To monitor Go applications deployed in Container Service for Kubernetes (ACK) or Container Compute Service (ACS), you must install the ack-onepilot component of Application Real-Time Monitoring Service (ARMS) and compile your Go binary file. You can then view monitoring data, such as application topology, API calls, and database analysis, in ARMS. This topic describes how to install a Go agent for an application deployed in Container Service for Kubernetes (ACK) or Container Compute Service (ACS).
The installation steps for ACK and ACS are identical. This guide uses ACK as the example.
If you have questions about the Go agent, contact us in our DingTalk Q&A group (ID: 159215000379).
Prerequisites
An ACK or ACS cluster:
A namespace is required. For more information, see Manage namespaces and quotas. This topic uses the default namespace.
Check the operating system, architecture, Go version, and framework version of your build environment. For specific requirements, see Go components and frameworks supported by ARMS application monitoring.
Step 1: Grant permissions to access ARMS resources
ACK managed cluster
If no ARMS Addon Token exists in your ACK managed cluster, you must manually grant the cluster permissions to access ARMS resources.
If a cluster has ARMS Addon Token, ARMS performs password-free authorization on the cluster. ARMS Addon Token may not exist in some ACK managed clusters. We recommend that you check whether an ACK managed cluster has ARMS Addon Token before you use ARMS to monitor applications in the cluster. If the cluster has no ARMS Addon Token, you must authorize the cluster to access ARMS.
ACK dedicated and registered clusters
To monitor applications in ACK dedicated clusters and ACK One registered clusters, ensure that the Alibaba Cloud account has the AliyunARMSFullAccess and AliyunSTSAssumeRoleAccess permissions. For more information about how to grant permissions, see Grant permissions to a RAM user.
After installing the ack-onepilot component, you must also provide it with the AccessKey pair (AccessKey ID and AccessKey secret) from an Alibaba Cloud account that has ARMS permissions.
Method 1: Specify the AccessKey pair in Helm
-
Log on to the ACK console. In the left navigation pane, click Clusters.
On the Clusters page, click the name of your target cluster. In the left-side navigation pane, choose . Find the ack-onepilot component and click Update in the Actions column.
Replace
accessKeyandaccessKeySecretwith your AccessKey ID and AccessKey secret, and then click OK.NoteFor information about how to obtain an AccessKey pair, see Create an AccessKey pair.
On the Update Release page, in the YAML configuration editor, locate the
accessKeyandaccessKeySecretfields under the controller section.Restart the application Deployment.
Method 2: Reference the AccessKey pair from a secret
Log on to the Container Service for Kubernetes (ACK) console. In the left-side navigation pane, click Clusters.
On the Clusters page, click the name of your target cluster. In the left-side navigation pane, choose .
Select the ack-onepilot namespace, create a secret, and then add your AccessKey pair information.
NoteFor information about how to obtain an AccessKey pair, see Create an AccessKey pair.
Set Name to
ack-onepilot-akskand Type to Opaque. In the data table, add key-value pairs namedakandsk, and set their values to the corresponding AccessKey ID and AccessKey secret. Then click OK.In the left-side navigation pane, choose . Click the ack-onepilot component, which is typically named ack-onepilot-ack-onepilot and located in the ack-onepilot namespace.
In the top-right corner of the ack-onepilot-ack-onepilot page, click Edit. Then, in the Environment Variables section, add
ONE_PILOT_ACCESSKEYandONE_PILOT_ACCESSKEY_SECRET, set their values by referencing the Secret, and click OK.Set the referenced secret for both variables to ack-onepilot-aksk. Set the key for
ONE_PILOT_ACCESSKEYto ak and the key forONE_PILOT_ACCESSKEY_SECRETto sk.
ACK serverless clusters (ASK) and ECI-integrated clusters
Complete authorization on the Resource Access Authorization page, then restart all pods of the ack-onepilot component.
Step 2: Install the ack-onepilot component
-
Log on to the ACK console. On the Clusters page, click the name of the cluster.
In the left-side navigation pane, click Component Management and search for ack-onepilot.
ImportantMake sure that the version of ack-onepilot is 3.2.0 or later.
-
Click Install on the ack-onepilot card.
NoteBy default, the ack-onepilot component supports 1,000 pods. For every additional 1,000 pods in the cluster, you must add 0.5 CPU cores and 512 MB memory for the component.
-
In the dialog box that appears, configure the parameters and click OK. We recommend that you use the default values.
NoteAfter you install ack-onepilot, you can upgrade, configure, or uninstall it on the Add-ons page.
Step 3: Compile the Go application image
(Optional) If your project includes a vendor directory, add
-mod=vendoraftergo build.Use the
wgetcommand to download the instgo compilation tool, and select the download address that corresponds to your compilation environment and the region of your compilation machine.Note that instgo automatically updates itself during compilation. Save instgo in a directory where the build user has write permissions.
NoteInstgo is a build tool that ARMS provides for Go applications. After you compile your Go project by using instgo, ARMS can monitor your Go application.
The build tool is the same across all regions. If your public network can access the OSS URL, you can download the tool from the public endpoint for the China (Hangzhou) region that matches your operating system and architecture.
Grant executable permissions to the build tool.
Linux and Mac
# Grant execute permission chmod +x instgoWindows
On Windows, you do not need to grant executable permissions.
(Optional) Configure the UID as a build parameter.
ImportantIf you skip this step, instgo installs the latest version of the ARMS agent by default.
Use the set command to configure the UID or license key as a build parameter.
instgo set --uid={YourAliyunUid} // You must use instgo 1.4.5 or a later version. The uid is the UID of your primary Alibaba Cloud account.Prefix your original build command with instgo.
instgo go build {arg1} {arg2} {arg3}This method also applies if you use go install.
Build an image using the binary file generated in the previous step.
Step 4: Enable ARMS monitoring for Go applications
The following YAML template shows a complete example of how to create a stateless (Deployment) application and enable ARMS application monitoring:
-
Log on to the ACK console. In the left navigation pane, click Clusters.
At the top of the Clusters page, select the resource group and region where the target cluster is located, and then click the name of the target cluster. In the left-side navigation pane, click Workloads and select Stateless, StatefulSets, or DaemonSets.
Find the target application and choose in the Actions column.
To create a new application, click Create Resources in YAML.
In the YAML file, add the following
labelsto the spec.template.metadata level.labels: aliyun.com/app-language: golang # Required for Go applications. This indicates that this is a Go application. armsPilotAutoEnable: 'on' armsPilotCreateAppName: "<YOUR-DEPLOYMENT-NAME>" # Replace <YOUR-DEPLOYMENT-NAME> with your application name.Click Update.
Results
After about a minute, the agent is connected if your Go application appears on the page in the ARMS console and is reporting data.
> Edit YAML