PageSourceSearch

https://archive-ce-3-14.netlify.app/assets/js/3d2bb8be.1071afd7.js

js archive-ce-3-14.netlify.app collected 2026-10-03 10:30:57 UTC 17,353 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([[3666],{3905:(e,t,r)=>{r.d(t,{Zo:()=>c,kt:()=>m});var a=r(67294);function o(e,t,r){return t in e?Object.defineProperty(e,t,{value:r,enumerable:!0,configurable:!0,writable:!0}):e[t]=r,e}function n(e,t){var r=Object.keys(e);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);t&&(a=a.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),r.push.apply(r,a)}return r}function s(e){for(var t=1;t<arguments.length;t++){var r=null!=arguments[t]?arguments[t]:{};t%2?n(Object(r),!0).forEach((function(t){o(e,t,r[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(r)):n(Object(r)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(r,t))}))}return e}function i(e,t){if(null==e)return{};var r,a,o=function(e,t){if(null==e)return{};var r,a,o={},n=Object.keys(e);for(a=0;a<n.length;a++)r=n[a],t.indexOf(r)>=0||(o[r]=e[r]);return o}(e,t);if(Object.getOwnPropertySymbols){var n=Object.getOwnPropertySymbols(e);for(a=0;a<n.length;a++)r=n[a],t.indexOf(r)>=0||Object.prototype.propertyIsEnumerable.call(e,r)&&(o[r]=e[r])}return o}var l=a.createContext({}),u=function(e){var t=a.useContext(l),r=t;return e&&(r="function"==typeof e?e(t):s(s({},t),e)),r},c=function(e){var t=u(e.components);return a.createElement(l.Provider,{value:t},e.children)},p={inlineCode:"code",wrapper:function(e){var t=e.children;return a.createElement(a.Fragment,{},t)}},d=a.forwardRef((function(e,t){var r=e.components,o=e.mdxType,n=e.originalType,l=e.parentName,c=i(e,["components","mdxType","originalType","parentName"]),d=u(r),m=o,g=d["".concat(l,".").concat(m)]||d[m]||p[m]||n;return r?a.createElement(g,s(s({ref:t},c),{},{components:r})):a.createElement(g,s({ref:t},c))}));function m(e,t){var r=arguments,o=t&&t.mdxType;if("string"==typeof e||o){var n=r.length,s=new Array(n);s[0]=d;var i={};for(var l in t)hasOwnProperty.call(t,l)&&(i[l]=t[l]);i.originalType=e,i.mdxType="string"==typeof e?e:o,s[1]=i;for(var u=2;u<n;u++)s[u]=r[u];return a.createElement.apply(null,s)}return a.createElement.apply(null,r)}d.displayName="MDXCreateElement"},63098:(e,t,r)=>{r.r(t),r.d(t,{assets:()=>c,contentTitle:()=>l,default:()=>m,frontMatter:()=>i,metadata:()=>u,toc:()=>p});var a=r(87462),o=(r(67294),r(3905)),n=r(74866),s=r(85162);const i={description:"Configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports."},l="Configure storage for logs and reports",u={unversionedId:"operations/logstorage/create-storage",id:"version-3.14/operations/logstorage/create-storage",title:"Configure storage for logs and reports",description:"Configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports.",source:"@site/calico-enterprise_versioned_docs/version-3.14/operations/logstorage/create-storage.mdx",sourceDirName:"operations/logstorage",slug:"/operations/logstorage/create-storage",permalink:"/calico-enterprise/3.14/operations/logstorage/create-storage",draft:!1,editUrl:"https://github.com/tigera/docs/edit/main/calico-enterprise_versioned_docs/version-3.14/operations/logstorage/create-storage.mdx",tags:[],version:"3.14",frontMatter:{description:"Configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports."