Creating a trigger for Cloud Logging that invokes a container from Serverless Containers
Create a trigger for Cloud Logging that invokes a container from Serverless Containers whenever entries are added to the log group.
Getting started
To create a trigger, you will need:
-
Container the trigger will invoke. If you do not have a container:
-
Optionally, a dead-letter queue for unprocessed messages from the container. If you do not have a queue, create one.
-
Service account with permissions to invoke the container and, optionally, write to the dead-letter queue. You can use the same service account or different ones. If you do not have a service account, create one.
- Log group whose new entries will set off the trigger. If you do not have a log group, create one.
Creating a trigger
Note
The trigger is initiated within five minutes after it is created.
-
In the management console
, select the folder where you want to create your trigger. -
Navigate
to Serverless Containers. -
In the left-hand panel, select
Triggers. -
Click Create trigger.
-
Under Basic settings:
-
Enter a name and description for the trigger.
-
In the Labels field, click Add label and specify the labels in
key: valueformat. -
In the Type field, select
Cloud Logging.
-
-
Under Cloud Logging settings, specify the following:
- Log group.
- Optionally, types of resources, e.g.,
serverless.functionin Cloud Functions. - Optionally, IDs of your resources or Yandex Cloud resources, e.g., functions in Cloud Functions.
- Optionally, log streams.
- Optionally, logging levels.
A trigger fires when the specified log group receives entries that comply with all of the optional settings. If the optional setting is not specified, the trigger fires for any value.
-
Under Batch message settings, specify the following:
- Waiting time, s. The values may range from 1 to 60 seconds. The default value is 1 second.
- Batch size. The values may range from 1 to 1,000. The default value is 1.
The trigger groups events within the specified wait time and sends them to the target. The number of events cannot exceed the specified batch size.
-
Under Targets:
-
In the Target type field, select
Container. -
Under Container settings, select a container and specify a service account that will invoke it.
-
Optionally, under Repeat request settings:
- In the Interval field, specify the time to wait before retrying the container invocation if it fails. The values may range from 10 to 60 seconds. The default value is 10 seconds.
- In the Number of attempts field, specify the number of invocation retries before the trigger moves a message to the dead-letter queue. The values may range from 1 to 5. The default value is 1.
-
Optionally, under Dead Letter Queue settings, select a dead-letter queue and a service account with write permissions for that queue.
-
Optionally, in the Filter field, specify a jq template to filter events sent to the target. If no filter is specified, all events are sent to the target.
-
Optionally, in the Transformation template field, specify a
jqtemplate to transform events before sending them to the target. If no template is specified, no transformations apply to the events.
-
-
Click Create trigger.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
To create a trigger that invokes a container, run this command:
yc serverless trigger create logging \
--name <trigger_name> \
--log-group-name <log_group_name> \
--batch-size <message_group_size> \
--batch-cutoff <maximum_timeout> \
--resource-ids <resource_ID> \
--resource-types <resource_type> \
--stream-names <log_stream> \
--log-levels <logging_level> \
--invoke-container-id <container_ID> \
--invoke-container-service-account-id <service_account_ID> \
--retry-attempts <number_of_retry_attempts> \
--retry-interval <interval_between_retry_attempts> \
--dlq-queue-id <dead-letter_queue_ID> \
--dlq-service-account-id <service_account_ID>
Where:
--name: Trigger name.--log-group-name: Name of the log group whose new log entries will invoke the container.
--batch-size: Message batch size. This is an optional setting. The values may range from 1 to 10. The default value is 1.--batch-cutoff: Maximum wait time. This is an optional setting. The values may range from 1 to 60 seconds. The default value is 1 second. The trigger groups messages within thebatch-cutoffperiod and sends them to the container. The number of messages cannot exceedbatch-size.
--resource-ids: IDs of your resources or Yandex Cloud resources, e.g., functions in Cloud Functions. This is an optional setting.--resource-types: Types of resources, e.g.,serverless.functionin Cloud Functions. This is an optional setting.--stream-names: Log streams. This is an optional setting.--log-levels: Logging levels. This is an optional setting.
A trigger fires when the specified log group receives entries that comply with all of the following settings:resource-ids,resource-types,stream-names, andlog-levels. If the setting is not specified, the trigger fires for any value.
--invoke-container-id: Container ID.--invoke-container-service-account-id: ID of the service account with permissions to invoke the container.--retry-attempts: Number of invocation retries before the trigger moves a message to the dead-letter queue. This is an optional setting. The values may range from 1 to 5. The default value is 1.--retry-interval: Time to wait before retrying the container invocation if it fails. This is an optional setting. The values may range from 10 to 60 seconds. The default value is 10 seconds.--dlq-queue-id: Dead-letter queue ID. This is an optional setting.--dlq-service-account-id: ID of the service account with write permissions for the dead-letter queue. This is an optional setting.
