Log Drivers & Rotation

Logs Will Eat Your Disk (Unless You Say Otherwise)

Scenario: A container logged ten lines a second for six weeks. Its json-file log grew to 40GB, the disk filled, and every container on the node started failing. The postmortem action item: log rotation, everywhere, enforced.

You already know docker logs reads whatever a container printed to stdout/stderr. What that section didn't cover is where that output physically lives while waiting to be read: on disk, one file per container, in a format called json-file (each log line stored as a small JSON record with a timestamp). By default that file has no size cap and is never rotated (rotation = periodically archiving/deleting old log data so it can't grow forever) - Docker will happily let it grow until the disk is full. Fix it per container:

$ docker run -d --log-driver json-file \
    --log-opt max-size=10m --log-opt max-file=3 myapp

…or for every container, in /etc/docker/daemon.json:

{ "log-driver": "json-file",
  "log-opts": { "max-size": "10m", "max-file": "3" } }
DriverSends logs to
json-filelocal files (the default; what docker logs reads)
localcompact local format, rotation by default
syslog / journaldthe host's log system
fluentd / gelf / awslogscentralized log pipelines
Warning: With most non-default drivers, docker logs stops working (nothing local to read). Teams often keep json-file with rotation and ship logs with a sidecar/agent instead.