DevOps

Logrotate Config Generator

Generate a logrotate configuration with the right rotation frequency, retention, compression and post-rotate signal handling, and avoid the copytruncate data loss trap.

Last reviewed by the Radiatus Cloud team

Configuration appears here.

Want this automated for your stack?

We build CI/CD, Kubernetes & IaC pipelines that scale.

Talk to an engineer

The directive that quietly loses data

When logrotate renames a file, a process that already has it open keeps writing to the renamed inode, so the new file stays empty and the disk never frees. There are two fixes and they are not equivalent. The correct one is to rename the file and then signal the process to reopen it, which is what a postrotate script does. The other is copytruncate, which copies the file and truncates the original in place, and anything written between the copy and the truncate is lost. copytruncate exists for programs that cannot be signalled, and using it when a signal is available trades correctness for convenience.

Retention is a size question as much as a time one

Rotating daily and keeping thirty copies sounds reasonable until the service has a bad day and each file is two gigabytes. The size directive rotates on volume rather than on the calendar, and maxage removes files past an age regardless of count. Combining a count limit with a size trigger bounds the worst case, which is what actually matters for a disk that also holds the database.

delaycompress exists for a reason

Compressing the newly rotated file immediately can truncate output from a process that has not yet reopened its handle. delaycompress leaves the most recent rotation uncompressed and compresses it on the following run, by which time every writer has moved on. It costs one extra uncompressed file and removes a whole class of intermittent corruption, which is why almost every distribution ships it in the default configuration.

Related tools

Frequently Asked Questions

When should I use copytruncate?

Only when the program cannot be told to reopen its log file. It copies then truncates, so anything written between those two operations is lost. If the process can be signalled with SIGHUP or has a reopen command, use a postrotate script instead.

What does delaycompress do?

It postpones compression of the most recent rotation until the next run, so a process that has not yet reopened its handle cannot have its output truncated mid-compression. It costs one extra uncompressed file and removes a real class of intermittent corruption.

How do I stop logs filling the disk?

Combine a rotation count with a size trigger and maxage. Time based rotation alone does not bound the worst case, because a bad day can produce a hundred times the normal volume before the next scheduled rotation.

Why is my log file still growing after rotation?

The writing process still holds the old inode. Renaming a file does not affect an open file descriptor. Either signal the process to reopen, which is what postrotate is for, or restart it. This is the single most common logrotate problem.

Should applications rotate their own logs?

Writing to stdout and letting the journal or the container runtime handle it is simpler and avoids the reopen problem entirely. logrotate is for programs that insist on managing their own files, which is still most of them.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Set the log path, rotation schedule and retention to generate a logrotate configuration.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.