Seeing what is happening.
WHERE LOGS SHOULD GO
Standard output and standard error.
WHY NOT FILES
Files inside a container disappear with it, and nothing collects them.
WHAT THE ENGINE DOES
Captures those streams and stores them.
HOW TO READ THEM
The logs command, optionally following.
WHAT TO ADD
A limit on how many lines, and a time filter.
WHY
The full history can be enormous.
WHAT TO CONFIGURE
A logging driver, and rotation.
WHY ROTATION MATTERS
Without it, logs grow until the disk is full.
WHAT THE DEFAULT FREQUENTLY IS
Unlimited.
WHAT THAT CAUSES
A host that fills up quietly.
WHAT TO SET
A maximum size and number of files, per container.
WHAT STRUCTURED LOGGING PROVIDES
Logs that can be searched and filtered rather than read.
WHY IT MATTERS MORE HERE
Many short-lived containers produce interleaved output.
WHAT TO INCLUDE IN EVERY LINE
A timestamp The service name A correlation identifier, where applicable
WHAT TO SEND TO A CENTRAL SYSTEM
Everything, in anything beyond a single host.
WHY
Containers disappear, and their logs with them.
WHAT TO NEVER LOG
Credentials, tokens or personal data.