},sidebar:"calicoEnterpriseSidebar",previous:{title:"Log storage recommendations",permalink:"/calico-enterprise/3.14/operations/logstorage/log-storage-recommendations"},next:{title:"Adjust log storage size",permalink:"/calico-enterprise/3.14/operations/logstorage/adjust-log-storage-size"}},c={},p=[{value:"Big picture",id:"big-picture",level:2},{value:"Concepts",id:"concepts",level:2},{value:"Persistent volume",id:"persistent-volume",level:3},{value:"Persistent volume claim",id:"persistent-volume-claim",level:3},{value:"Dynamic provisioner",id:"dynamic-provisioner",level:3},{value:"Storage class",id:"storage-class",level:3},{value:"Before you begin...",id:"before-you-begin",level:2},{value:"How to",id:"how-to",level:2},{value:"Create a storage class",id:"create-a-storage-class",level:3},{value:"Pre-provisioned local disks",id:"pre-provisioned-local-disks",level:4}
1,{value:"AWS EBS disks",id:"aws-ebs-disks",level:4},{value:"AKS Azure Files storage",id:"aks-azure-files-storage",level:4},{value:"GCP Persistent Disks",id:"gcp-persistent-disks",level:4},{value:"Additional resources",id:"additional-resources",level:2}],d={toc:p};function m(e){let{components:t,...r}=e;return(0,o.kt)("wrapper",(0,a.Z)({},d,r,{components:t,mdxType:"MDXLayout"}),(0,o.kt)("h1",{id:"configure-storage-for-logs-and-reports"},"Configure storage for logs and reports"),(0,o.kt)("h2",{id:"big-picture"},"Big picture"),(0,o.kt)("p",null,"Before installing Calico Enterprise, you must configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports."),(0,o.kt)("h2",{id:"concepts"},"Concepts"),(0,o.kt)("p",null,"Before configuring a storage class for Calico Enterprise, the following terms will help you understand storage interactions."),(0,o.kt)("h3",{id:"persistent-volume"},"Persistent volume"),(0,o.kt)("p",null,"Used by pods to persist storage within the cluster. Combined with ",(0,o.kt)("strong",{parentName:"p"},"persistent volume claims"),", pods can persist data across restarts and rescheduling."),(0,o.kt)("h3",{id:"persistent-volume-claim"},"Persistent volume claim"),(0,o.kt)("p",null,"Used by pods to request and mount storage volumes. The claim specifies the volume requirements for the request: size, access rights, and storage class."),(0,o.kt)("h3",{id:"dynamic-provisioner"},"Dynamic provisioner"),(0,o.kt)("p",null,"Provisions types of persistent volumes on demand. Although most managed public-cloud clusters provide a dynamic provisioner using cloud-specific storage APIs (for example, Amazon EBS or Google persistent disks), not all clusters have a dynamic provisioner."),(0,o.kt)("p",null,"When a pod makes a persistent volume claim from a storage class that uses a dynamic provisioner, the volume is automatically created. If the storage class does not use a dynamic provisioner (for example the local storage class), the volumes must be created in advance. For help, see the ",(0,o.kt)("a",{parentName:"p",href:"https://kubernetes.io/docs/concepts/storage/dynamic-provisioning/"},"Kubernetes documentation"),"."),(0,o.kt)("h3",{id:"storage-class"},"Storage class"),(0,o.kt)("p",null,"The storage provided by the cluster. Storage classes can be used with dynamic provisioners to automatically provision persistent volumes on demand, or with manually-provisioned persistent volumes. Different storage classes provide different service levels."),(0,o.kt)("h2",{id:"before-you-begin"},"Before you begin..."),(0,o.kt)("p",null,(0,o.kt)("strong",{parentName:"p"},"Review log storage recommendations")),(0,o.kt)("p",null,"Review ",(0,o.kt)("a",{parentName:"p",href:"/calico-enterprise/3.14/operations/logstorage/log-storage-recommendations"},"Log storage recommendations")," for guidance on the number of nodes and resources to configure for your environment."),(0,o.kt)("p",null,(0,o.kt)("strong",{parentName:"p"},"Determine storage support")),(0,o.kt)("p",null,"Determine the storage types that are available on your cluster. If you are using dynamic provisioning, verify it is supported.