services: logstream: build: . container_name: logstream restart: unless-stopped depends_on: - victorialogs - docker-proxy ports: - "${SYSLOG_PORT:-514}:5514/udp" - "${SYSLOG_PORT:-514}:5514/tcp" - "${HTTP_PORT:-8080}:8080" environment: VLOGS_URL: http://victorialogs:9428 SYSLOG_PUBLIC_PORT: ${SYSLOG_PORT:-514} # shown in Settings > Sources (the mapping is set above) TZ: ${TZ:-Europe/Paris} AUTH_USER: ${AUTH_USER:-} # leave empty to disable authentication AUTH_PASS: ${AUTH_PASS:-} RDNS: ${RDNS:-on} # replace IP hosts with their DNS name (PTR) DNS_SERVER: ${DNS_SERVER:-} # e.g. 192.168.1.1 to query your LAN DNS; empty = system resolver ALLOW_PURGE: ${ALLOW_PURGE:-true} EXPORT_MAX: ${EXPORT_MAX:-100000} DOCKER_LOGS: ${DOCKER_LOGS:-on} # collect the logs of this machine's containers DOCKER_HOST: tcp://docker-proxy:2375 # read-only Docker API gateway (below) DOCKER_BACKFILL: ${DOCKER_BACKFILL:-1h} # history read from a container seen for the first time volumes: - logstream-data:/data # tags.json, docker.json (container choices) labels: logstream.exclude: "true" # never collect Logstream's own logs victorialogs: # Pinned version: see "Updating" in the README before changing it image: victoriametrics/victoria-logs:v1.52.0 container_name: logstream-victorialogs restart: unless-stopped command: - -storageDataPath=/vlogs - -retentionPeriod=${RETENTION:-30d} - -httpListenAddr=:9428 - -delete.enable # required by "Delete all logs" in Settings volumes: - vlogs-data:/vlogs ports: # VictoriaLogs debug UI (http://localhost:9428/select/vmui), localhost only - "127.0.0.1:9428:9428" docker-proxy: # Read-only gateway to the Docker API: Logstream can only list containers, # read their logs, receive events and engine info. Anything else (start, # stop, exec, images, volumes…) is refused. image: tecnativa/docker-socket-proxy:v0.5.0 container_name: logstream-docker-proxy restart: unless-stopped environment: CONTAINERS: 1 EVENTS: 1 INFO: 1 POST: 0 volumes: - /var/run/docker.sock:/var/run/docker.sock:ro labels: logstream.exclude: "true" # its access log would only echo Logstream's own requests volumes: logstream-data: vlogs-data: