Review Kubernetes audit log backup count

Choose the rotated-file count for actual log volume and retention needs.

Description

The kube-apiserver --audit-log-maxbackup setting limits the number of old audit log files retained. Zero means no file-count limit; omission uses the running version’s default. A small positive value combined with frequent rotation can shorten actual retention.

Potential impact

  • Frequent rotation can remove needed historical records early.
  • A file count chosen without considering volume may not meet retention targets.

Remediation

  • Set --audit-log-maxbackup according to log volume, file size and required retention. Ten files is an example, not an automatic guarantee of enough retention days.
  • Enable the audit policy and file destination, and manage maxage, external collection and storage capacity together. Verify the records that actually remain after rotation.

Examples

These existing v1.30.0 excerpts compare arguments. The audit policy, --audit-log-path, required mounts and other API server settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --audit-log-maxbackup=5

At most five old files are kept. High log volume may cause records to be deleted too early.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --audit-log-maxbackup=10

At most ten old files are kept. This does not mean ten files always exist or that a minimum retention period is guaranteed.

References