Collect the logs of the local Docker containers
- docker.go follows every running container through the Docker API (events + logs with follow), resumes after a restart from the last position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h) of history for new containers, strips terminal color codes and guesses the severity from the line (JSON, logfmt, [ERROR], ERROR ...). - Logs carry source_type=docker, container, container_id, image, compose_project, compose_service and stream; host is the Docker host. - Settings > Sources: one switch per container (grouped by compose project), enable/disable all, follow new containers automatically. Choices are saved per compose service in /data/docker.json. - Source filter (syslog / docker) in the filter bar and the live view. - docker-compose: read-only docker-socket-proxy; Logstream and the proxy are labelled logstream.exclude=true and never collected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
aad0fb7c16
commit
085095c46f
12 files changed
+974
-10
No files matched your search
+24
-1
@@ -5,6 +5,7 @@ services:
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
- victorialogs
|
||||
- docker-proxy
|
||||
ports:
|
||||
- "${SYSLOG_PORT:-514}:5514/udp"
|
||||
- "${SYSLOG_PORT:-514}:5514/tcp"
|
||||
@@ -18,8 +19,13 @@ services:
|
||||
DNS_SERVER: ${DNS_SERVER:-} # e.g. 192.168.1.1 to query your LAN DNS; empty = system resolver
|
||||
ALLOW_PURGE: ${ALLOW_PURGE:-true}
|
||||
EXPORT_MAX: ${EXPORT_MAX:-100000}
|
||||
DOCKER_LOGS: ${DOCKER_LOGS:-on} # collect the logs of this machine's containers
|
||||
DOCKER_HOST: tcp://docker-proxy:2375 # read-only Docker API gateway (below)
|
||||
DOCKER_BACKFILL: ${DOCKER_BACKFILL:-1h} # history read from a container seen for the first time
|
||||
volumes:
|
||||
- logstream-data:/data # tags.json
|
||||
- logstream-data:/data # tags.json, docker.json (container choices)
|
||||
labels:
|
||||
logstream.exclude: "true" # never collect Logstream's own logs
|
||||
|
||||
victorialogs:
|
||||
# Pin a specific version in production (see hub.docker.com/r/victoriametrics/victoria-logs/tags)
|
||||
@@ -37,6 +43,23 @@ services:
|
||||
# VictoriaLogs debug UI (http://localhost:9428/select/vmui), localhost only
|
||||
- "127.0.0.1:9428:9428"
|
||||
|
||||
docker-proxy:
|
||||
# Read-only gateway to the Docker API: Logstream can only list containers,
|
||||
# read their logs, receive events and engine info. Anything else (start,
|
||||
# stop, exec, images, volumes…) is refused.
|
||||
image: tecnativa/docker-socket-proxy:latest
|
||||
container_name: logstream-docker-proxy
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
CONTAINERS: 1
|
||||
EVENTS: 1
|
||||
INFO: 1
|
||||
POST: 0
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
labels:
|
||||
logstream.exclude: "true" # its access log would only echo Logstream's own requests
|
||||
|
||||
volumes:
|
||||
logstream-data:
|
||||
vlogs-data:
|
||||
Reference in new issue
Block a user