summaryrefslogtreecommitdiffstats
path: root/roles/openshift_logging_fluentd/templates
diff options
context:
space:
mode:
authorJosef Karasek <jkarasek@redhat.com>2017-10-03 14:17:18 +0200
committerJosef Karasek <jkarasek@redhat.com>2017-10-11 17:25:26 +0200
commitbd53ea8112dbeab5a579bf204b235f52c05203c7 (patch)
treebed2b21cc893a6162afc6a7f32f9c0427a35b40e /roles/openshift_logging_fluentd/templates
parent0db302a8eb8cef17fe20ef651cad6e4cb3308d2b (diff)
downloadopenshift-bd53ea8112dbeab5a579bf204b235f52c05203c7.tar.gz
openshift-bd53ea8112dbeab5a579bf204b235f52c05203c7.tar.bz2
openshift-bd53ea8112dbeab5a579bf204b235f52c05203c7.tar.xz
openshift-bd53ea8112dbeab5a579bf204b235f52c05203c7.zip
Add switch to enable/disable container engine's audit log being stored in ES.
If enabled, tho logs are stored in ES' operations index, accesible only by cluster admins.
Diffstat (limited to 'roles/openshift_logging_fluentd/templates')
-rw-r--r--roles/openshift_logging_fluentd/templates/fluentd.j222
1 files changed, 22 insertions, 0 deletions
diff --git a/roles/openshift_logging_fluentd/templates/fluentd.j2 b/roles/openshift_logging_fluentd/templates/fluentd.j2
index f286b0656..644b70031 100644
--- a/roles/openshift_logging_fluentd/templates/fluentd.j2
+++ b/roles/openshift_logging_fluentd/templates/fluentd.j2
@@ -172,6 +172,28 @@ spec:
value: "{{ openshift_logging_fluentd_remote_syslog_payload_key }}"
{% endif %}
+{% if audit_container_engine %}
+ - name: "AUDIT_CONTAINER_ENGINE"
+ value: "{{ audit_container_engine | lower }}"
+{% endif %}
+
+{% if audit_container_engine %}
+ - name: "NODE_NAME"
+ valueFrom:
+ fieldRef:
+ fieldPath: spec.nodeName
+{% endif %}
+
+{% if audit_log_file != '' %}
+ - name: AUDIT_FILE
+ value: "{{ audit_log_file }}"
+{% endif %}
+
+{% if audit_pos_log_file != '' %}
+ - name: AUDIT_POS_FILE
+ value: "{{ audit_pos_log_file }}"
+{% endif %}
+
volumes:
- name: runlogjournal
hostPath: