Amazon DocumentDB용 Database Monitoring 설정하기
Database Monitoring은 핵심 메트릭, 작업 샘플, 실행 계획, 복제 상태 변경에 대한 접근을 제공해 Amazon DocumentDB(MongoDB 호환) 데이터베이스에 대한 포괄적인 인사이트를 제공해요. Amazon DocumentDB용 Database Monitoring을 활용하려면 Datadog Agent가 설치되고 Amazon DocumentDB 인스턴스에 연결되도록 구성되었는지 확인하세요. 이 가이드는 Amazon DocumentDB용 Database Monitoring을 설정하는 단계를 안내해요.
출처: 문서
본문
시작하기 전에
지원되는 Amazon DocumentDB 메이저 버전: 4.0.0, 5.0.0
지원되는 Amazon DocumentDB 클러스터 유형: 인스턴스 기반 클러스터. 참고: Amazon DocumentDB Elastic cluster는 지원되지 않아요.
지원되는 Agent 버전: 7.59.0+
성능 영향: Database Monitoring의 기본 Agent 구성은 보수적이지만, 수집 간격과 작업 샘플링 비율 같은 설정을 필요에 맞게 조정할 수 있어요. 대부분의 워크로드에서 에이전트는 데이터베이스의 쿼리 실행 시간의 1% 미만, CPU의 1% 미만을 차지해요.
연결 문자열 또는 SRV 문자열: Amazon DocumentDB 연결 문자열은 자동 페일오버와 부하 분산 같은 많은 이점을 제공하지만, Datadog Agent는 모니터링되는 DocumentDB 인스턴스에 직접 연결해야 해요. 에이전트가 실행 중에 다른 DocumentDB 인스턴스에 연결하면(페일오버, 부하 분산 등의 경우) 에이전트는 두 호스트 간의 통계 차이를 계산해 부정확한 메트릭을 생성해요.
데이터 보안 고려 사항: 에이전트가 데이터베이스에서 수집하는 데이터와 이를 안전하게 유지하는 방법에 대한 정보는 Database Management가 민감한 정보를 처리하는 방법을 읽어보세요.
설정 (Setup)
데이터베이스에 Database Monitoring을 활성화하려면:
- 에이전트에 Amazon DocumentDB 인스턴스 접근 권한 부여
- 에이전트 설치 및 구성
- (선택) Amazon DocumentDB 통합 설치
에이전트에 Amazon DocumentDB 인스턴스 접근 권한 부여
Datadog Agent는 통계와 쿼리를 수집하려면 Amazon DocumentDB 인스턴스에 대한 읽기 전용 접근이 필요해요.
Mongo 셸에서 복제본 세트의 주(primary) 노드에 인증하고, admin 데이터베이스에 Datadog Agent용 읽기 전용 사용자를 만든 다음 필요한 권한을 부여하세요:
# Authenticate as the admin user.
use admin
db.auth("admin", "<YOUR_AMAZON_DOCUMENTDB_ADMIN_PASSWORD>")
# Create the user for the Datadog Agent.
db.createUser({
"user": "datadog",
"pwd": "<UNIQUE_PASSWORD>",
"roles": [
{ role: "read", db: "admin" },
{ role: "read", db: "local" },
{ role: "clusterMonitor", db: "admin" }
]
})
모니터링하려는 데이터베이스에서 datadog 사용자에게 추가 권한을 부여하세요:
db.grantRolesToUser("datadog", [
{ role: "read", db: "mydatabase" },
{ role: "read", db: "myotherdatabase" }
])
또는 admin 데이터베이스에서 datadog 사용자에게 readAnyDatabase 역할을 부여해 모든 데이터베이스를 모니터링할 수 있어요:
db.grantRolesToUser("datadog", [
{ role: "readAnyDatabase", db: "admin" }
])
비밀번호 안전하게 저장하기
Vault 같은 비밀 관리 소프트웨어로 비밀번호를 저장하세요. 그러면 에이전트 구성 파일에서 이 비밀번호를 ENC[<SECRET_NAME>]로 참조할 수 있어요. 예: ENC[datadog_user_database_password]. 자세한 내용은 Secrets Management를 참고하세요.
