To monitor a Go application deployed in Alibaba Cloud Container Service for Kubernetes (ACK), you can install an Application Real-Time Monitoring Service (ARMS) component (ack-onepilot) and compile the Go binary file. Then, you can view the monitoring data of the application, such as the application topology, interface calls, and database analysis. This topic describes how to install an ARMS agent for a Go application deployed in ACK.
If you have any questions when you use an ARMS agent, join the DingTalk group chat (ID: 35568145) for technical support.
Prerequisites
An ACK cluster is created. You can create an ACK dedicated cluster, ACK managed cluster, or ACK Serverless cluster based on your business requirements.
A namespace is created in the cluster. For more information, see Manage namespaces and resource quotas. The namespace used in this example is default.
Check the operating system and architecture of the environment, and the versions of Go and frameworks. For more information, see Compatibility requirements of the ARMS agent for Go.
A go.mod file is created. Application Monitoring only supports compilation based on a go.mod file. To create a go.mod file, run the go mod init command.
Step 1: Install the ack-onepilot component
Log on to the ACK console.
In the left-side navigation pane of the ACK console, click Clusters. On the Clusters page, click the name of the cluster.
In the left-side navigation pane, choose
. On the Add-ons page, enter ack-onepilot in the upper-right corner.ImportantMake sure that the ack-onepilot version is 3.2.0 or later.
Click Install on the ack-onepilot card.
NoteBy default, the ack-onepilot component supports 1,000 pods. For every additional 1,000 pods in the cluster, you need to add 0.5 CPU cores and 512 MB memory for the component.
In the dialog box that appears, configure the parameters and click OK. We recommend that you use the default values.
NoteAfter you install ack-onepilot, you can upgrade, configure, or uninstall it on the Add-ons page.
Step 2: Compile the Go binary file
Run the
wget
command to download the compilation tool based on the region where the environment and machine reside.NoteIf you are able to access Object Storage Service (OSS) over the Internet, you can directly use the public endpoint of the operating system and architecture in the China (Hangzhou) region to obtain the compilation tool.
Grant the compilation tool the permissions required to perform the related operations.
Linux/Darwin
# Grant the permissions. chmod +x instgo
Windows
In Windows, you do not need to grant permissions.
In OpenAPI Explorer, call the DescribeTraceLicenseKey operation to obtain the license key. For more information, see DescribeTraceLicenseKey.
In the directory where the main function of the project is located, run the compilation tool to compile the project. Replace the
{licenseKey}
parameter in the command with the license key obtained in the previous step.If you need to test the compilation result or cannot obtain the license key, add
--dev
to enable Dev Mode. In this mode, you do not need to specify the license key.ImportantThe compilation results in Dev Mode are degraded. Do not use Dev Mode in a production environment.
Run the
./instgo build
command rather than thego build
command.Linux/Darwin
./instgo build --licenseKey="{licenseKey}" --cacheDir=./
Windows
.\instgo.exe build --licenseKey="{licenseKey}" --cacheDir=./
To specify the Linux system as the operating system where Go appliations run in Windows, run the following commands in PowerShell to set compilation environment variables:
$env: GOOS="linux" $env: GOARCH="amd64"
If you want to add additional parameters in the command for subsequent compilation purposes, use a delimiter (
--
) after the options and then add the parameters in the original format. Example:Linux/Darwin
./instgo build --licenseKey="{licenseKey}" --cacheDir=./ -- {arg1} {arg2} ...
Windows
.\instgo.exe build --licenseKey="{licenseKey}" --cacheDir=./ -- {arg1} {arg2} ...
Use the binary file compiled in the previous step to build the image.
References
The following table describes the common Instgo commands.
Command
Flag
Parameter type
Description
Required
build
(compilation)--licenseKey, -l
String
The license key.
Yes (except for Dev Mode)
--dev
-
Specifies Dev Mode as the development mode. In this mode, you can compile data to test functionality without specifying the license key.
ImportantSome features are degraded. Do not use Dev Mode in a production environment.
No
--agentVersion
String
Specifies the version of the ARMS agent.
No
--agentPath
String
Specifies the local path of the ARMS agent.
No
--cacheDir
String
Specifies the cache directory of the ARMS agent.
