Anthos clusters on VMware (GKE on-prem) includes multiple options for cluster logging and monitoring, including cloud-based managed services, open source tools, and validated compatibility with third-party commercial solutions. This document explains these options and provides some basic guidance on selecting the proper solution for your environment.
Options for Anthos clusters on VMware
You have several logging and monitoring options for your Anthos clusters on VMware:
- Cloud Logging and Cloud Monitoring, enabled by in-cluster agents deployed with Anthos clusters on VMware.
- Prometheus and Grafana, disabled by default.
- Validated configurations with third-party solutions.
Cloud Logging and Cloud Monitoring
Google Cloud's operations suite (formerly Stackdriver) is the built-in observability solution for Google Cloud. It offers a fully managed logging solution, metrics collection, monitoring, dashboarding, and alerting. Cloud Monitoring monitors Anthos clusters on VMware clusters in a similar way as cloud-based GKE clusters.
You can configure the in-cluster agents for the scope of monitoring and logging, as well as the level of metrics collected:
- Scope of logging and monitoring can be set to system components only (the default) or for system components and applications
- Level of metrics collected can be configured for an optimized set of metrics or for full metrics
See Configuring Logging and Monitoring agents for Anthos clusters on VMware on this document for more information.
Cloud Logging and Cloud Monitoring provide an ideal solution for customers wanting a single, easy-to-configure, powerful cloud-based observability solution. We highly recommend Logging and Monitoring when running workloads only on Anthos clusters on VMware, or workloads on GKE and Anthos clusters on VMware. For applications with components running on Anthos clusters on VMware and traditional on-premises infrastructure, you might consider other solutions for an end-to-end view of those applications.
For details about architecture, configuration, and what data is replicated to your Google Cloud project by default for Anthos clusters on VMware, see the section How Logging and Monitoring for Anthos clusters on VMware works.
For more information about Logging, see the Cloud Logging documentation.
For more information about Monitoring, see the Cloud Monitoring documentation.
Prometheus and Grafana
Prometheus and Grafana are two popular open source monitoring products:
Prometheus collects application and system metrics.
Alertmanager handles sending alerts out with several different alerting mechanisms.
Grafana is a dashboarding tool.
Prometheus and Grafana can be enabled on each admin cluster and user cluster. Prometheus and Grafana is recommended for application teams with prior experience with those products, or for operational teams who prefer to retain application metrics within the cluster and for troubleshooting issues when network connectivity is lost.
Google has worked with several third-party logging and monitoring solution providers to help their products work well with Anthos clusters on VMware. These include Datadog, Elastic, and Splunk. Additional validated third parties will be added in the future.
The following solution guides are available for using third-party solutions with Anthos clusters on VMware:
- Monitoring Anthos clusters on VMware with the Elastic Stack
- Collect logs on Anthos clusters on VMware with Splunk Connect
- Monitoring Anthos clusters on VMware infrastructure with Datadog
How Logging and Monitoring for Anthos clusters on VMware works
Logging and Monitoring agents are installed and activated in each cluster when you create a new admin or user cluster. The agents collect data about system components—the scope of which you can configure.
To view the collected data on the Google Cloud Console, you must configure the Cloud project that stores the logs and metrics you want to view.
The Logging and Monitoring agents include several components on each cluster:
Logging and Monitoring manager (
stackdriver-operator-*). Manages the lifecycle for all other Logging and Monitoring agents deployed onto the cluster.
Stackdriver custom resource. A resource that is automatically created as part of the Anthos clusters on VMware installation process; users can change the custom resource to update values such as project ID, cluster name, and cluster location at any time.
Log Forwarder (
stackdriver-log-forwarder-*). A Fluent Bit DaemonSet that forwards logs from each machine to Cloud Logging. The Log Forwarder buffers the log entries on the node locally and resends them for up to four hours. If the buffer gets full or if the Log Forwarder can't reach the Cloud Logging API for more than four hours, then logs are dropped.
Metrics Collector (
stackdriver-prometheus-k8s-*). A Prometheus and Stackdriver Prometheus Sidecar StatefulSet that sends Prometheus metrics to the Cloud Logging API.
Metadata Collector (
stackdriver-metadata-agent-*). A deployment that sends metadata for Kubernetes resources such as pods, deployments, or nodes to the Stackdriver Resource Metadata API; this data is used to enrich metric queries by enabling you to query by deployment name, node name, or even Kubernetes service name.
You can see all of the agents by running the following command:
kubectl -n kube-system get pods | grep stackdriver
The output of this command is similar to the following:
stackdriver-log-forwarder-bpf8g 1/1 Running 0 4h31m stackdriver-log-forwarder-cht4m 1/1 Running 0 4h31m stackdriver-log-forwarder-fth5s 1/1 Running 0 4h31m stackdriver-log-forwarder-kw4j2 1/1 Running 0 4h29m stackdriver-metadata-agent-cluster-level... 1/1 Running 0 4h31m stackdriver-operator-76ddb64d57-4tcj9 1/1 Running 0 4h37m stackdriver-prometheus-k8s-0 2/2 Running 0 4h31m
Configuring Logging and Monitoring agents for Anthos clusters on VMware
The agents installed with Anthos clusters on VMware collect data about system components, subject to your settings and configuration, for the purposes of maintaining and troubleshooting issues with your clusters.