이 페이지의 예시는 비밀번호가 저장된 비밀의 이름을 나타내기 위해 datadog_user_database_password를 사용해요. 비밀번호를 평문으로 참조할 수도 있지만 권장하지 않아요.
에이전트 설치 및 구성
Amazon DocumentDB Cluster를 모니터링하려면 Amazon DocumentDB Cluster에 원격으로 접근할 수 있는 호스트에 Datadog Agent를 설치하고 구성해야 해요. 이 호스트는 Linux 호스트, Docker 컨테이너, Kubernetes 파드일 수 있어요.
구성 파일 만들기
Amazon DocumentDB 복제본 세트를 모니터링하려면 에이전트는 복제본 세트의 모든 멤버(arbiter 포함)에 연결해야 해요.
다음 구성 블록을 예시로 사용해 에이전트가 복제본 세트 멤버에 연결하도록 구성하세요:
init_config:
instances:
## @param hosts - required
## Specify the hostname, IP address, or UNIX domain socket of
## a mongod instance as listed in the replica set configuration.
## If the port number is not specified, the default port 27017 is used.
#
- hosts:
- <HOST>:<PORT>
## @param username - string - optional
## The username to use for authentication.
#
username: datadog
## @param password - string - optional
## The password to use for authentication.
#
password: 'ENC[datadog_user_database_password]'
## @param options - mapping - optional
## Connection options. For a complete list, see:
## https://docs.mongodb.com/manual/reference/connection-string/#connections-connection-options
#
options:
authSource: admin
## @param tls - boolean - required
## Required 'true' in Amazon DocumentDB.
tls: true
## @param tls_ca_file - string - required
## Path to the CA certificate file used to verify the server certificate.
tls_ca_file: <CERT_FILE_PATH>
## @param dbm - boolean - optional
## Set to true to enable Database Monitoring.
#
dbm: true
## @param cluster_name - string - optional
## The unique name of the cluster to which the monitored MongoDB instance belongs.
## Used to group MongoDB instances in a MongoDB cluster.
## cluster_name should follow Datadog tags naming conventions. See:
## https://docs.datadoghq.com/extend/guide/what-best-practices-are-recommended-for-naming-metrics-and-tags/#rules-and-best-practices-for-naming-tags
## Required when `dbm` is enabled.
#
cluster_name: <MONGO_CLUSTER_NAME>
## @param reported_database_hostname - string - optional
## Set the reported database hostname for the connected MongoDB instance.
## This value overrides the MongoDB hostname detected by the Agent
## from the MongoDB admin command serverStatus.host.
#
reported_database_hostname: <DATABASE_HOSTNAME_OVERRIDE>
## @param additional_metrics - list of strings - optional
## List of additional metrics to collect. Available options are:
## - metrics.commands: Use of database commands
## - tcmalloc: TCMalloc memory allocator
## - top: Usage statistics for each collection
## - collection: Metrics of the specified collections
#
additional_metrics: ['metrics.commands', 'tcmalloc', 'top', 'collection']
## @param collections_indexes_stats - boolean - optional
## Set to true to collect index statistics for the specified collections.
## Requires `collections` to be set.
#
collections_indexes_stats: true
## @param database_autodiscovery - mapping - optional
## Enable database autodiscovery to automatically collect metrics from all your MongoDB databases.
#
database_autodiscovery:
## @param enabled - boolean - required
## Enable database autodiscovery.
#
enabled: true
## @param include - list of strings - optional
## List of databases to include in the autodiscovery. Use regular expressions to match multiple databases.
## For example, to include all databases starting with "mydb", use "^mydb.*".
## By default, include is set to ".*" and all databases are included.
#
include:
- '^mydb.*'
## @param exclude - list of strings - optional
## List of databases to exclude from the autodiscovery. Use regular expressions to match multiple databases.
## For example, to exclude all databases starting with "mydb", use "^mydb.*".
## When the exclude list conflicts with include list, the exclude list takes precedence.
#
exclude:
- '^mydb2.*'
- 'admin$'
## @param max_databases - integer - optional
## Maximum number of databases to collect metrics from. The default value is 100.
#
max_databases: 100
## @param refresh_interval - integer - optional
## Interval in seconds to refresh the list of databases. The default value is 600 seconds.
#
refresh_interval: 600
주(primary) 1개와 보조(secondary) 2개가 있는 복제본 세트에 대한 예시 구성은 다음과 같아요:
init_config:
instances:
- hosts:
- <HOST_REPLICA_1>:<PORT> # Primary node
username: datadog
password: 'ENC[datadog_user_database_password]'
options:
authSource: admin
tls: true
tls_ca_file: <CERT_FILE_PATH>
dbm: true
cluster_name: <MONGO_CLUSTER_NAME>
reported_database_hostname: <DATABASE_HOSTNAME_OVERRIDE>
additional_metrics: ['metrics.commands', 'tcmalloc', 'top', 'collection']
collections_indexes_stats: true
database_autodiscovery:
enabled: true
- hosts:
- <HOST_REPLICA_2>:<PORT> # Secondary node
username: datadog
password: 'ENC[datadog_user_database_password]'
options:
authSource: admin
tls: true
tls_ca_file: <CERT_FILE_PATH>
dbm: true
cluster_name: <MONGO_CLUSTER_NAME>
reported_database_hostname: <DATABASE_HOSTNAME_OVERRIDE>
additional_metrics: ['metrics.commands', 'tcmalloc', 'top', 'collection']
collections_indexes_stats: true
database_autodiscovery:
enabled: true
- hosts:
- <HOST_REPLICA_3>:<PORT> # Secondary node
username: datadog
password: 'ENC[datadog_user_database_password]'
options:
authSource: admin
tls: true
tls_ca_file: <CERT_FILE_PATH>
dbm: true
cluster_name: <MONGO_CLUSTER_NAME>
reported_database_hostname: <DATABASE_HOSTNAME_OVERRIDE>
additional_metrics: ['metrics.commands', 'tcmalloc', 'top', 'collection']
collections_indexes_stats: true
database_autodiscovery:
enabled: true
Amazon DocumentDB 통합 텔레메트리로 인스턴스를 풍부하게 하기 위해 Amazon DocumentDB 통합을 설치했다면 구성에 이 섹션을 추가하세요:
## @param aws - mapping - optional
## This block defines the configuration for Amazon DocumentDB instances.
## These values are only applied when `dbm: true` option is set.
#
aws:
## @param instance_endpoint - string - optional
## Equal to the Endpoint.Address of the instance the Agent is connecting to.
## This value is optional if the value of `host` is already configured to the instance endpoint.
##
## For more information on instance endpoints,
## see the AWS docs https://docs.aws.amazon.com/documentdb/latest/developerguide/API_Endpoint.html
#
instance_endpoint: <AMAZON_DOCUMENTDB_ENDPOINT>
## @param cluster_identifier - string - optional
## Equal to the cluster identifier of the instance the Agent is connecting to.
## This value is optional if the value of `cluster_name` is already configured to the cluster identifier.
##
## For more information on cluster identifiers,
## see the AWS docs https://docs.aws.amazon.com/documentdb/latest/developerguide/API_DBCluster.html
#
cluster_identifier: <AMAZON_DOCUMENTDB_CLUSTER_IDENTIFIER>
에이전트 설정하기
Linux 호스트
이전 단계에서 만든 MongoDB Agent 구성 파일을 /etc/datadog-agent/conf.d/mongo.d/conf.yaml에 넣으세요. 사용 가능한 모든 구성 옵션은 샘플 conf 파일을 참고하세요.
모든 Agent 구성이 완료되면 Datadog Agent를 재시작하세요.
