Description
The kube-apiserver --audit-log-maxbackup setting limits the number of old audit log files retained. Zero means no file-count limit; omission uses the running version’s default. A small positive value combined with frequent rotation can shorten actual retention.
Potential impact
- Frequent rotation can remove needed historical records early.
- A file count chosen without considering volume may not meet retention targets.
Remediation
- Set --audit-log-maxbackup according to log volume, file size and required retention. Ten files is an example, not an automatic guarantee of enough retention days.
- Enable the audit policy and file destination, and manage maxage, external collection and storage capacity together. Verify the records that actually remain after rotation.
Examples
These existing v1.30.0 excerpts compare arguments. The audit policy, --audit-log-path, required mounts and other API server settings are omitted.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --audit-log-maxbackup=5
At most five old files are kept. High log volume may cause records to be deleted too early.
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --audit-log-maxbackup=10
At most ten old files are kept. This does not mean ten files always exist or that a minimum retention period is guaranteed.