\nIf you are using local disks, you may find the ",(0,o.kt)("a",{parentName:"p",href:"https://github.com/kubernetes-sigs/sig-storage-local-static-provisioner"},"sig-storage local static provisioner")," useful. It creates and manages PersistentVolumes by watching for disks mounted in a configured directory."),(0,o.kt)("admonition",{type:"caution"},(0,o.kt)("p",{parentName:"admonition"},"Do not use the host path storage provisioner. This provisioner is not suitable for production and results in scalability issues, instability, and data loss.")),(0,o.kt)("admonition",{type:"caution"},(0,o.kt)("p",{parentName:"admonition"},"Do not use shared network file systems, such as AWS' EFS or Azure's azure-file. These file systems may result in decreases of performance and data loss.")),(0,o.kt)("h2",{id:"how-to"},"How to"),(0,o.kt)("h3",{id:"create-a-storage-class"},"Create a storage class"),(0,o.kt)("p",null,"Before installing Calico Enterprise, create a storage class named, ",(0,o.kt)("inlineCode",{parentName:"p"},"tigera-elasticsearch"),"."),(0,o.kt)("p",null,(0,o.kt)("strong",{parentName:"p"},"Examples")),(0,o.kt)("h4",{id:"pre-provisioned-local-disks"},"Pre-provisioned local disks"),(0,o.kt)("p",null,"In the following example, we create a ",(0,o.kt)("strong",{parentName:"p"},"StorageClass")," to use when explicitly adding ",(0,o.kt)("strong",{parentName:"p"},"PersistentVolumes")," for local disks. This can be performed manually, or using the ",(0,o.kt)("a",{parentName:"p",href:"https://github.com/kubernetes-sigs/sig-storage-local-static-provisioner"},"sig-storage local static provisioner"),"."),(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: storage.k8s.io/v1\nkind: StorageClass\nmetadata:\n  name: tigera-elasticsearch\nprovisioner: kubernetes.io/no-provisioner\nvolumeBindingMode: WaitForFirstConsumer\nreclaimPolicy: Retain\n")),(0,o.kt)("h4",{id:"aws-eb
1s-disks"},"AWS EBS disks"),(0,o.kt)("p",null,"In the following example for an AWS cloud provider integration, the ",(0,o.kt)("strong",{parentName:"p"},"StorageClass")," is based on ",(0,o.kt)("a",{parentName:"p",href:"https://docs.aws.amazon.com/eks/latest/userguide/ebs-csi.html"},"how your EBS disks are provisioned"),":"),(0,o.kt)(n.Z,{mdxType:"Tabs"},(0,o.kt)(s.Z,{label:"Amazon EBS CSI",value:"Amazon EBS CSI-0",mdxType:"TabItem"},(0,o.kt)("p",null,"Make sure the CSI plugin is enabled in your cluster and apply the following manifest."),(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: storage.k8s.io/v1\nkind: StorageClass\nmetadata:\n  name: tigera-elasticsearch\nprovisioner: ebs.csi.aws.com\nreclaimPolicy: Retain\nallowVolumeExpansion: true\nvolumeBindingMode: WaitForFirstConsumer\n"))),(0,o.kt)(s.Z,{label:"Legacy Kubernetes EBS driver",value:"Legacy Kubernetes EBS driver-1",mdxType:"TabItem"},(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: storage.k8s.io/v1\nkind: StorageClass\nmetadata:\n  name: tigera-elasticsearch\nprovisioner: kubernetes.io/aws-ebs\nparameters:\n  type: gp2\n  