Configuring log levels for cert-manager and the cert-manager Operator for Red Hat OpenShift
To troubleshoot issues with the cert-manager components and the cert-manager Operator for Red Hat OpenShift, you can configure the log level verbosity.
To use different log levels for different cert-manager components, see Customizing cert-manager Operator API fields.
Setting a log level for cert-manager
To troubleshoot issues and control log volume, configure the log level for the cert-manager Operator for Red Hat OpenShift. You can set specific verbosity levels to capture the necessary details for debugging or to reduce noise in your cluster logs.
Prerequisites
- You have access to the cluster with
cluster-adminprivileges. - You have installed version 1.11.1 or later of the cert-manager Operator for Red Hat OpenShift.
Procedure
-
Edit the
CertManagerresource by running the following command:$ oc edit certmanager.operator cluster -
Set the log level value by editing the
spec.logLevelsection:apiVersion: operator.openshift.io/v1alpha1kind: CertManager...spec:logLevel: <log_level>The
CertManagerresource supports the followinglogLevelvalues:Normal- Audits logs and records common operations. The default setting. Use this level when there are no issues.
Debug- Provides verbose logs. Use this level to troubleshoot minor issues.
Trace- Provides highly verbose logs. Use this level to troubleshoot major issues.
TraceAll- Provides maximum log detail. Use this level to troubleshoot serious issues.
noteTraceAllgenerates huge amount of logs. After settinglogLeveltoTraceAll, you might experience performance issues. -
Save your changes and quit the text editor to apply your changes. After applying the changes, the verbosity level for the cert-manager components controller, CA injector, and webhook is updated.
Setting a log level for the cert-manager Operator for Red Hat OpenShift
To troubleshoot issues and control log volume, set the log level for the cert-manager Operator for Red Hat OpenShift. You can configure the verbosity of the Operator log messages to capture the specific details required for your environment.
Prerequisites
- You have access to the cluster with
cluster-adminprivileges. - You have installed version 1.11.1 or later of the cert-manager Operator for Red Hat OpenShift.
Procedure
-
Update the subscription object for cert-manager Operator for Red Hat OpenShift to provide the verbosity level for the operator logs by running the following command:
$ oc -n cert-manager-operator patch subscription openshift-cert-manager-operator --type='merge' -p '{"spec":{"config":{"env":[{"name":"OPERATOR_LOG_LEVEL","value":"v"}]}}}'Replace
vwith the desired log level number. The valid values forvcan range from1to10. The default value is2.
Verification
-
The cert-manager Operator pod is redeployed. Verify that the log level of the cert-manager Operator for Red Hat OpenShift is updated by running the following command:
$ oc set env deploy/cert-manager-operator-controller-manager -n cert-manager-operator --list | grep -e OPERATOR_LOG_LEVEL -e containerExample output# deployments/cert-manager-operator-controller-manager, container kube-rbac-proxyOPERATOR_LOG_LEVEL=9# deployments/cert-manager-operator-controller-manager, container cert-manager-operatorOPERATOR_LOG_LEVEL=9 -
Verify that the log level of the cert-manager Operator for Red Hat OpenShift is updated by running the
oc logscommand:$ oc logs deploy/cert-manager-operator-controller-manager -n cert-manager-operator
Additional resources