Description
If the TKE log agent is disabled and no alternative collector is used, container logs may be difficult to access centrally.
Potential impact
Application logs needed for outage or security investigations may be unavailable after Pods terminate.
Remediation
Set enabled = true in log_agent on tencentcloud_kubernetes_cluster, then configure collection rules and destinations. Verify delivery, retention, and access permissions.
Examples
These excerpts enable the log agent and omit other cluster settings and collection rules. Audit logging and event persistence are separate settings.
Before
hcl
resource "tencentcloud_kubernetes_cluster" "example" {
cluster_name = "test"
cluster_deploy_type = "MANAGED_CLUSTER"
log_agent {
enabled = false
}
}
After
hcl
resource "tencentcloud_kubernetes_cluster" "example" {
cluster_name = "test"
cluster_deploy_type = "MANAGED_CLUSTER"
log_agent {
enabled = true
}
}