c95194747d
Agent-side of Docker container-log collection (milestone 79). Each interval the agent fetches new log lines per running container over the local Docker socket, demuxes the multiplexed stream, and folds sample["docker_logs"] into the same push as metrics — no inbound channel needed. - since-cursor per container kept in rate-state; a container's first interval seeds from a short tail, then fetches incrementally via ?since=<cursor> - _docker_request_raw + _demux_docker_logs + RFC3339Nano ts parsing (stdlib, TTY/unframed fallback); one row per (stream, ts, line) - per-batch byte cap with a truncation marker; logs are dropped (never buffered) across a backoff so an outage keeps metrics but not stale logs - docker_logs_enabled (default on) + docker_log_exclude per-host config keys - AGENT_VERSION 1.6.0 -> 1.7.0 Server ignores the new sample key until the ingest step lands, so this commit is CI-safe on its own. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CAGR73DUowdVFVvYzLXC5C
86 lines
3.2 KiB
Django/Jinja
86 lines
3.2 KiB
Django/Jinja
#!/bin/sh
|
|
# Steward host agent installer
|
|
# Generated for: {{ host_name }} ({{ host_address }})
|
|
# Steward URL: {{ url }}
|
|
set -e
|
|
|
|
STEWARD_URL="{{ url }}"
|
|
AGENT_TOKEN="{{ token }}"
|
|
AGENT_VERSION="{{ agent_version }}"
|
|
|
|
AGENT_USER="steward-agent"
|
|
AGENT_DIR="/usr/local/lib/steward-agent"
|
|
CONF_FILE="/etc/steward-agent.conf"
|
|
UNIT_FILE="/etc/systemd/system/steward-agent.service"
|
|
|
|
# ── preflight ────────────────────────────────────────────────────────────────
|
|
[ "$(id -u)" = "0" ] || { echo "must run as root (use sudo)"; exit 1; }
|
|
command -v systemctl >/dev/null 2>&1 || { echo "systemd not found — unsupported init system"; exit 1; }
|
|
command -v python3 >/dev/null 2>&1 || { echo "python3 not found — install python3 first"; exit 1; }
|
|
|
|
# Handle --uninstall
|
|
if [ "${1:-}" = "--uninstall" ]; then
|
|
systemctl disable --now steward-agent.service 2>/dev/null || true
|
|
rm -f "$UNIT_FILE" "$CONF_FILE"
|
|
rm -rf "$AGENT_DIR"
|
|
systemctl daemon-reload
|
|
# keep the system user — removing it risks orphaned files elsewhere
|
|
echo "uninstalled"
|
|
exit 0
|
|
fi
|
|
|
|
# ── create system user ───────────────────────────────────────────────────────
|
|
if ! id "$AGENT_USER" >/dev/null 2>&1; then
|
|
useradd --system --no-create-home --shell /usr/sbin/nologin "$AGENT_USER"
|
|
fi
|
|
|
|
# ── drop the agent file ──────────────────────────────────────────────────────
|
|
mkdir -p "$AGENT_DIR"
|
|
curl -sSL "${STEWARD_URL}/plugins/host_agent/agent.py" -o "$AGENT_DIR/agent.py"
|
|
chmod 0755 "$AGENT_DIR/agent.py"
|
|
chown root:root "$AGENT_DIR/agent.py"
|
|
|
|
# ── write config ─────────────────────────────────────────────────────────────
|
|
cat > "$CONF_FILE" <<EOF
|
|
url = $STEWARD_URL
|
|
token = $AGENT_TOKEN
|
|
interval_seconds = 30
|
|
# Container logs are collected by default. To opt this host out entirely:
|
|
# docker_logs_enabled = false
|
|
# To skip specific noisy containers (comma-separated names):
|
|
# docker_log_exclude = watchtower, some-chatty-service
|
|
EOF
|
|
chown "root:$AGENT_USER" "$CONF_FILE"
|
|
chmod 0640 "$CONF_FILE"
|
|
|
|
# ── write systemd unit ───────────────────────────────────────────────────────
|
|
cat > "$UNIT_FILE" <<EOF
|
|
[Unit]
|
|
Description=Steward host agent
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=$AGENT_USER
|
|
ExecStart=/usr/bin/python3 $AGENT_DIR/agent.py
|
|
Restart=on-failure
|
|
RestartSec=10
|
|
NoNewPrivileges=yes
|
|
ProtectSystem=strict
|
|
ProtectHome=yes
|
|
PrivateTmp=yes
|
|
ReadOnlyPaths=/proc /sys
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now steward-agent.service
|
|
|
|
echo
|
|
echo "Steward host agent $AGENT_VERSION installed and running."
|
|
echo "Check status: systemctl status steward-agent"
|
|
echo "Logs: journalctl -u steward-agent -f"
|