Skip to content
BotServBotServ
DockerLogsLog Rotationjson-filelogrotate

Set Up Docker Log Rotation

Rotate and limit Docker container logs. Configure json-file, logrotate, and Promtail.

S

schutzgeist

3 min read
Set Up Docker Log Rotation

Setting Up Docker Log Rotation

What This Article Covers

  • Why container logs need limits.
  • How Docker stores logs by default.
  • How to cap log size and file count.
  • Alternatives like local and external logging services.
  • Tips for production environments.

Introduction: Setting Up Docker Log Rotation

Docker containers write logs to stdout and stderr by default. Without configuration, these logs grow indefinitely and eventually consume your disk space. With scaling applications, chatbots, or services handling many requests, logs can quickly reach several gigabytes. Log rotation ensures old logs are deleted or archived while keeping recent ones accessible.

This article shows how to set up Docker log rotation properly.

Key Terms

  • Log Driver: The component that stores or forwards logs.
  • json-file: Default driver that saves logs as JSON.
  • local: A driver that rotates logs locally.
  • Log Rotation: Regular archiving or deletion of old logs.
  • Log Forwarder: A service that sends logs to external systems.
  • Retention: How long logs are kept.
  • max-size: Maximum size of a log file.
  • max-file: Maximum number of rotated files to retain.

Default Behavior

Docker stores logs using the json-file driver. Each line gets written to a JSON file. Without limits, these files grow unbounded:

/var/lib/docker/containers/<id>/<id>-json.log

Configure Logging Per Container

In compose.yaml:

services:
  app:
    image: mein-app
    logging:
      driver: "json-file"
      options:
        max-size: "10m"
        max-file: "3"

This caps each log file at 10 MB and keeps three files.

Configure Globally

In /etc/docker/daemon.json:

{
  "log-driver": "json-file",
  "log-opts": {
    "max-size": "10m",
    "max-file": "3"
  }
}

Restart Docker afterward:

sudo systemctl restart docker

Existing containers must be recreated for the new options to take effect.

Local Log Driver

The local driver rotates automatically and is lighter weight than json-file:

{
  "log-driver": "local",
  "log-opts": {
    "max-size": "10m",
    "max-file": "3"
  }
}

Check Logs

docker logs <container>
docker logs --tail 100 <container>
docker logs --since 1h <container>

Check Log Size

sudo du -sh /var/lib/docker/containers/*

Or for a specific container:

sudo ls -lh /var/lib/docker/containers/<id>/<id>-json.log

Clear Logs

Stop the container:

docker stop <container>

Truncate the log file:

sudo sh -c 'truncate -s 0 /var/lib/docker/containers/<id>/<id>-json.log'

Start the container again:

docker start <container>

External Logs with syslog

services:
  app:
    image: mein-app
    logging:
      driver: "syslog"
      options:
        syslog-address: "udp://localhost:514"

Send Logs to Loki or Splunk

services:
  app:
    image: mein-app
    logging:
      driver: "loki"
      options:
        loki-url: "http://localhost:3100/loki/api/v1/push"

Using logrotate for Container Logs

For host logs or bind-mounted logs, use logrotate:

/var/log/containers/*.log {
  daily
  missingok
  rotate 7
  compress
  delaycompress
  notifempty
  create 0640 root adm
  sharedscripts
}

Tips

  • Always set size and file count limits.
  • Use local instead of json-file if you don’t need JSON processing.
  • For production, use external logging like Loki or Splunk.
  • Document your retention policy.
  • Regularly check that rotation is working.
  • Never log secrets.

Common Pitfalls

  • No log limits: Disk fills up.
  • Changed global settings but forgot to recreate containers: Old containers keep the old driver.
  • Truncating while running: Data loss.
  • Log forwarder unreachable: Container fails to start.
  • Retention too short: Can’t trace errors afterward.
  • Wrong permissions: Logs can’t be deleted.

Further Reading

FAQ: Docker Log Rotation

Are logs automatically deleted? No. Without configuration, they grow indefinitely.

Which log driver is best? For local setups, local or json-file with max-size. For centralized collection, Loki or Splunk.

How do global settings take effect? Only for containers created after the change.

How often are logs rotated? When max-size is reached, not on a time schedule.

Should I compress logs? Yes, if you’re keeping them long-term to save space.

Sources and Further Reading

Summary: Setting Up Docker Log Rotation

Docker log rotation prevents container logs from consuming unlimited disk space. The json-file or local driver with max-size and max-file is the simplest approach for local setups. For centralized log management, external logging services work well. By setting limits, checking regularly, and defining a retention policy, you keep storage under control while ensuring relevant logs remain available for troubleshooting.

Back to Blog
Share:

Related Posts