검증
Agent의 status 하위 명령을 실행하고 Checks 섹션에서 mongo를 찾으세요. 시작하려면 Datadog의 MongoDB용 Database Monitoring 페이지로 이동하세요.
Docker
Docker 컨테이너에서 실행되는 Database Monitoring Agent를 구성하려면 Autodiscovery Integration Templates을 Agent 컨테이너의 Docker 라벨로 설정하세요.
MongoDB 체크는 Datadog Agent에 포함되어 있어요. 추가 설치가 필요하지 않아요.
참고: 라벨의 자동탐지(autodiscovery)가 작동하려면 에이전트가 Docker 소켓에 대한 읽기 권한이 있어야 해요.
이전 단계의 MongoDB 체크 구성 세부 정보를 com.datadoghq.ad.checks 라벨에 추가하세요. 사용 가능한 모든 구성 옵션은 샘플 conf 파일을 참고하세요.
export DD_API_KEY=<DD_API_KEY>
export DD_AGENT_VERSION=7.58.0
docker run -e "DD_API_KEY=${DD_API_KEY}" \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
-l com.datadoghq.ad.checks='{
"mongo": {
"init_config": {},
"instances": [{
"hosts": ["<HOST>:<PORT>"],
"username": "datadog",
"password": "<UNIQUE_PASSWORD>",
"options": {
"authSource": "admin"
},
"dbm": true,
"cluster_name": "<MONGO_CLUSTER_NAME>",
"reported_database_hostname": "<DATABASE_HOSTNAME_OVERRIDE>",
"additional_metrics": ["metrics.commands", "tcmalloc", "top", "collection"],
"collections_indexes_stats": true,
"database_autodiscovery": {
"enabled": true
}
}]
}
}' \
registry.datadoghq.com/agent:${DD_AGENT_VERSION}
검증
Agent의 status 하위 명령을 실행하고 Checks 섹션에서 mongo를 찾으세요. 시작하려면 Datadog의 MongoDB용 Database Monitoring 페이지로 이동하세요.
Kubernetes
Kubernetes 클러스터가 있다면 Database Monitoring에 Datadog Cluster Agent를 사용하세요.
Kubernetes 클러스터에서 클러스터 체크가 아직 활성화되지 않았다면 클러스터 체크 활성화 지침을 따르세요. Cluster Agent를 Cluster Agent 컨테이너에 마운트된 정적 파일로 구성하거나, Kubernetes 서비스 어노테이션으로 구성할 수 있어요.
Helm으로 명령줄 구성
다음 Helm 명령을 실행해 Kubernetes 클러스터에 Datadog Cluster Agent를 설치하세요. 계정과 환경에 맞게 값을 교체하세요:
helm repo add datadog https://helm.datadoghq.com
helm repo update
helm install <RELEASE_NAME> \
--set 'datadog.apiKey=<DATADOG_API_KEY>' \
--set 'clusterAgent.enabled=true' \
--set 'clusterChecksRunner.enabled=true' \
--set 'clusterAgent.confd.mongo\.yaml=cluster_check: true
init_config:
instances:
- hosts:
- <HOST>:<PORT>
username: datadog
password: <UNIQUE_PASSWORD>
options:
authSource: admin
dbm: true
cluster_name: <MONGO_CLUSTER_NAME>
reported_database_hostname: <DATABASE_HOSTNAME_OVERRIDE>
database_autodiscovery:
enabled: true
additional_metrics: ["metrics.commands", "tcmalloc", "top", "collection"]
collections_indexes_stats: true' \
datadog/datadog
마운트된 파일로 구성
마운트된 구성 파일로 클러스터 체크를 구성하려면 구성 파일을 Cluster Agent 컨테이너의 /conf.d/mongo.yaml 경로에 마운트하세요:
cluster_check: true # Make sure to include this flag
init_config:
