Description
The kube-apiserver --audit-log-maxsize setting specifies the maximum audit log file size in MB before rotation. Smaller files rotate more often, which can remove records sooner when the backup count is limited. Omission alone does not establish that the size is too small; check the running version’s default.
Potential impact
- A surge in log volume can leave a shorter history within a fixed file count.
- Excessively large files can complicate storage and transfer.
Remediation
- Set --audit-log-maxsize for actual log volume and storage/transfer needs. The example’s 100MB is not sufficient for every environment.
- Configure the audit policy and file destination, and review maxbackup, maxage and external retention together. Check actual rotation frequency and retained history.
Examples
These excerpts compare v1.30.0 arguments only. The audit policy, --audit-log-path, mounts and other API server settings are omitted. Setting file size alone does not enable audit logging.
Before
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --audit-log-maxsize=50
Rotation is configured at 50MB. Whether this is appropriate depends on volume and the full retention policy.
After
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --audit-log-maxsize=100
Increasing the size to 100MB reduces rotation frequency for the same volume. Verify the required retention period separately.