Short answer: Promtail does not open Docker’s log files. It connects to the local Docker socket, lists container ids, and calls the engine logs API with follow. It splits stdout from stderr, removes Docker’s timestamp prefix, and POSTs the lines to Loki at /loki/api/v1/push. This page assumes that push…
Tag: Promtail
How Promtail ships container logs to Loki across an IPsec split tunnel
Short answer: Do not open a remote Docker socket to read container stdout. Promtail on the remote host tails the local socket and pushes to Loki. If that host’s IPsec policy can reach only one virtual address, and Loki is bound to a different virtual address on the same…
