Documentation
¶
Overview ¶
Package awsautomode collects AWS VPC CNI Network Policy Agent flow logs on EKS Auto Mode clusters.
On EKS Auto Mode the VPC CNI and its Network Policy Agent are AWS-managed and are NOT exposed as pods, so the standard aws-node pod-log collector cannot see them. Instead the agent writes a node-local log file (/var/log/aws-routed-eni/network-policy-agent.log) which this collector reads through the Kubernetes kubelet node-proxy endpoint:
GET /api/v1/nodes/{node}/proxy/logs/aws-routed-eni/network-policy-agent.log
This endpoint does not stream, so the collector polls each node on an interval, using a per-node checkpoint to fetch only new records and to handle log rotation, truncation, and node restarts.
The node-proxy log endpoint is polled rather than streamed. It uses only the operator service account, in-cluster API server access, and Kubernetes RBAC (nodes + the read-only kubelet log endpoint: nodes/log on k8s >=1.33 with fine-grained kubelet authorization, else nodes/proxy). It never connects to node IPs directly, mounts host paths, runs privileged, or uses AWS credentials/SDKs.
Index ¶
Constants ¶
const ( // DefaultPollInterval is the default node-proxy log poll interval. Steady-state // polls issue an HTTP Range request and stream only the small tail after the // per-node checkpoint, but this is still intentionally slower than the pod-log // collector's default to limit load on the apiserver and kubelets. DefaultPollInterval = 10 * time.Second // DefaultMaxConcurrentNodePolls bounds how many nodes are polled at once so a // large cluster does not open one in-flight request per node simultaneously. DefaultMaxConcurrentNodePolls = 10 )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Factory ¶
type Factory struct {
Logger *zap.Logger
FlowSink collector.FlowSink
K8sClient kubernetes.Interface
PollInterval time.Duration
MaxConcurrentNodePolls int
// LogPath overrides the node-local Network Policy Agent log path (relative to
// the kubelet log root). Empty uses collector.DefaultNetworkPolicyAgentLogPath.
LogPath string
// StatsAutoModeNodes, if set, is called each poll cycle with the number of
// Auto Mode nodes observed. StatsAutoModeErrors, if set, is called on each
// per-node or list error. Both are optional (nil-safe).
StatsAutoModeNodes func(int)
StatsAutoModeErrors func()
// Rotation-recovery stats callbacks (all optional / nil-safe):
// StatsRotationsDetected(n) - n unseen rotated generations detected on a poll.
// StatsRotationRecovered() - a rotated generation's tail was recovered.
// StatsRotationRecoveryErr()- a rotated generation failed to recover.
// StatsRotationGap() - a rotated generation was gone before recovery.
StatsRotationsDetected func(int)
StatsRotationRecovered func()
StatsRotationRecoveryErr func()
StatsRotationGap func()
}
Factory creates EKS Auto Mode flow collector clients.
type RotatedFile ¶
type RotatedFile struct {
// ID is the lumberjack backup timestamp (e.g. "2026-08-07T15-04-05.000"),
// shared by the transient ".log" and the final ".log.gz" of one rotation.
ID string
// Filename is the actual file name to fetch via the node-proxy log endpoint.
Filename string
// Compressed is true when Filename ends in ".gz" and must be gunzipped.
Compressed bool
}
RotatedFile is a single rotated generation of the Network Policy Agent log as produced by lumberjack. lumberjack rotates by size: when the active file (network-policy-agent.log) reaches its max size it is RENAMED to network-policy-agent-<timestamp>.log and then compressed in place to network-policy-agent-<timestamp>.log.gz. The timestamp uses lumberjack's backupTimeFormat "2006-01-02T15-04-05.000", which is fixed-width, so the raw string sorts lexically in chronological order and is used directly as the rotation ID.