No
--regionId, -r
String
The ID of the region from which the dependencies of the ARMS agent are downloaded. Default value: cn-hangzhou.
No
--timeout, -t
Integer
The timeout period for downloading the dependencies of the ARMS agent. Unit: seconds. Default value: 180.
No
--verbose, -v
-
Specifies whether to print detailed compilation logs.
No
--vpc
-
Specifies whether to download the dependencies of the ARMS agent over a virtual private cloud (VPC).
No
clean
(cleanup)
-
-
-
-
update
(update)--licenseKey, -l
String
The license key.
Yes
--cacheDir
String
Specifies the cache directory of the ARMS agent.
No
--regionId, -r
String
The ID of the region from which the dependencies of the ARMS agent are downloaded. Default value: cn-hangzhou.
No
--timeout, -t
Integer
The timeout period for downloading the dependencies of the ARMS agent. Unit: seconds. Default value: 180.
No
--vpc
Specifies whether to download the dependencies of the ARMS agent over a VPC.
No
version
(version)
-
-
-
-
The first time that you compile the application, the ARMS agent is downloaded to the
/opt
directory (C:\ProgramData
in Windows) by default. If you have no permissions on the directory, you can use the--cacheDir
flag to specify a cache directory or run thesudo -E
command to compile the agent. In Windows, run commands to compile the application as an administrator.If the compilation is forcibly stopped or killed, a residue may be caused. For information about how to clean up the residue, see Uninstall an ARMS agent for Go.
Step 3: Grant access permissions on ARMS resources
To monitor applications in a serverless Kubernetes (ASK) cluster or applications in a Kubernetes cluster connected to Elastic Container Instance (ECI), you must first authorize the cluster to access ARMS on the Cloud Resource Access Authorization page. Then, restart all pods on which the ack-onepilot component is deployed.
To monitor an application deployed in an ACK cluster with no ARMS Addon Token, perform the following operations to authorize the ACK cluster to access ARMS. If ARMS Addon Token exists, go to Step 4.
NoteIf a cluster has ARMS Addon Token, ARMS performs password-free authorization on the cluster. ARMS Addon Token may not exist in some ACK managed clusters. We recommend that you check whether an ACK managed cluster has ARMS Addon Token before you use ARMS to monitor applications in the cluster. If the cluster has no ARMS Addon Token, you must manually authorize the cluster to access ARMS.
Log on to the ACK console.
In the left-side navigation pane, click Clusters. On the Clusters page, click the name of the cluster.
On the Cluster Information page, click the Cluster Resources tab. Then, click the link next to Worker RAM Role.
On the Permissions tab, click Grant Permission.
Select the AliyunARMSFullAccess policy and click OK.
To monitor an application deployed in an ACK dedicated cluster or registered cluster, make sure that the AliyunARMSFullAccess and AliyunSTSAssumeRoleAccess permissions are granted to the RAM user. For more information about how to grant permissions to a RAM user, see Grant permissions to a RAM user.
After you install the ack-onepilot component, you must enter the AccessKey ID and AccessKey secret of the Alibaba Cloud account in the configuration file of the ack-onepilot component.
In the left-side navigation pane, choose
. Then, click Update next to ack-onepilot.Replace
accessKey
andaccessKeySecret
with the AccessKey ID and AccessKey secret of the Alibaba Cloud account and click OK.NoteFor more information about how to obtain an AccessKey pair, see Create an AccessKey pair.
Restart the Deployment application.
Step 4: Enable Application Monitoring for the application
Log on to the ACK console. In the left-side navigation pane, click Clusters. On the Clusters page, find the cluster that you want to manage, and click Applications in the Actions column.
On the Deployments page, find the application and choose in the Actions column.
To enable Application Monitoring for a new Go application, click Create from YAML on the Deployments page.
Add the following
labels
to the spec > template > metadata section in the Template code editor:labels: aliyun.com/app-language: golang # Specify a Go application. armsPilotAutoEnable: 'on' armsPilotCreateAppName: "<your-deployment-name>" # Replace <your-deployment-name> with the Deployment name.
The following YAML template shows how to create a Deployment application and enable Application Monitoring for the application:
Verify the result
After about one minute, log on to the ARMS console. In the left-side navigation pane, choose . If the application is displayed on the Application List page, the application is being monitored.