fsType: ext4\nreclaimPolicy: Retain\nallowVolumeExpansion: true\nvolumeBindingMode: WaitForFirstConsumer\n")))),(0,o.kt)("h4",{id:"aks-azure-files-storage"},"AKS Azure Files storage"),(0,o.kt)("p",null,"In the following example for an AKS cloud provider integration, the ",(0,o.kt)("strong",{parentName:"p"},"StorageClass")," tells Calico Enterprise to use LRS disks for log storage."),(0,o.kt)("admonition",{type:"note"},(0,o.kt)("p",{parentName:"admonition"},"Premium Storage is recommended for databases greater than 100GiB and for production installations.")),(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: storage.k8s.io/v1\nkind: StorageClass\nmetadata:\n  name: tigera-elasticsearch\nprovisioner: kubernetes.io/azure-disk\nparameters:\n  cachingmode: ReadOnly\n  kind: Managed\n  storageaccounttype: StandardSSD_LRS\nreclaimPolicy: Retain\nvolumeBindingMode: WaitForFirstConsumer\nallowVolumeExpansion: true\n")),(0,o.kt)("h4",{id:"gcp-persistent-disks"},"GCP Persistent Disks"),(0,o.kt)("p",null,"In the following example for a GKE cloud provider integration, the ",(0,o.kt)("strong",{parentName:"p"},"StorageClass")," tells Calico Enterprise to use the GCE Persistent Disks for log storage."),(0,o.kt)("admonition",{type:"note"},(0,o.kt)("p",{parentName:"admonition"},"There are currently two types available ",(0,o.kt)("inlineCode",{parentName:"p"},"pd-standard")," and ",(0,o.kt)("inlineCode",{parentName:"p"},"pd-ssd"),". For production deployments, we recommend using the ",(0,o.kt)("inlineCode",{parentName:"p"},"pd-ssd")," storage type.")),(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-yaml"},"apiVersion: storage.k8s.io/v1\nkind: StorageClass\nmetadata:\n  name: tigera-elasticsearch\nprovisioner: kubernetes.io/gce-pd\nparameters:\n  type: pd-ssd\n  replication-type: none\nreclaimPolicy: Retain\nvolumeBindingMode: WaitForFirstConsumer\nallowVolumeExpansion: true\n")),(0,o.kt)("h2",{id:"additional-resources"},"Additional resources"),(0,o.kt)("ul",null,(0,o.kt)("li",{parentName:"ul"},(0,o.kt)("a",{parentName:"li",href:"/calico-enterprise/3.14/operations/logstorage/adjust-log-storage-size"},"Adjust size of Elasticsearch cluster"))))}m.isMDXComponent=!0},85162:(e,t,r)=>{r.d(t,{Z:()=>s});var a=r(67294),o=r(86010);const n="tabItem_Ymn6";function s(e){let{children:t,hidden:r,className:s}=e;return a.createElement("div",{role:"tabpanel",className:(0,o.Z)(n,s),hidden:r},t)}},74866:(e,t,r)=>{r.d(t,{Z:()=>S});var a=r(87462),o=r(67294),n=r(86010),s=r(12466),i=r(76775),l=r(91980),u=r(67392),c=r(50012);function p(e){return function(e){return o.Children.map(e,(e=>{if(!e||(0,o.isValidElement)(e)&&function(e){const{props:t}=e;return!!t&&"object"==typeof t&&"value"in t}(e))return e;throw new Error(`Docusaurus error: Bad <Tabs> child <${"string"==typeof e.type?e.type:e.type.name}>: all children of the <Tabs> component should be <TabItem>, and every <TabItem> should have a unique "value" prop.`)}))?.filter(Boolean)??[]}(e).map((e=>{let{props:{value:t,label:r,attributes:a,default:o}}=e;return{value:t,label:r,attributes:a,default:o}}))}function d(e){const{values:t,children:r}=e;return(0,o.useMemo)((()=>{const e=t??p(r);return function(e){const t=(0,u.l)(e,((e,t)=>
