mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add retention config for workspace_agent_logs (#21039)
Replace hardcoded 7-day retention for workspace agent logs with configurable retention from deployment settings. Defaults to 7d to preserve existing behavior. Depends on #21038 Updates #20743
This commit is contained in:
@@ -1,8 +1,8 @@
|
||||
# Data Retention
|
||||
|
||||
Coder supports configurable retention policies that automatically purge old
|
||||
Audit Logs, Connection Logs, and API keys. These policies help manage database
|
||||
growth by removing records older than a specified duration.
|
||||
Audit Logs, Connection Logs, Workspace Agent Logs, and API keys. These policies
|
||||
help manage database growth by removing records older than a specified duration.
|
||||
|
||||
## Overview
|
||||
|
||||
@@ -16,7 +16,8 @@ Retention policies help you:
|
||||
|
||||
> [!NOTE]
|
||||
> Retention policies are disabled by default (set to `0`) to preserve existing
|
||||
> behavior. The only exception is API keys, which defaults to 7 days.
|
||||
> behavior. The exceptions are API keys and workspace agent logs, which default
|
||||
> to 7 days.
|
||||
|
||||
## Configuration
|
||||
|
||||
@@ -25,11 +26,12 @@ a YAML configuration file.
|
||||
|
||||
### Settings
|
||||
|
||||
| Setting | CLI Flag | Environment Variable | Default | Description |
|
||||
|-----------------|-------------------------------|-----------------------------------|----------------|--------------------------------------|
|
||||
| Audit Logs | `--audit-logs-retention` | `CODER_AUDIT_LOGS_RETENTION` | `0` (disabled) | How long to retain Audit Log entries |
|
||||
| Connection Logs | `--connection-logs-retention` | `CODER_CONNECTION_LOGS_RETENTION` | `0` (disabled) | How long to retain Connection Logs |
|
||||
| API Keys | `--api-keys-retention` | `CODER_API_KEYS_RETENTION` | `7d` | How long to retain expired API keys |
|
||||
| Setting | CLI Flag | Environment Variable | Default | Description |
|
||||
|----------------------|------------------------------------|----------------------------------------|----------------|-----------------------------------------|
|
||||
| Audit Logs | `--audit-logs-retention` | `CODER_AUDIT_LOGS_RETENTION` | `0` (disabled) | How long to retain Audit Log entries |
|
||||
| Connection Logs | `--connection-logs-retention` | `CODER_CONNECTION_LOGS_RETENTION` | `0` (disabled) | How long to retain Connection Logs |
|
||||
| API Keys | `--api-keys-retention` | `CODER_API_KEYS_RETENTION` | `7d` | How long to retain expired API keys |
|
||||
| Workspace Agent Logs | `--workspace-agent-logs-retention` | `CODER_WORKSPACE_AGENT_LOGS_RETENTION` | `7d` | How long to retain workspace agent logs |
|
||||
|
||||
### Duration Format
|
||||
|
||||
@@ -48,7 +50,8 @@ Go duration units (`h`, `m`, `s`):
|
||||
coder server \
|
||||
--audit-logs-retention=365d \
|
||||
--connection-logs-retention=90d \
|
||||
--api-keys-retention=7d
|
||||
--api-keys-retention=7d \
|
||||
--workspace-agent-logs-retention=7d
|
||||
```
|
||||
|
||||
### Environment Variables Example
|
||||
@@ -57,6 +60,7 @@ coder server \
|
||||
export CODER_AUDIT_LOGS_RETENTION=365d
|
||||
export CODER_CONNECTION_LOGS_RETENTION=90d
|
||||
export CODER_API_KEYS_RETENTION=7d
|
||||
export CODER_WORKSPACE_AGENT_LOGS_RETENTION=7d
|
||||
```
|
||||
|
||||
### YAML Configuration Example
|
||||
@@ -66,6 +70,7 @@ retention:
|
||||
audit_logs: 365d
|
||||
connection_logs: 90d
|
||||
api_keys: 7d
|
||||
workspace_agent_logs: 7d
|
||||
```
|
||||
|
||||
## How Retention Works
|
||||
@@ -100,6 +105,17 @@ ago. Active keys are never deleted by the retention policy.
