> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Kubernetes architecture of the CXDOT Collector

> Learn how the CXDOT Collector deploys components in a Kubernetes cluster.

The CXDOT Collector is a single container image that contains the `cxdot-collector`
binary. When you [install](/ingest/xcor/collector/install/kubernetes) the CXDOT Collector
in a Kubernetes cluster, the CXDOT Collector deploys several components that work in
tandem to collect telemetry data and send that data to Palo Alto Networks Cortex XCOR.

```mermaid actions={false} theme={null}
graph TB
  accTitle: CXDOT Kubernetes architecture
  accDescr: The CXDOT Collector deploys several components in a Kubernetes cluster. Telemetry data flows to the Cortex XCOR OTLP Ingestion API.

  subgraph cloud["Cloud environment"]
    subgraph cluster["Kubernetes cluster"]
      subgraph node["Kubernetes node"]
        direction TB
        app["App Pod"]
        nc["CXDOT node<br/>collector<br/>(DaemonSet)"]
        subgraph targets["Local scrape targets"]
          direction TB
          infrapod["Infra Pod"]
          kubelet["kubelet"]
          runtime["Container<br/>runtime"]
        end
        app --> nc
        nc --> infrapod
        nc --> kubelet
        nc --> runtime
      end
      cc["CXDOT cluster<br/>collector<br/>(Deployment)"]
      api["CXDOT API server<br/>(Deployment)"]
      k8s["Kubernetes<br/>API server"]
    end
    managed["Managed<br/>services"]
  end

  ingestion["Cortex XCOR OTLP<br/>Ingestion API"]

  nc .-> api
  cc .-> api
  cc --> managed
  k8s <--> api
  k8s <--> cc
  nc ==> ingestion
  cc ==> ingestion
  managed ~~~ ingestion

  classDef cxdot fill:#60E684,stroke:#000,stroke-width:2px,color:#000;
  classDef workload fill:#E8D5F5,stroke:#6320EE,stroke-width:1px,color:#000;
  classDef infra fill:#FFF,stroke:#999,stroke-width:1px,stroke-dasharray:5 5,color:#000;
  classDef otl fill:lightblue,stroke:#000,stroke-width:2px,color:#000;

  class nc,cc,api cxdot
  class app,infrapod,managed workload
  class kubelet,runtime,k8s infra
  class ingestion otl
```

The CXDOT Collector deploys these components to collect telemetry data from your
Kubernetes workloads:

* The [node collector](#node-collector) is a DaemonSet with one Pod on each
  eligible node.
* The [cluster collector](#cluster-collector) is a Deployment with one or more
  worker Pods.
* The [API server](#api-server) provides cluster-wide services that support the
  node collector and cluster collector.

## Node collector

The node collector is a DaemonSet with one Pod on each eligible node. It uses
push-based collection when it listens for HTTP and UDP requests from application
Pods on the same node. It uses pull-based collection when it queries Pods on the
same node to collect data from infrastructure services, such as MySQL. The node
collector also gathers information about the node itself through the kubelet API
and through the container runtime.

After it collects telemetry data, the node collector sends that data to
Cortex XCOR through the
[Cortex XCOR OTLP Ingestion API](/ingest/logs/otel-logs#otlp-endpoint-urls).

## Cluster collector

The cluster collector is a Deployment with one or more worker Pods. It handles
cluster-wide collection tasks, like running the OpenTelemetry `k8scluster`
receiver to gather data from the Kubernetes API. It also collects telemetry data
from managed services that are accessible only from within your cloud
environment.

By default, the cluster collector deploys two replicas. You can change this
behavior by setting the value of `clusterCollector.replicas` in your Helm values
file.

After it collects telemetry data, the cluster collector sends that data to
Cortex XCOR through the
[Cortex XCOR OTLP Ingestion API](/ingest/logs/otel-logs#otlp-endpoint-urls).

## API server

The CXDOT API server provides cluster-wide services that support the node collector
and cluster collector. Its primary function is to cache the state of Kubernetes
resources in your cluster, which helps determine which attributes to add to the
telemetry data collected by the node collector and cluster collector. The API server
does this by using watch streams to keep the cache current and by responding to
queries from the node collector and cluster collector.

The CXDOT API server also hosts a mutating admission controller webhook that, when
enabled, returns a set of mutations to apply to new Pods before their creation.
These mutations inject information into Pods for use by instrumentation SDKs.

<Note>
  The CXDOT API server doesn't directly collect or handle telemetry data.
</Note>


## Related topics

- [Install the CXDOT Collector in a Kubernetes cluster](/ingest/xcor/collector/install/kubernetes.md)
- [Discover Kubernetes scrape targets with the CXDOT Collector](/ingest/xcor/collector/discover/kubernetes.md)
- [Kubernetes](/ingest/xcor/integrations/collector/kubernetes.md)
- [CXDOT Collector](/ingest/xcor/collector.md)
- [Install the CXDOT Collector on Linux](/ingest/xcor/collector/install/linux.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.