1e.value===t.value));if(t.length>0)throw new Error(`Docusaurus error: Duplicate values "${t.map((e=>e.value)).join(", ")}" found in <Tabs>. Every value needs to be unique.`)}(e),e}),[t,r])}function m(e){let{value:t,tabValues:r}=e;return r.some((e=>e.value===t))}function g(e){let{queryString:t=!1,groupId:r}=e;const a=(0,i.k6)(),n=function(e){let{queryString:t=!1,groupId:r}=e;if("string"==typeof t)return t;if(!1===t)return null;if(!0===t&&!r)throw new Error('Docusaurus error: The <Tabs> component groupId prop is required if queryString=true, because this value is used as the search param name. You can also provide an explicit value such as queryString="my-search-param".');return r??null}({queryString:t,groupId:r});return[(0,l._X)(n),(0,o.useCallback)((e=>{if(!n)return;const t=new URLSearchParams(a.location.search);t.set(n,e),a.replace({...a.location,search:t.toString()})}),[n,a])]}function f(e){const{defaultValue:t,queryString:r=!1,groupId:a}=e,n=d(e),[s,i]=(0,o.useState)((()=>function(e){let{defaultValue:t,tabValues:r}=e;if(0===r.length)throw new Error("Docusaurus error: the <Tabs> component requires at least one <TabItem> children component");if(t){if(!m({value:t,tabValues:r}))throw new Error(`Docusaurus error: The <Tabs> has a defaultValue "${t}" but none of its children has the corresponding value. Available values are: ${r.map((e=>e.value)).join(", ")}. If you intend to show no default tab, use defaultValue={null} instead.`);return t}const a=r.find((e=>e.default))??r[0];if(!a)throw new Error("Unexpected error: 0 tabValues");return a.value}({defaultValue:t,tabValues:n}))),[l,u]=g({queryString:r,groupId:a}),[p,f]=function(e){let{groupId:t}=e;const r=function(e){return e?`docusaurus.tab.${e}`:null}(t),[a,n]=(0,c.Nk)(r);return[a,(0,o.useCallback)((e=>{r&&n.set(e)}),[r,n])]}({groupId:a}),v=(()=>{const e=l??p;return m({value:e,tabValues:n})?e:null})();(0,o.useLayoutEffect)((()=>{v&&i(v)}),[v]);return{selectedValue:s,selectValue:(0,o.useCallback)((e=>{if(!m({value:e,tabValues:n}))throw new Error(`Can't select invalid tab value=${e}`);i(e),u(e),f(e)}),[u,f,n]),tabValues:n}}var v=r(72389);const h="tabList__CuJ",k="tabItem_LNqP";function y(e){let{className:t,block:r,selectedValue:i,selectValue:l,tabValues:u}=e;const c=[],{blockElementScrollPositionUntilNextRender:p}=(0,s.o5)(),d=e=>{const t=e.currentTarget,r=c.indexOf(t),a=u[r].value;a!==i&&(p(t),l(a))},m=e=>{let t=null;switch(e.key){case"Enter":d(e);break;case"ArrowRight":{const r=c.indexOf(e.currentTarget)+1;t=c[r]??c[0];break}case"ArrowLeft":{const r=c.indexOf(e.currentTarget)-1;t=c[r]??c[c.length-1];break}}t?.focus()};return o.createElement("ul",{role:"tablist","aria-orientation":"horizontal",className:(0,n.Z)("tabs",{"tabs--block":r},t)},u.map((e=>{let{value:t,label:r,attributes:s}=e;return o.createElement("li",(0,a.Z)({role:"tab",tabIndex:i===t?0:-1,"aria-selected":i===t,key:t,ref:e=>c.push(e),onKeyDown:m,onClick:d},s,{className:(0,n.Z)("tabs__item",k,s?.className,{"tabs__item--active":i===t})}),r??t)})))}function b(e){let{lazy:t,children:r,selectedValue:a}=e;const n=(Array.isArray(r)?r:[r]).filter(Boolean);if(t){const e=n.find((e=>e.props.value===a));return e?(0,o.cloneElement)(e,{className:"margin-top--md"}):null}return o.createElement("div",{className:"margin-top--md"},n.map(((e,t)=>(0,o.cloneElement)(e,{key:t,hidden:e.props.value!==a}))))}function w(e){const t=f(e);return o.createElement("div",{className:(0,n.Z)("tabs-container",h)},o.createElement(y,(0,a.Z)({},e,t)),o.createElement(b,(0,a.Z)({},e,t)))}function S(e){const t=(0,v.Z)();return o.createElement(w,(0,a.Z)({key:String(t)},e))}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.