
【免费下载链接】charts⚠️(OBSOLETE) Curated applications for Kubernetes项目地址https://gitcode.com/gh_mirrors/chart/charts点击查看免费下载本文基于charts仓库中 incubator/elasticsearch-curator 的 Helm Chart 编写。该 Chart 的核心作用是在 Kubernetes 集群中部署一个定期执行的 Elasticsearch Curator 定时任务CronJob通过声明式的action_file.yml与config.yml配置自动化完成旧索引删除、索引合并等维护工作。读完本文你将掌握该 Chart 的安装方式、全部可配置参数、配置模板的底层实现原理以及如何结合仓库源码自定义索引清理策略并了解其迁移到 stable 目录后的增强能力。一、Chart 概览与仓库现状Elasticsearch Curator 是 Elastic 官方推出的索引生命周期管理工具可用于按时间或条件删除、关闭、重建索引。而本仓库中的elasticsearch-curatorChart 则负责把 Curator 以Kubernetes CronJob的形式部署到集群中让索引维护任务按 cron 表达式自动触发。需要特别说明的是incubator 目录下的该 Chart 已标记为废弃deprecated官方在 Chart.yaml 与 README 中都明确提示其已迁移至 stable/elasticsearch-curator。两者核心机制一致但 stable 版本基于新的镜像与模板做了大量增强。本文以 incubator 版本文档为主干展开同时对照 stable 版本说明演进差异。二、前置条件Prerequisites根据 incubator/elasticsearch-curator/README.md 中的说明部署前需要满足ElasticsearchChart 本身不部署 Elasticsearch需要集群中存在可访问的 Elasticsearch 实例同一命名空间或可通过 DNS 解析。Kubernetes CronJob 支持需要运行版本 1.8的 Kubernetes 集群。若集群版本低于 1.8则需要显式启用batch/v2alpha1API在 API Server 启动参数中传入--runtime-configbatch/v2alpha1true。从源码层面看这个版本判断逻辑在 _helpers.tpl 中实现模板会根据集群版本自动选择 CronJob 的 apiVersion{{- define cronjob.apiVersion -}} {{- if semverCompare 1.8-0 .Capabilities.KubeVersion.GitVersion -}} {{- print batch/v2alpha1 }} {{- else if semverCompare 1.8-0 .Capabilities.KubeVersion.GitVersion -}} {{- print batch/v1beta1 }} {{- end -}} {{- end -}}即在 1.8 之前使用batch/v2alpha11.8 及之后使用batch/v1beta1这个 apiVersion 随后被 cronjob.yaml 以apiVersion: {{ template cronjob.apiVersion . }}的方式引用。三、Chart 功能与安装方式该 Chart 的职责非常聚焦创建一个运行 Curator 的 CronJob详见 README 的 Chart Details 小节。安装命令incubator 版本$ helm install incubator/elasticsearch-curatorstable 版本对应的命令为$ helm install stable/elasticsearch-curator如果你需要覆盖默认参数使用--set keyvalue语法多个参数用逗号分隔$ helm install stable/elasticsearch-curator \ --set configMaps.config_yml.client.hosts[0]elasticsearch-logging-cluster \ --set cronjob.schedule0 */6 * * *四、可配置参数全解析以下是 README 中列出的全部参数及其默认值这些默认值在 values.yaml 中均有对应声明ParameterDescriptionDefaultimage.pullPolicy容器镜像拉取策略IfNotPresentimage.repository使用的容器镜像quay.io/pires/docker-elasticsearch-curatorimage.tag镜像版本标签5.5.4cronjob.scheduleCronJob 的调度表达式0 1 * * *每天凌晨 1 点cronjob.annotations添加到 CronJob 上的注解{}cronjob.concurrencyPolicy并发策略可选Allow/Forbid/Replacenilcronjob.failedJobsHistoryLimit保留的失败 Job 数量nilcronjob.successfulJobsHistoryLimit保留的成功 Job 数量nilpod.annotations添加到 Pod 上的注解{}config.elasticsearch.hosts要清理的 Elasticsearch 主机列表- CHANGEME.hostconfig.elasticsearch.portElasticsearch 连接端口9200configMaps.action_file_ymlCurator action_file.yml 内容见 values.yaml默认删除 7 天前的索引configMaps.config_ymlCurator config.yml 内容会覆盖 config 配置见 values.yamlresources资源请求与限制{}priorityClassNamePod 优先级类名nilextraVolumeMounts额外的卷挂载extraVolumes额外卷4.1 镜像参数image默认使用quay.io/pires/docker-elasticsearch-curator:5.5.4。Chart.yaml 的appVersion: 5.5.4与image.tag保持一致。stable 版本则切换为作者官方镜像untergeek/curator:5.7.6并在升级说明中强调新镜像的 Curator 可执行文件路径为/curator/curator不在 PATH 中因此 stable 模板中默认command: [/curator/curator]。