Review Kubernetes audit log rotation size

Manage file size and backup count together to retain the records you need.

Description

The kube-apiserver --audit-log-maxsize setting specifies the maximum audit log file size in MB before rotation. Smaller files rotate more often, which can remove records sooner when the backup count is limited. Omission alone does not establish that the size is too small; check the running version’s default.

Potential impact

  • A surge in log volume can leave a shorter history within a fixed file count.
  • Excessively large files can complicate storage and transfer.

Remediation

  • Set --audit-log-maxsize for actual log volume and storage/transfer needs. The example’s 100MB is not sufficient for every environment.
  • Configure the audit policy and file destination, and review maxbackup, maxage and external retention together. Check actual rotation frequency and retained history.

Examples

These excerpts compare v1.30.0 arguments only. The audit policy, --audit-log-path, mounts and other API server settings are omitted. Setting file size alone does not enable audit logging.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --audit-log-maxsize=50

Rotation is configured at 50MB. Whether this is appropriate depends on volume and the full retention policy.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --audit-log-maxsize=100

Increasing the size to 100MB reduces rotation frequency for the same volume. Verify the required retention period separately.

References