Chapter 9. Viewing logs and audit records
As a cluster administrator, you can use the OpenShift AI Operator logger to monitor and troubleshoot issues. You can also use OpenShift audit records to review a history of changes made to the OpenShift AI Operator configuration.
9.1. Configure the OpenShift AI Operator logger Copy linkLink copied to clipboard!
You can change the log level for the OpenShift AI Operator by setting the .spec.devFlags.logLevel flag for the DSC Initialization (DSCI) custom resource during runtime. If you do not set a logLevel value, the logger uses the info log level by default.
The log level that you set with .spec.devFlags.logLevel applies only to the rhods-operator itself, not to the individual OpenShift AI components that the Operator manages.
The following table describes the available log levels:
| Log level | Severity | Verbosity | Output format | Description |
|---|---|---|---|---|
|
| N/A | Low | JSON |
Restricts logging output to |
|
|
| Medium | JSON |
Enables standard informational logs and |
|
|
| High | JSON |
Enables all logs: |
| Custom numeric |
| Very High | JSON | Fine-grained controller execution logging for advanced troubleshooting. Higher integers yield progressively more detailed tracing output. |
Prerequisites
-
You have administrator access to the
DSCInitializationresources in the OpenShift cluster. You have installed the OpenShift CLI (
oc) as described in the appropriate documentation for your cluster:- Installing the OpenShift CLI for OpenShift Container Platform
- Installing the OpenShift CLI for Red Hat OpenShift Service on AWS
Procedure
- Log in to the OpenShift as a cluster administrator.
Go to the Installed Operators page. The navigation path depends on your OpenShift version:
-
On OpenShift 4.20 and later, click Ecosystem
Installed Operators. -
On OpenShift 4.19, click Operators
Installed Operators.
-
On OpenShift 4.20 and later, click Ecosystem
- Click the DSC Initialization tab.
- Click the default-dsci object.
- Click the YAML tab.
In the
specsection, update the.spec.devFlags.logLevelflag with the log level that you want to set.apiVersion: dscinitialization.opendatahub.io/v2 kind: DSCInitialization metadata: name: default-dsci spec: devFlags: logLevel: debug- Click Save.
Alternatively, to configure the log level from the OpenShift CLI (
oc), run the following command:$ oc patch dsci default-dsci -p {"spec":{"devFlags":{"logLevel":"debug"}}} --type=merge
Verification
-
If you set the log level to
error, logs generate infrequently and only capture critical execution failures and errors. -
If you set the log level to
info(or leave it unset), logs generate at a standard frequency and includeinfoanderrormessages. -
If you set the log level to
debug, logs generate often and include alldebug,info, anderrormessages. -
If you set the log level to a numeric value (such as
1,2, or3), logs generate at an extremely high frequency, exposing deep, fine-grained controller execution data for advanced troubleshooting. Higher integers yield progressively more detailed tracing output.
9.1.1. View the OpenShift AI Operator logs Copy linkLink copied to clipboard!
-
Log in to the OpenShift CLI (
oc). Run the following command to stream logs from all Operator pods:
for pod in $(oc get pods -l name=rhods-operator -n redhat-ods-operator -o name); do oc logs -f "$pod" -n redhat-ods-operator & doneThe Operator pod logs open in your terminal.
TipPress
Ctrl+Cto stop viewing. To fully stop all log streams, runkill $(jobs -p).
You can also view each Operator pod log in the OpenShift console by navigating to Workloads redhat-ods-operator project, clicking a pod name, and then clicking the Logs tab.
9.2. Viewing audit records Copy linkLink copied to clipboard!
Cluster administrators can use OpenShift auditing to see changes made to the OpenShift AI Operator configuration by reviewing modifications to the DataScienceCluster (DSC) and DSCInitialization (DSCI) custom resources. Audit logging is enabled by default in standard OpenShift cluster configurations. For more information, see Viewing audit logs in the OpenShift documentation.
In Red Hat OpenShift Service on AWS, audit logging is disabled by default because the Elasticsearch log store does not provide secure storage for audit logs. To configure log forwarding, see Logging in the Red Hat OpenShift Service on AWS documentation.
The following example shows how to use the OpenShift audit logs to see the history of changes made (by users) to the DSC and DSCI custom resources.
Prerequisites
- You have cluster administrator privileges for your OpenShift cluster.
You have installed the OpenShift CLI (
oc) as described in the appropriate documentation for your cluster:- Installing the OpenShift CLI for OpenShift Container Platform
- Installing the OpenShift CLI for Red Hat OpenShift Service on AWS
Procedure
In a terminal window, if you are not already logged in to your OpenShift cluster as a cluster administrator, log in to the OpenShift CLI as shown in the following example:
$ oc login <openshift_cluster_url> -u <admin_username> -p <password>-
To access the full content of the changed custom resources, set the OpenShift audit log policy to
WriteRequestBodiesor a more comprehensive profile. For more information, see Configuring the audit log policy. Fetch the audit log files that are available for the relevant control plane nodes. For example:
oc adm node-logs --role=master --path=kube-apiserver/ \ | awk '{ print $1 }' | sort -u \ | while read node ; do oc adm node-logs $node --path=kube-apiserver/audit.log < /dev/null done \ | grep opendatahub > /tmp/kube-apiserver-audit-opendatahub.logSearch the files for the DSC and DSCI custom resources. For example:
jq 'select((.objectRef.apiGroup == "dscinitialization.opendatahub.io" or .objectRef.apiGroup == "datasciencecluster.opendatahub.io") and .user.username != "system:serviceaccount:redhat-ods-operator:redhat-ods-operator-controller-manager" and .verb != "get" and .verb != "watch" and .verb != "list")' < /tmp/kube-apiserver-audit-opendatahub.log
Verification
- The commands return relevant log entries.
To configure the log retention time, see the Logging section in the OpenShift documentation.