4.2 CronJob 调度参数cronjobcronjob.yaml 对调度相关参数做了条件渲染spec: schedule: {{ .Values.cronjob.schedule }} {{- with .Values.cronjob.concurrencyPolicy }} concurrencyPolicy: {{ . }} {{- end }} {{- with .Values.cronjob.failedJobsHistoryLimit }} failedJobsHistoryLimit: {{ . }} {{- end }} {{- with .Values.cronjob.successfulJobsHistoryLimit }} successfulJobsHistoryLimit: {{ . }} {{- end }}默认schedule为0 1 * * *即每天凌晨 01:00 执行一次concurrencyPolicy控制上一个任务未结束时是否允许并发执行Allow允许并发、Forbid跳过、Replace终止旧的启动新的failedJobsHistoryLimit与successfulJobsHistoryLimit控制历史 Job 的保留数量可防止 Job 无限堆积。stable 版本在此基础上新增了cronjob.labels、cronjob.jobRestartPolicy默认Never与cronjob.startingDeadlineSeconds错过调度时间后的补偿重试窗口。4.3 Pod 参数与资源控制pod.annotations通过 cronjob.yaml 渲染进 Pod 模板resources直接透传到容器模板中{{ toYaml .Values.resources | indent 16 }}默认留空由用户按需配置。values.yaml 中给出了推荐示例resources: limits: cpu: 100m memory: 128Mi requests: cpu: 100m memory: 128MipriorityClassName用于设置 Pod 优先级类extraVolumes/extraVolumeMounts用于挂载额外卷典型场景是 Elasticsearch 开启 TLS 时挂载证书values.yaml 中给出了完整的示例extraVolumes: - name: es-certs secret: defaultMode: 420 secretName: es-certs extraVolumeMounts: - name: es-certs mountPath: /certs readOnly: true4.4 连接配置config.elasticsearchChart 通过config.elasticsearch.hosts主机数组默认CHANGEME.host安装前必须替换为真实主机名和config.elasticsearch.port默认9200两个参数生成 Curator 的config.yml。生成逻辑在 configmap.yaml 中config.yml: | client: hosts: - {{ range .Values.config.elasticsearch.hosts }} {{ . }} {{ end }} port: {{ .Values.config.elasticsearch.port }}注意这里只是最简单的客户端连接配置若需要 SSL、认证、URL 前缀等高级选项应使用configMaps.config_yml直接提供完整的 config.yml见 4.5。4.5 Curator 行为配置configMapsconfigMaps是 Chart 的核心配置区包含两个键configMaps.action_file_ymlCurator 动作文件action_file.yml描述做什么configMaps.config_yml完整的 Curator 配置文件config.yml描述怎么连。一旦设置 config_yml模板中的简单 config 生成逻辑将不再生效见 configmap.yaml 的{{ if .Values.configMaps.config_yml }}分支。两个文件最终会分别以action_file.yml与config.yml两个 key 写入同一 ConfigMap再由 CronJob 挂载到容器的/etc/es-curator目录容器启动命令为command: [ curator ] args: [ --config, /etc/es-curator/config.yml, /etc/es-curator/action_file.yml ]见 cronjob.yaml默认 action_file.yml 深入解读values.yaml 中默认的清理策略是删除 7 天以前、索引名带日期后缀的索引完整内容如下configMaps: action_file_yml: |- --- actions: 1: action: delete_indices description: Clean up ES by deleting old indices options: timeout_override: continue_if_exception: False disable_action: False ignore_empty_list: True filters: - filtertype: age source: name direction: older timestring: %Y.%m.%d unit: days unit_count: 7 field: stats_result: epoch: exclude: False各字段含义action: delete_indices执行删除索引动作options.timeout_override覆盖默认超时continue_if_exception控制单条失败是否继续disable_action设为 True 可演练只打印不执行ignore_empty_list: True表示过滤结果为空时直接跳过避免因无匹配索引而报错filters.filtertype: age按索引年龄过滤source: name从索引名解析时间需配合timestring: %Y.%m.%d如logstash-2026.10.01direction: olderunit: daysunit_count: 7删除 7 天前的索引。