Files
logstream/docker-compose.yml
T
cedricandClaude Opus 5.5 085095c46f Collect the logs of the local Docker containers
- docker.go follows every running container through the Docker API
  (events + logs with follow), resumes after a restart from the last
  position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
  of history for new containers, strips terminal color codes and guesses
  the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
  compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
  project), enable/disable all, follow new containers automatically.
  Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
  are labelled logstream.exclude=true and never collected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 16:52:05 +02:00

66 lines
2.4 KiB
YAML

services:
logstream:
build: .
container_name: logstream
restart: unless-stopped
depends_on:
- victorialogs
- docker-proxy
ports:
- "${SYSLOG_PORT:-514}:5514/udp"
- "${SYSLOG_PORT:-514}:5514/tcp"
- "${HTTP_PORT:-8080}:8080"
environment:
VLOGS_URL: http://victorialogs:9428
TZ: ${TZ:-Europe/Paris}
AUTH_USER: ${AUTH_USER:-} # leave empty to disable authentication
AUTH_PASS: ${AUTH_PASS:-}
RDNS: ${RDNS:-on} # replace IP hosts with their DNS name (PTR)
DNS_SERVER: ${DNS_SERVER:-} # e.g. 192.168.1.1 to query your LAN DNS; empty = system resolver
ALLOW_PURGE: ${ALLOW_PURGE:-true}
EXPORT_MAX: ${EXPORT_MAX:-100000}
DOCKER_LOGS: ${DOCKER_LOGS:-on} # collect the logs of this machine's containers
DOCKER_HOST: tcp://docker-proxy:2375 # read-only Docker API gateway (below)
DOCKER_BACKFILL: ${DOCKER_BACKFILL:-1h} # history read from a container seen for the first time
volumes:
- logstream-data:/data # tags.json, docker.json (container choices)
labels:
logstream.exclude: "true" # never collect Logstream's own logs
victorialogs:
# Pin a specific version in production (see hub.docker.com/r/victoriametrics/victoria-logs/tags)
image: victoriametrics/victoria-logs:latest
container_name: logstream-victorialogs
restart: unless-stopped
command:
- -storageDataPath=/vlogs
- -retentionPeriod=${RETENTION:-30d}
- -httpListenAddr=:9428
- -delete.enable # required by "Delete all logs" in Settings
volumes:
- vlogs-data:/vlogs
ports:
# VictoriaLogs debug UI (http://localhost:9428/select/vmui), localhost only
- "127.0.0.1:9428:9428"
docker-proxy:
# Read-only gateway to the Docker API: Logstream can only list containers,
# read their logs, receive events and engine info. Anything else (start,
# stop, exec, images, volumes…) is refused.
image: tecnativa/docker-socket-proxy:latest
container_name: logstream-docker-proxy
restart: unless-stopped
environment:
CONTAINERS: 1
EVENTS: 1
INFO: 1
POST: 0
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
labels:
logstream.exclude: "true" # its access log would only echo Logstream's own requests
volumes:
logstream-data:
vlogs-data: