关于Kubernetes日志查询及Docker日志轮转的技术咨询
Hey there! Let's walk through your two questions—these are super common needs when managing Kubernetes and Docker workloads, so I’m glad you asked.
1. Viewing Latest Logs or Time-Range Specific Logs with Kubectl
Absolutely, kubectl logs has built-in flags to handle both scenarios seamlessly:
Track Real-Time (Latest) Logs
To stream new logs as they’re generated (just like tail -f on Linux), use the -f (follow) flag:
kubectl logs -f pod_name -n namespace
If you only want to start streaming from the most recent N lines, combine -f with the --tail flag:
kubectl logs -f --tail=50 pod_name -n namespace
This starts showing the last 50 lines of logs and keeps updating with new entries as they come in.
Query Logs from a Specific Time Range
You have two flexible options here:
- Use
--sincefor relative time ranges (e.g., last hour, 30 minutes):kubectl logs --since=1h pod_name -n namespace # Pull logs from the last hour kubectl logs --since=30m pod_name -n namespace # Pull logs from the last 30 minutes - Use
--since-timeand--until-timefor absolute time windows (format must follow RFC3339, likeYYYY-MM-DDTHH:MM:SSZ):kubectl logs --since-time="2024-05-20T09:00:00Z" --until-time="2024-05-20T10:30:00Z" pod_name -n namespace
This will only return logs generated between those exact timestamps.
2. Docker Log Rotation by Size or Date
Yes, you can configure Docker to rotate logs based on size, number of retained files, and indirectly by time (via size limits). Here’s how to set it up:
Node-Level Docker Configuration
The most common approach is to configure Docker’s daemon.json file (usually located at /etc/docker/daemon.json—create it if it doesn’t exist).
Add this configuration to enable rotation for the default json-file log driver:
{ "log-driver": "json-file", "log-opts": { "max-size": "10m", // Rotate logs when a file reaches 10MB "max-file": "5", // Keep up to 5 rotated log files "local-time": "true" // Use local time in rotated file names (optional) } }
max-size: Supports units likek(kilobytes),m(megabytes), org(gigabytes) to define when a log file gets rotated.max-file: Limits how many old rotated files are kept before they’re automatically deleted.
After editing the file, restart the Docker daemon to apply changes:
sudo systemctl restart docker
All new containers (including Kubernetes Pods) will use this rotation policy. Existing containers won’t pick up the change unless you restart them.
Per-Pod Log Rotation (Kubernetes)
If you need custom rotation settings for a single Pod, you can override the node-level config directly in the Pod’s YAML. Add a logConfig section under your container spec:
apiVersion: v1 kind: Pod metadata: name: custom-log-pod namespace: your-namespace spec: containers: - name: app-container image: your-app-image logConfig: type: "json-file" config: max-size: "5m" max-file: "3"
This applies the rotation rules only to this specific container.
Notes for Other Log Drivers
If you’re using journald instead of json-file, rotation is managed via systemd’s journald.conf file. Look for settings like SystemMaxUse and SystemMaxFileSize to adjust retention policies.
内容的提问来源于stack exchange,提问作者user1578872

