# In k8s, which archtecture is better?

**URL:** <https://discuss.elastic.co/t/in-k8s-which-archtecture-is-better/355087>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 9, 2024, 9:19pm UTC](https://discuss.elastic.co/t/in-k8s-which-archtecture-is-better/355087 "2024-03-09T21:19:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![teemoGod](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teemogod/32/40817_2.png) [@teemoGod](https://discuss.elastic.co/u/teemoGod)\
**Post date:** [March 9, 2024, 9:19pm UTC](https://discuss.elastic.co/t/in-k8s-which-archtecture-is-better/355087/1 "2024-03-09T21:19:51Z")

</div>

i have two options.

1. multiple Web application pods, each WAS pods have a filebeat as a sidecar  
(if 3 WAS exists, than totally 3 Filebeats exists, totally 3 Pods)

2. multiple Web application pods, only one filebeat pod as a main container  
(3 WAS exists, but only one Filebeat exists in another Pod without web application, totally 4 Pods)

in first option, i am worried about each filebeat race condition(filebeat.lock file) or resending logs(after restart pods or deploy new pods).

i know that `file_identity.inode_marker` or `data.path` options about `filebeat.yml`.  
in this case, 2 options will be shared among filebeats.  
(is this correct?)

I have 1 Persistence Volume, all WAS Pods will save log files in this PV's same file and logs will be rotated.  
and all filebeat's `data.path` and `file_identity.inode_marker.path` properties shared in one file.

I'm configuring first option now, but suddenly thought second option.

logs must be sent without loss.  
that's why i'm not save log files in each WAS Pods.

which option is better or general?  
`filebeat.yml` will not be changed frequently.

filebeat version is 7.9.

if any other options better than above 2 options, please recommend to me.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [March 23, 2024, 1:21pm UTC](https://discuss.elastic.co/t/in-k8s-which-archtecture-is-better/355087/2 "2024-03-23T13:21:24Z")

</div>

If you can get on newer versions of Elastic stack, Elastic Agent provides a Daemonset and easy to configure integrations for collecting logs and metrics from Kubernetes.

It might be worth setting up a quick POC cluster with KIND or minikube so you can get a better Idea of how the agent based method works.

The elastic agent uses a Daemonset (one agent per node, not one agent per pod) so that's probably a safe place to start.

---

<div class="post-metadata">

**Author:** ![teemoGod](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teemogod/32/40817_2.png) [@teemoGod](https://discuss.elastic.co/u/teemoGod)\
**Post date:** [March 24, 2024, 8:29am UTC](https://discuss.elastic.co/t/in-k8s-which-archtecture-is-better/355087/3 "2024-03-24T08:29:27Z")

</div>

thanks for your answer. i will consider your suggestion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2024, 10:30am UTC](https://discuss.elastic.co/t/in-k8s-which-archtecture-is-better/355087/4 "2024-04-21T10:30:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