instances:
- hosts:
- <HOST>:<PORT>
username: datadog
password: "ENC[datadog_user_database_password]"
options:
authSource: admin
dbm: true
cluster_name: <MONGO_CLUSTER_NAME>
reported_database_hostname: <DATABASE_HOSTNAME_OVERRIDE>
database_autodiscovery:
enabled: true
additional_metrics: ["metrics.commands", "tcmalloc", "top", "collection"]
collections_indexes_stats: true
Kubernetes 서비스 어노테이션으로 구성
파일을 마운트하는 대신 인스턴스 구성을 Kubernetes Service로 선언할 수 있어요. Kubernetes에서 실행되는 Agent에 대해 이 체크를 구성하려면 Datadog Cluster Agent와 같은 네임스페이스에 Service를 만드세요:
apiVersion: v1
kind: Service
metadata:
name: mongodb-datadog-check-instances
annotations:
ad.datadoghq.com/service.checks: |
{
"mongo": {
"init_config": {},
"instances": [{
"hosts": ["<HOST>:<PORT>"],
"username": "datadog",
"password": "ENC[datadog_user_database_password]",
"options": {
"authSource": "admin"
},
"dbm": true,
"cluster_name": "<MONGO_CLUSTER_NAME>",
"reported_database_hostname": "<DATABASE_HOSTNAME_OVERRIDE>",
"additional_metrics": ["metrics.commands", "tcmalloc", "top", "collection"],
"collections_indexes_stats": true,
"database_autodiscovery": {
"enabled": true
}
}]
}
}
spec:
ports:
- port: 27017
protocol: TCP
targetPort: 27017
name: mongodb
Cluster Agent는 이 구성을 자동으로 등록하고 MongoDB 통합 실행을 시작해요.
datadog 사용자의 비밀번호를 평문으로 노출하지 않으려면 에이전트의 비밀 관리 패키지를 사용하고 ENC[] 구문으로 비밀번호를 선언하세요.
검증
Agent의 status 하위 명령을 실행하고 Checks 섹션에서 mongo를 찾으세요. 시작하려면 Datadog의 MongoDB용 Database Monitoring 페이지로 이동하세요.
Amazon DocumentDB 통합 설치
Amazon DocumentDB에서 더 포괄적인 데이터베이스 메트릭을 수집하려면 Amazon DocumentDB 통합을 설치하세요 (선택).
수집되는 데이터 (Data collected)
메트릭 (Metrics)
통합이 수집하는 메트릭의 포괄적인 목록은 통합 문서를 참고하세요.
작업 샘플과 실행 계획
Amazon DocumentDB용 Database Monitoring은 currentOp 명령을 사용해 작업 샘플을 수집해요. 이 명령은 DocumentDB 인스턴스에서 현재 실행 중인 작업에 대한 정보를 제공해요. 또한 Database Monitoring은 explain 명령을 사용해 읽기 작업 샘플에 대한 실행 계획을 수집해 쿼리 실행 계획에 대한 자세한 인사이트를 제공해요.
복제 상태 변경
Amazon DocumentDB용 Database Monitoring은 DocumentDB 인스턴스 내에서 복제 상태에 변화가 있을 때마다 이벤트를 생성해요. 이를 통해 복제의 변경 사항이 신속하게 감지되고 보고되도록 보장해요.
스키마와 인덱스 수집
Amazon DocumentDB용 Database Monitoring은 Amazon DocumentDB 컬렉션의 추론된 스키마와 인덱스를 수집해요. 이 정보는 컬렉션의 구조와 구성을 이해하는 데 인사이트를 제공해요.
Amazon DocumentDB 컬렉션을 분석할 때 Datadog는 $sample 집계 단계로 문서를 샘플링해 추론된 스키마 정보를 수집해요. 이 분석에서 필드 이름, 필드 출현 빈도(각 필드가 나타나는 빈도), 각각의 데이터 타입 같은 스키마에 대한 메타데이터만 수집되어 Datadog로 전송돼요. Datadog는 문서의 실제 내용이나 고객 비즈니스 데이터를 수집하거나 전송하지 않아요. 이를 통해 민감한 데이터를 보호하면서도 컬렉션의 구조와 구성에 대한 유용한 인사이트를 제공할 수 있어요.