默认 config_yml注释模板解读values.yaml 中预留了完整的 config.yml 模板涵盖 SSL、认证、日志等配置可按需取消注释使用config_yml: |- --- client: hosts: - elasticsearch-logging-cluster port: 9200 url_prefix: use_ssl: True certificate: client_cert: client_key: ssl_no_validate: True http_auth: timeout: 30 master_only: False logging: loglevel: INFO logfile: logformat: default blacklist: [elasticsearch, urllib3]其中use_ssl/certificate/client_cert/client_key用于 TLS 连接http_auth用于账号认证master_only可限制只连主节点logging.blacklist可屏蔽第三方库的冗余日志。五、模板实现原理从 values 到 CronJob 的完整链路整个 Chart 的渲染链路可以概括为values.yaml提供全部默认值_helpers.tpl 提供命名辅助函数elasticsearch-curator.fullname、elasticsearch-curator.name、elasticsearch-curator.chart并负责按集群版本选择 CronJob apiVersionconfigmap.yaml 将 action_file.yml 与 config.yml 打包进名为release-elasticsearch-curator-config的 ConfigMapcronjob.yaml 创建 CronJob把 ConfigMap 以config-volume卷挂载到/etc/es-curator并执行curator --config ... action_file.yml。其中命名规则为release 名不含 chart 名时生成release-elasticsearch-curator否则直接用 release 名长度截断到 63 字符遵循 DNS 命名规范。CronJob 与 ConfigMap 通过一致的fullname模板确保互相引用正确。六、部署后的运维要点安装完成后NOTES.txt 会提示两件重要事项CronJob 不会随 Helm 卸载自动删除已生成的 Job。删除 release 后如需清理遗留 Job需手动执行kubectl -n namespace delete job -l appelasticsearch-curator,releaserelease-name该 Chart 已废弃建议改用 stable 版本。日常排障时可通过以下命令观察任务执行情况# 查看 CronJob 状态 kubectl get cronjob -l appelasticsearch-curator # 查看最近一次 Job kubectl get jobs -l appelasticsearch-curator # 查看 Job 日志 kubectl logs -l appelasticsearch-curator --tail50七、迁移至 stable 版本的差异与增强stable 目录下的 elasticsearch-curator 是在 incubator 版本基础上的重构除了镜像与命令路径变更untergeek/curator:5.7.6、/curator/curator外主要增强包括RBAC / ServiceAccount / PodSecurityPolicyrbac.enabled、psp.create、serviceAccount.create默认 true等参数适配受管集群的安全要求dryrun 演练模式dryrun: false可设为 true 让 Curator 只打印计划不真正执行便于验证 action_filehookshooks.install/hooks.upgrade可在安装/升级时以一次性 Job 方式立即执行 Curator配合templates/hooks/job.install.yamlextraInitContainers支持注入 init 容器官方注释示例展示了等待 Elasticsearch 就绪后创建 S3 快照仓库的典型场景securityContext默认runAsUser: 16以非 root 的 cron 用户运行容器env / envFromSecrets向容器注入环境变量或从 Secret 注入敏感配置。stable 版本的升级动作清单详见其 README 的 Upgrading an existing Release to a new major version 小节——升级到 2.0.0 时若硬编码过command需改为/curator/curator。八、常见使用场景小结日志索引保留默认配置即可实现删除 7 天前的索引修改unit_count即可调整保留天数TLS/认证的 Elasticsearch启用configMaps.config_yml并配合extraVolumes挂载证书错峰执行通过cronjob.schedule避开业务高峰通过concurrencyPolicy: Forbid防止任务重叠上线前演练stable 版本将dryrun设为 true或在 action_file 中设置disable_action: True。提醒本仓库已于 2020 年 11 月进入归档状态见 stable/elasticsearch-curator/README.md 的 Repo Archive Notice相关 Chart 不再更新生产环境建议关注官方 Helm 生态或 Elastic 官方提供的替代方案。赞分享【免费下载链接】charts⚠️(OBSOLETE) Curated applications for Kubernetes项目地址https://gitcode.com/gh_mirrors/chart/charts点击查看免费下载相关推荐90DaysOfDevOps 实战使用 Elasticsearch Curator 自动清理 ELK 栈过期索引90DaysOfDevOps 实战使用 Elasticsearch Curator 自动清理 ELK 栈过期索引 本文围绕 90DaysOfDevOps 仓库文档/教程Elasticsearch Curator实战使用delete_indices.yml清理过期索引Elasticsearch Curator实战使用delete_indices.yml清理过期索引 什么是Elasticsearch Curator Elas后端搜索引擎运维docker-elk 扩展实战用 Elasticsearch Curator 定时清理 logstash 索引docker elk 扩展实战用 Elasticsearch Curator 定时清理 logstash 索引 导读 本篇文章讲解 docker elk 项目日志分析可观测性运维DevOps上一篇考研笔记备份三道防线408 OneNote资料完整防护方案下一篇一文读懂Laguna-M.1-6bit架构从注意力机制到专家路由系统创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考