Description
The kube-apiserver --audit-log-maxage setting specifies the maximum age in days for rotated audit log files. Zero removes age-based deletion, while omission uses the running version’s default. A short positive value can remove needed historical records too early.
Thirty days is an example retention target, not a universal requirement or a guaranteed minimum. File-count limits, log volume and external retention also affect how long records remain available.
Potential impact
- Records needed for an investigation may no longer be available.
- Excessive local retention can increase storage and sensitive-data management demands.
Remediation
- Choose --audit-log-maxage for investigation and retention requirements, and check the running version’s default. If 30 days are needed, verify that file-count and size limits do not remove records earlier.
- Configure the audit policy and file destination, and test rotation, external collection, storage capacity and record retrieval. For managed control planes, use the provider’s audit retention settings.
Examples
These existing v1.30.0 excerpts compare arguments only. The actual audit policy, --audit-log-path, required mounts and other API server settings are omitted.
Before
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --audit-log-maxage=26
Rotated files have an age threshold of 26 days. Compare it with the required retention period.
After
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --audit-log-maxage=30
The age threshold increases to 30 days. Other deletion conditions can still prevent records from being retained for the full period.