System components only (default scope)
Upon installation, agents collect logs and metrics, including performance details (for example, CPU and memory utilization) and similar metadata, for Google-provided system components. These include all workloads in the admin cluster, and for user clusters, workloads in the kube-system, gke-system, gke-connect, istio-system, and config-management-system namespaces. You can configure or disable the agents as described in the following sections.
The scope of logs and metrics collected can be expanded to include applications, as well. For instructions to enable application logging and monitoring, see Enabling Logging and Monitoring for user applications.
Optimized metrics (default metrics)
By default, the metrics agents running in the cluster collect and report an optimized set of container and kubelet metrics to Google Cloud's operations suite (formerly Stackdriver). Fewer resources are needed to collect this optimized set of metrics, which improves overall performance and scalability. This is especially important for container-level metrics, due to the large quantity of objects to monitor.
Excluded container metrics
The following container metrics are excluded from the optimized metrics:
The complete set of Anthos clusters on VMware metrics is documented in Anthos metrics.
Excluded kubelet metrics
The following kubelet metrics are excluded from the optimized metrics:
The complete set of Anthos clusters on VMware metrics is documented in Anthos metrics.
To disable optimized metrics (not recommended), set the
false in your Stackdriver custom resource. For more information on changing
your Stackdriver custom resource, see
Configuring Stackdriver component resources.
All Anthos clusters on VMware metrics, including those excluded by default, are
described in Anthos metrics.
You can disable Logging and Monitoring agents completely by deleting the Stackdriver custom resource. Before you disable Stackdriver, see the support page for details about how this affects Google Cloud Support's SLAs.
To disable Stackdriver for Anthos clusters on VMware:
kubectl -n kube-system delete stackdriver stackdriver
Logging and Monitoring agents capture data stored locally, subject to your storage and retention configuration. The data is replicated to the Google Cloud project specified at installation by using a service account that is authorized to write data to that project. You can disable these agents at any time, as described earlier.
You can also manage and delete data collected by Logging and Monitoring agents like any other metric and log data, as described in the Cloud Monitoring documentation.
Configuration requirements for Logging and Monitoring
To view Logging and Monitoring data, you must configure the Cloud project that stores the logs and metrics you want to view. This Cloud project is called your logging-monitoring project.
Enable the following APIs in your logging-monitoring project:
Grant the following IAM roles to your logging-monitoring service account on your logging-monitoring project.
There is no charge for Anthos system logs and metrics.
In a Anthos clusters on VMware cluster, Anthos system logs and metrics include the following:
- Logs and metrics from all components in an admin cluster
- Logs and metrics from components in these namespaces in a user cluster:
For more information, see Pricing for Google Cloud's operations suite.
To learn about credit for Cloud Logging metrics, contact sales for pricing.
How Prometheus and Grafana for Anthos clusters on VMware work
Each Anthos clusters on VMware cluster is created with Prometheus and Grafana disabled by default. You can follow the installation guide to enable them.
The Prometheus Server is set up in a highly-available configuration with two replicas running on two separate nodes. Resource requirements are adjusted to support clusters running up to five nodes, with each handling up to 30 Pods that serve custom metrics. Prometheus has a dedicated PersistentVolume with disk space preallocated to fit data for a retention period of four days plus an added safety buffer.
The admin control plane, as well as each user cluster, has a dedicated monitoring stack that you can configure independently. Each admin and user cluster includes a monitoring stack that delivers a full set of features: Prometheus Server for monitoring, Grafana for observability, and Prometheus Alertmanager for alerting.
All monitoring endpoints, transferred metric data, and monitoring APIs are secured with Istio components by using mTLS and RBAC rules. Access to monitoring data is restricted only to cluster administrators.
Metrics collected by Prometheus
Prometheus collects the following metrics and metadata from the admin control plane and user clusters:
- Resource usage, such as CPU utilization on Pods and nodes.
- Kubernetes control plane metrics.
- Metrics from add-ons and Kubernetes system components running on nodes, such as kubelet.
- Cluster state, such as health of Pods in a Deployment.
- Application metrics.
- Machine metrics, such as network, entropy, and inodes.
The Prometheus and Grafana instance installed on the admin cluster is specially configured to provide insight across the entire Anthos clusters on VMware instance, including the admin cluster and each user cluster. This enables you to:
- Use a Grafana dashboard to access metrics from all user clusters and admin clusters.
- View metrics from individual user clusters on Grafana dashboards; the metrics are available for direct queries in full resolution.
- Access user clusters' node-level and workload metrics for aggregated queries, dashboards and alerting (workload metrics are limited to workloads running in the kube-system namespace).
- Configure alerts for specific clusters.