--- # Fluent Bit - Log forwarder from journald to Graylog GELF # Deployed as systemd service (not container) for direct journal access # # Graylog's GELF input is fluent-bit's only output, so the two share a switch: # with the stack down fluent-bit would just spin retrying a dead 127.0.0.1:12202 # and filling the journal it is meant to be draining. The package and config # stay installed either way -- only the service follows graylog_enabled (see # inventories/home/hosts.yml) -- so re-enabling is a restart, not a reinstall. - name: install fluent-bit package become: true ansible.builtin.dnf: name: fluent-bit state: present - name: create fluent-bit state directory for tail db files become: true ansible.builtin.file: path: /var/lib/fluent-bit state: directory owner: root group: root mode: '0755' - name: deploy fluent-bit parsers configuration become: true ansible.builtin.template: src: fluent-bit/parsers.conf.j2 dest: /etc/fluent-bit/parsers.conf owner: root group: root mode: '0644' notify: restart fluent-bit - name: deploy fluent-bit configuration become: true ansible.builtin.template: src: fluent-bit/fluent-bit.conf.j2 dest: /etc/fluent-bit/fluent-bit.conf owner: root group: root mode: '0644' notify: restart fluent-bit - name: set fluent-bit service state to match graylog_enabled become: true ansible.builtin.systemd: name: fluent-bit enabled: "{{ graylog_enabled | bool }}" state: "{{ 'started' if (graylog_enabled | bool) else 'stopped' }}"