
أداة فحص مجموعات Kubernetes السحابية الأصلية التي تكتشف التكوينات الخاطئة للتطبيقات والمكونات غير الصحية ومشاكل العقد باستخدام قواعد OPA وPromQL والنظام المخصصة.
الإنجليزية | 中文
KubeEye هي أداة فحص عناقيد سحابية أصلية مصممة خصيصًا لـ Kubernetes، وقادرة على تحديد المشكلات والمخاطر داخل عنقود Kubernetes بناءً على قواعد مخصصة.
قم بتنزيل حزمة التثبيت من Releases، والتي تتضمن مخطط Helm وقواعد العرض التوضيحي والصور للتثبيت دون اتصال.
VERSION=v1.0.3
wget https://github.com/kubesphere/kubeeye/releases/download/${VERSION}/kubeeye-offline-${VERSION}.tar.gz
tar -zxvf kubeeye-offline-${VERSION}.tar.gz
cd kubeeye-offline-${VERSION}
# offline installation, please import the images in the 'images' folder into the local container repository yourself and modify the images repo in `chart/kubeeye/values.yaml`.
helm upgrade --install kubeeye chart/kubeeye -n kubeeye-system --create-namespace
يوفر دليل
rulesفي حزمة التثبيت قواعد العرض التوضيحي، والتي يمكن تخصيصها وفقًا للاحتياجات المحددة.
ملاحظة: تحتاج قواعد PromQL إلى تعيين نقطة نهاية Prometheus مسبقًا.
kubectl apply -f rules
قم بتكوين خطط الفحص حسب الطلب.
cat > plan.yaml << EOF
apiVersion: kubeeye.kubesphere.io/v1alpha2
kind: InspectPlan
metadata:
name: inspectplan
spec:
# The planned time for executing inspections only supports cron expressions. For example, '*/30 * * * ?' means that the inspection will be performed every 30 minutes.'
# If only a single inspection is required, then remove this parameter.
schedule: "* */12 * * ?"
# The maximum number of retained inspection results, if not filled in, will retain all.
maxTasks: 10
# Should the inspection plan be paused, applicable only to periodic inspections, true or false (default is false).
suspend: false
# Inspection timeout, default 10 minutes.
timeout: 10m
# Inspection rule list, used to associate corresponding inspection rules, please fill in the inspectRule name.
# Execute `kubectl get inspectrule` to view the inspection rules in the cluster.
ruleNames:
- name: configmap-inspect-rules
- name: cronjob-inspect-rules
- name: daemonset-inspect-rules
- name: deployment-inspect-rules
- name: event-inspect-rules
- name: job-inspect-rules
- name: node-inspect-rules
- name: pod-inspect-rules
- name: pod-state-inspect-rules
# nodeName: master
# nodeSelector:
# node-role.kubernetes.io/master: ""
# Multi-cluster inspection (currently only supports multi-cluster inspection in KubeSphere)
# clusterName:
# - name: host
EOF
kubectl apply -f plan.yaml
# View the name of the inspection result for inspection report download.
kubectl get inspectresult
## Get the address and port of kubeeye-apiserver service.
kubectl get svc -n kubeeye-system kubeeye-apiserver -o custom-columns=CLUSTER-IP:.spec.clusterIP,PORT:.spec.ports[*].port
## Download the inspection report, and please replace <> with the actual information obtained from the environment.
curl http://<svc-ip>:9090/kapis/kubeeye.kubesphere.io/v1alpha2/inspectresults/<result name>\?type\=html -o inspectReport.html
## After downloading, you can use a browser to open the HTML file for viewing.
## Create a nodePort type svc for kubeeye-apiserver.
kubectl -n kubeeye-system expose deploy kubeeye-apiserver --port=9090 --type=NodePort --name=ke-apiserver-node-port
## Enter the inspection report URL in the browser to view, and remember to replace <> with the actual information obtained from the environment.
http://<node address>:<node port>/kapis/kubeeye.kubesphere.io/v1alpha2/inspectresults/<result name>?type=html