### {{ ansible_managed }} # Without a cap journald sizes itself at 10% of the filesystem, which on this # 1.9 TB root means it will happily grow into the tens of gigabytes; it had # reached 4 GB before this was set. # # Container stdout lands here: every container runs with log_driver=journald # except zomboid, which is chatty enough to evict everything else and so gets # its own rotating k8s-file log instead. {% if graylog_enabled | bool %} # fluent-bit drains the journal into Graylog continuously (systemd input, # _COMM=conmon -- see templates/fluent-bit/fluent-bit.conf.j2), so Graylog is # the system of record and what stays here is only the buffer that covers # fluent-bit being down. {% else %} # Graylog is disabled (see graylog_enabled in inventories/home/hosts.yml), so # the journal is now the only log store. No increase was needed for that: the # cap is a size limit, not a time limit, and fluent-bit only ever read the # journal rather than rotating it, so retention is unchanged at roughly 25 days # at the current rate -- longer than Graylog's own four live indices covered. {% endif %} [Journal] SystemMaxUse={{ journald_max_use | default('500M') }}