Kubernetes with Helm¶
The Logstrm Helm chart deploys the Data Plane and optional Manager. It supports Data Plane Deployment or node-local DaemonSet mode, health probes, and persistent Manager state. Obtain the chart, image references, version compatibility information, and registry access instructions from the Logstrm distribution channel provided to your organization. This guide does not assume a public chart repository or anonymously accessible images.
Prerequisites¶
- Kubernetes 1.25+ and Helm 3.12+;
- the Logstrm chart and supported Data Plane/Manager images for the same release;
- registry credentials if the supplied images are private;
- a dynamic StorageClass for Manager persistence, unless using a pre-created PVC;
- an approved secret-management method for the Data Plane hot-reload token and emitter credentials.
Install¶
Set LOGSTRM_CHART to the chart reference or local chart package supplied with your distribution, and LOGSTRM_VERSION to its matching release version. Configure image repositories and tags to the exact values supplied for that release. The example leaves these as explicit inputs rather than presenting placeholder coordinates as downloadable artifacts.
The Data Plane Service defaults to ClusterIP, so its API and ingestion ports are internal to the Kubernetes cluster. If external sources must connect directly, use a private ingress or LoadBalancer with TLS termination and network restrictions. Direct LoadBalancer exposure is an explicit opt-in:
--set dataplane.service.type=LoadBalancer
The chart also requires hot-reload authentication. Create the logstrm-hot-reload Secret before installation, as shown below; chart rendering fails if neither a Secret reference nor a demo token is configured. If the referenced Secret or key is absent, both workloads fail to start rather than running with unauthenticated reload.
export LOGSTRM_CHART='<chart reference supplied with your distribution>'
export LOGSTRM_VERSION='<supported release version>'
export LOGSTRM_IMAGE_REPOSITORY='<Data Plane image repository>'
export LOGSTRM_MANAGER_IMAGE_REPOSITORY='<Manager image repository>'
helm upgrade --install logstrm "$LOGSTRM_CHART" \
--namespace logstrm \
--create-namespace \
--set images.logstrm.repository="$LOGSTRM_IMAGE_REPOSITORY" \
--set images.manager.repository="$LOGSTRM_MANAGER_IMAGE_REPOSITORY" \
--set images.logstrm.tag="$LOGSTRM_VERSION" \
--set images.manager.tag="$LOGSTRM_VERSION" \
--set dataplane.hotReload.existingSecret=logstrm-hot-reload
Create logstrm-hot-reload through your secret manager or approved Kubernetes secret workflow before installation, using the key expected by the supplied chart version (hot-reload-token by default). Use a high-entropy token of at least 32 random bytes and ensure the secret value has no trailing newline. Do not put token values in shell history or commit them to a values file. Configure registry pull credentials as documented by your registry and chart distribution.
AKS Workload Identity¶
For Sentinel DCR emitters with auth_mode: workload_identity, enable the chart's AKS Workload Identity wiring so the webhook projects a federated token into the Data Plane pods:
helm upgrade --install logstrm "$LOGSTRM_CHART" \
--namespace logstrm \
--create-namespace \
--set dataplane.hotReload.existingSecret=logstrm-hot-reload \
--set serviceAccount.workloadIdentity.enabled=true \
--set serviceAccount.workloadIdentity.clientID='<federated-identity-client-id>'
With serviceAccount.workloadIdentity.enabled=true the chart adds the azure.workload.identity/use: "true" pod label to both workloads and forces automountServiceAccountToken: true, which the AKS webhook requires to project the service account token. Setting clientID adds the azure.workload.identity/client-id annotation to the ServiceAccount; omit it when the webhook should use its default client ID mapping.
Cluster prerequisites: an AKS cluster with the OIDC issuer and the Workload Identity add-on enabled, an Entra managed identity with a federated identity credential bound to the release's ServiceAccount (namespace logstrm, service account logstrm by default), and the Monitoring Metrics Publisher role for that identity scoped to the Data Collection Rule. The Data Plane resolves AZURE_CLIENT_ID, AZURE_TENANT_ID and AZURE_FEDERATED_TOKEN_FILE from the webhook and fails at startup when any of them cannot be resolved.
The AKS Workload Identity path has been smoke-tested end-to-end with one schema-matched event confirmed in a custom Log Analytics table. This validates the basic federated-authentication and delivery path only; it is not a capacity, resilience or production-readiness result. See the Sentinel DCR validation notes.
Operational checks¶
kubectl rollout status deployment/logstrm-dataplane -n logstrm
kubectl get pods,svc,pvc -n logstrm
The Data Plane exposes /api/v1/ready for readiness and /api/v1/health for liveness. Readiness returns 503 during graceful drain while liveness remains healthy. The Manager uses /api/v1/health. Keep the Manager PVC backed up; it contains configuration history and rollout state.
Security baseline¶
Use the release's supported non-root images, read-only filesystems, dropped capabilities, image pull secrets for private registries, and network policies restricting access and egress. Do not expose profiling or benchmark-only listeners through a public Service. Inject emitter credentials using an approved secret-management mechanism, not chart values or ConfigMaps. serviceAccount.automountServiceAccountToken stays false unless explicitly enabled; the AKS Workload Identity wiring is the documented exception and forces it to true together with the azure.workload.identity/use pod label.
Upgrade note: the chart's Data Plane Service default changed from LoadBalancer to ClusterIP, and hot-reload authentication is now mandatory. Before upgrading, create a Kubernetes Secret with the existing reload token and set dataplane.hotReload.existingSecret. If migrating from a chart-managed dataplane.hotReload.token, clear that value when switching to the Secret. Also set dataplane.service.type=LoadBalancer if the release relies on its external Service IP. Otherwise, chart rendering may fail or external ingestion clients may lose connectivity.