Result:
id: a1s5msktijh2********
folder_id: b1gmit33hgh2********
created_at: "2022-10-24T15:19:15.353909857Z"
name: logging-trigger
rule:
logging:
log_group_id: e23bidnftlh2********
resource_type:
- serverless.functions
resource_id:
- d4e1gpsgam78********
stream_name:
- test
levels:
- INFO
batch_settings:
size: "1"
cutoff: 1s
invoke_container:
container_id: bba5jb38o8h2********
service_account_id: aje03adgd2h2********
retry_settings:
retry_attempts: "1"
interval: 10s
dead_letter_queue:
queue-id: yrn:yc:ymq:ru-central1:b1gmit33ngh2********:dlq
service-account-id: aje3lebfemh2********
status: ACTIVE
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
To create a trigger for Cloud Logging:
-
Describe the trigger in the configuration file:
resource "yandex_serverless_triggers" "my_trigger" { name = "<trigger_name>" source { logging { log_group_id = "<log_group_ID>" resource_type = [ "<resource_type>" ] resource_id = [ "<resource_ID>" ] stream_name = [ "<log_stream>" ] levels = [ "<logging_level>", "<logging_level>" ] batch_settings { max_count = "<max_number_of_messages>" max_bytes = "<max_group_size_in_bytes>" cutoff = "<maximum_wait_time>" } } } action { invoke_container { container_id = "<container_ID>" path = "<HTTP_path>" service_account_id = "<service_account_ID>" } retry_policy { retry_attempts = "<number_of_retries>" interval = "<interval_between_retries>" } dead_letter { dead_letter_queue { queue_arn = "<Dead_Letter_Queue_ARN>" service_account_id = "<service_account_ID>" } } } }Where:
-
name: Trigger name. The name format is as follows:- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
-
description: Trigger description. This is an optional parameter. -
labels: Trigger labels inkey:valueformat. This is an optional parameter.
-
source: Event source settings:-
logging: Log group settings:-
log_group_id: ID of the log group whose new log entries will invoke the container. -
resource_type: Types of resources, e.g., functions in Cloud Functions. This is an optional parameter. -
resource_id: IDs of your resources or Yandex Cloud resources, e.g., functions in Cloud Functions. This is an optional parameter. -
stream_name: Log streams. This is an optional parameter. -
levels: Logging levels. This is an optional parameter.A trigger fires when the specified log group receives entries that comply with all of the following parameters:
resource_id,resource_type,stream_name, andlevels. If the setting is not specified, the trigger fires for any value.
-
batch_settings: Event grouping settings. This is an optional section.cutoff: Maximum event grouping time. This is a required setting. After the specified time has passed, the trigger sends the event group, even if it is not complete.max_count: Maximum number of events per group.max_bytes: Maximum total size of events per group, in bytes.
At least one of the parameters,
max_countormax_bytes, must be greater than 0.
-
-
-
action: Target settings. You can specify this section multiple times so the trigger calls multiple resources, including those of different types. There are limits on the maximum number of resources.-
invoke_container: Container settings:container_id: Container ID.path: HTTP path to call the container at. This is an optional parameter.service_account_id: ID of the service account with permissions to invoke the container.
-
filter: Filtering events before sending them to the target. This is an optional section.jq: jq template to filter events sent to the target. It not specified, all events reach the target.
-
transformer: Transforming events before sending them to the target. This is an optional section.jq: jq template to transform events before sending them to the target. It omitted, no transformations apply to the events.
-
retry_policy: Repeated request settings. This is an optional section.interval: Time interval before a retry attempt to send the event if the current attempt fails.retry_attempts: Number of retry attempts before the trigger moves the event to the dead-letter queue.
-
dead_letter: Dead-letter queue settings. This is an optional section.-
dead_letter_queue: Queue settings:queue_arn: Queue ARN.service_account_id: ID of the service account with permissions to write to the queue.message_attributes: Attributes to add to each message in the queue, inkey:valueformat. This is an optional parameter.
-
-
For more on the properties of the
yandex_serverless_triggersresource, see this provider guide.Configuration for the yandex_function_trigger resource
resource "yandex_function_trigger" "my_trigger" { name = "<trigger_name>" container { id = "<container_ID>" service_account_id = "<service_account_ID>" retry_attempts = "<number_of_retry_attempts>" retry_interval = "<time_between_retry_attempts>" } logging { group_id = "<log_group_ID>" resource_types = [ "<resource_type>" ] resource_ids = [ "<resource_ID>" ] stream_names = [ "<log_stream>" ] levels = [ "logging_level", "logging_level" ] batch_cutoff = "<maximum_wait_time>" batch_size = "<message_batch_size>" } dlq { queue_id = "<dead-letter_queue_ID>" service_account_id = "<service_account_ID>" } }Where:
-
name: Trigger name. Follow these naming requirements:- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
-
container: Container settings:id: Container ID.service_account_id: ID of the service account with permissions to invoke the container.
retry_attempts: Number of invocation retries before the trigger moves a message to the dead-letter queue. This is an optional setting. The values may range from 1 to 5. The default value is 1.retry_interval: Time to wait before retrying the container invocation if it fails. This is an optional setting. The values may range from 10 to 60 seconds. The default value is 10 seconds.
-
logging: Trigger settings:-
group_id: ID of the log group whose new log entries will invoke the container. -
resource_types: Types of resources, e.g., functions in Cloud Functions. This is an optional setting. -
resource_ids: IDs of your resources or Yandex Cloud resources, e.g., functions in Cloud Functions. This is an optional setting. -
stream_names: Log streams. This is an optional setting. -
levels: Logging levels. This is an optional setting.A trigger fires when the specified log group receives entries that comply with all of the following parameters:
resource_ids,resource_types,stream_names, andlevels. If the setting is not specified, the trigger fires for any value.
batch_cutoff: Maximum wait time. This is an optional setting. The values may range from 1 to 60 seconds. The default value is 1 second. The trigger groups messages within thebatch_cutoffperiod and sends them to the container. The number of messages cannot exceedbatch_size.batch_size: Message batch size. This is an optional setting. The values may range from 1 to 10. The default value is 1.
-
dlq: Dead-letter queue settings:queue_id: Dead-letter queue ID.service_account_id: ID of the service account with write permissions for the dead-letter queue.
For more on the properties of the
yandex_function_triggerresource, see this provider guide. -
-
Create the resources:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
Terraform will create all the required resources. You can check the new resources using the management console
or this CLI command:yc serverless trigger list -
To create a trigger for Cloud Logging, use the create REST API method for the Trigger resource or the TriggerService/Create gRPC API call.
Checking the result
Check that the trigger works correctly. To do this, view container logs that show information on invocations.