-operators-redhat"
    11. Create a Role-based Access Control (RBAC) object file (for example, eo-rbac.yaml) to grant Prometheus permission to access the openshift-operators-redhat namespace:

      apiVersion: rbac.authorization.k8s.io/v1
      kind: Role
      metadata:
        name: prometheus-k8s
        namespace: openshift-operators-redhat
      rules:
      - apiGroups:
        - ""
        resources:
        - services
        - endpoints
        - pods
        verbs:
        - get
        - list
        - watch
      ---
      apiVersion: rbac.authorization.k8s.io/v1
      kind: RoleBinding
      metadata:
        name: prometheus-k8s
        namespace: openshift-operators-redhat
      roleRef:
        apiGroup: rbac.authorization.k8s.io
        kind: Role
        name: prometheus-k8s
      subjects:
      - kind: ServiceAccount
        name: prometheus-k8s
      namespace: openshift-operators-redhat
    12. Create the RBAC object:

      $ oc create -f eo-rbac.yaml

      The Elasticsearch operator is installed to each project in the cluster.

  2. You can install the Cluster Logging Operator using the OpenShift Container Platform web console for best results:

    1. In the CLI, create a project for cluster logging. You must create the project with the CLI:

      apiVersion: v1
      kind: Namespace
      metadata:
        name: openshift-logging
        annotations:
          openshift.io/node-selector: "" (1)
        labels:
          openshift.io/cluster-logging: "true"
          openshift.io/cluster-monitoring: "true"
      1 Optionally specify an empty node selector in order for the logging pods to spread evenly across your cluster. The logging pods will be spread evenly throughout the cluster. If you want the logging pods to run on specific nodes, you can specify a node selector value here.
    2. Run the following command to create the project:

      $ oc create -f <file-name>.yaml
    3. In the OpenShift Container Platform web console, click CatalogOperatorHub.

    4. Choose Cluster Logging from the list of available Operators, and click Install.

    5. On the Create Operator Subscription page, under A specific namespace on the cluster select openshift-logging. Then, click Subscribe.

  3. Verify the operator installations:

    1. Switch to the CatalogInstalled Operators page.

    2. Ensure that Cluster Logging and Elasticsearch Operator are listed on the InstallSucceeded tab with a Status of InstallSucceeded. Change the project to all projects if necessary.

      During installation an operator might display a Failed status. If the operator then installs with an InstallSucceeded message, you can safely ignore the Failed message.

      If either operator does not appear as installed, to troubleshoot further:

      • On the Copied tab of the Installed Operators page, if an operator show a Status of Copied, this indicates the installation is in process and is expected behavior.

      • Switch to the CatalogOperator Management page and inspect the Operator Subscriptions and Install Plans tabs for any failure or errors under Status.

      • Switch to the WorkloadsPods page and check the logs in any Pods in the openshift-logging and openshift-operators-red projects that are reporting issues.

  4. Create a cluster logging instance:

    1. Switch to the the AdministrationCustom Resource Definitions page.

    2. On the Custom Resource Definitions page, click ClusterLogging.

    3. On the Custom Resource Definition Overview page, select View Instances from the Actions menu.

    4. On the Cluster Loggings page, click Create Cluster Logging.

      You might have to refresh the page to load the data.

    5. In the YAML, replace the code with the following:

      This default cluster logging configuration should support a wide array of environments. Review the topics on tuning and configuring the cluster logging components for information on modifications you can make to your cluster logging cluster.

      apiVersion: "logging.openshift.io/v1"
      kind: "ClusterLogging"
      metadata:
        name: "instance" (1)
        namespace: "openshift-logging"
      spec:
        managementState: "Managed"  (2)
        logStore:
          type: "elasticsearch"  (3)
          elasticsearch:
            nodeCount: 3 (4)
            storage:
              storageClassName: gp2
              size: 200G
            redundancyPolicy: "SingleRedundancy"
        visualization:
          type: "kibana"  (5)
          kibana:
            replicas: 1
        curation:
          type: "curator"  (6)
          curator:
            schedule: "30 3 * * *"
        collection:
          logs:
            type: "fluentd"  (7)
            fluentd: {}
      1 The name of the CR. This must be instance.
      2 The cluster logging management state. In most cases, if you change the default cluster logging defaults, you must set this to Unmanaged. However, an unmanaged deployment does not receive updates until the cluster logging is placed back into a managed state. For more information, see Changing cluster logging management state.
      3 Settings for configuring Elasticsearch. Using the CR, you can configure shard replication policy and persistent storage. For more information, see Configuring Elasticsearch.
      4 Specify the number of Elasticsearch nodes. See the note that follows this list.
      5 Settings for configuring Kibana. Using the CR, you can scale Kibana for redundancy and configure the CPU and memory for your Kibana nodes. For more information, see Configuring Kibana.
      6 Settings for configuring Curator. Using the CR, you can set the Curator schedule. For more information, see Configuring Curator.
      7 Settings for configuring Fluentd. Using the CR, you can configure Fluentd CPU and memory limits. For more information, see Configuring Fluentd.

      The maximum number of Elasticsearch master nodes is three. If you specify a nodeCount greater than 3, OpenShift Container Platform creates three Elasticsearch nodes that are Master-eligible nodes, with the master, client, and data roles. The additional Elasticsearch nodes are created as Data-only nodes, using client and data roles. Master nodes perform cluster-wide actions such as creating or deleting an index, shard allocation, and tracking nodes. Data nodes hold the shards and perform data-related operations such as CRUD, search, and aggregations. Data-related operations are I/O-, memory-, and CPU-intensive. It is important to monitor these resources and to add more Data nodes if the current nodes are overloaded.

      For example, if nodeCount=4, the following nodes are created:

      $ oc get deployment
      
      cluster-logging-operator       1/1     1            1           18h
      elasticsearch-cd-x6kdekli-1    0/1     1            0           6m54s
      elasticsearch-cdm-x6kdekli-1   1/1     1            1           18h
      elasticsearch-cdm-x6kdekli-2   0/1     1            0           6m49s
      elasticsearch-cdm-x6kdekli-3   0/1     1            0           6m44s
    6. Click Create. This creates the Cluster Logging Custom Resource and Elasticsearch Custom Resource, which you can edit to make changes to your cluster logging cluster.

  5. Verify the install:

    1. Switch to the WorkloadsPods page.

    2. Select the openshift-logging project.

      You should see several pods for cluster logging, Elasticsearch, Fluentd, and Kibana similar to the following list:

      • cluster-logging-operator-cb795f8dc-xkckc

      • elasticsearch-cdm-b3nqzchd-1-5c6797-67kfz

      • elasticsearch-cdm-b3nqzchd-2-6657f4-wtprv

      • elasticsearch-cdm-b3nqzchd-3-588c65-clg7g

      • fluentd-2c7dg

      • fluentd-9z7kk

      • fluentd-br7r2

      • fluentd-fn2sb

      • fluentd-pb2f8

      • fluentd-zqgqx

      • kibana-7fb4fd4cc9-bvt4p

    3. Switch to the WorkloadsPods page.

Additional resources

For more information on installing operators,see Installing Operators from the OperatorHub.