|
||||
Keeping expired keys for a short period allows Coder to return a more helpful
|
||||
error message when users attempt to use an expired key.
|
||||
|
||||
### Workspace Agent Logs Behavior
|
||||
|
||||
Workspace agent logs are deleted based on when the agent last connected, not the
|
||||
age of the logs themselves. **Logs from the latest build of each workspace are
|
||||
always retained** regardless of when the agent last connected. This ensures you
|
||||
can always debug issues with active workspaces.
|
||||
|
||||
For non-latest builds, logs are deleted if the agent hasn't connected within the
|
||||
retention period. Setting `--workspace-agent-logs-retention=7d` deletes logs for
|
||||
agents that haven't connected in 7 days (excluding those from the latest build).
|
||||
|
||||
## Best Practices
|
||||
|
||||
### Recommended Starting Configuration
|
||||
@@ -111,6 +127,7 @@ retention:
|
||||
audit_logs: 365d
|
||||
connection_logs: 90d
|
||||
api_keys: 7d
|
||||
workspace_agent_logs: 7d
|
||||
```
|
||||
|
||||
### Compliance Considerations
|
||||
@@ -150,9 +167,10 @@ To keep data indefinitely for any data type, set its retention value to `0`:
|
||||
|
||||
```yaml
|
||||
retention:
|
||||
audit_logs: 0s # Keep audit logs forever
|
||||
connection_logs: 0s # Keep connection logs forever
|
||||
api_keys: 0s # Keep expired API keys forever
|
||||
audit_logs: 0s # Keep audit logs forever
|
||||
connection_logs: 0s # Keep connection logs forever
|
||||
api_keys: 0s # Keep expired API keys forever
|
||||
workspace_agent_logs: 0s # Keep workspace agent logs forever
|
||||
```
|
||||
|
||||
## Monitoring
|
||||
|
||||
Generated
+2
-1
@@ -466,7 +466,8 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
|
||||
"retention": {
|
||||
"api_keys": 0,
|
||||
"audit_logs": 0,
|
||||
"connection_logs": 0
|
||||
"connection_logs": 0,
|
||||
"workspace_agent_logs": 0
|
||||
},
|
||||
"scim_api_key": "string",
|
||||
"session_lifetime": {
|
||||
|
||||
Generated
+12
-8
@@ -3150,7 +3150,8 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
|
||||
"retention": {
|
||||
"api_keys": 0,
|
||||
"audit_logs": 0,
|
||||
"connection_logs": 0
|
||||
"connection_logs": 0,
|
||||
"workspace_agent_logs": 0
|
||||
},
|
||||
"scim_api_key": "string",
|
||||
"session_lifetime": {
|
||||
@@ -3671,7 +3672,8 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
|
||||
"retention": {
|
||||
"api_keys": 0,
|
||||
"audit_logs": 0,
|
||||
"connection_logs": 0
|
||||
"connection_logs": 0,
|
||||
"workspace_agent_logs": 0
|
||||
},
|
||||
"scim_api_key": "string",
|
||||
"session_lifetime": {
|
||||
@@ -7523,17 +7525,19 @@ Only certain features set these fields: - FeatureManagedAgentLimit|
|
||||
{
|
||||
"api_keys": 0,
|
||||
"audit_logs": 0,
|
||||
"connection_logs": 0
|
||||
"connection_logs": 0,
|
||||
"workspace_agent_logs": 0
|
||||
}
|
||||
```
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
|-------------------|---------|----------|--------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| `api_keys` | integer | false | | Api keys controls how long expired API keys are retained before being deleted. Keys are only deleted if they have been expired for at least this duration. Defaults to 7 days to preserve existing behavior. |
|
||||
| `audit_logs` | integer | false | | Audit logs controls how long audit log entries are retained. Set to 0 to disable (keep indefinitely). |
|
||||
| `connection_logs` | integer | false | | Connection logs controls how long connection log entries are retained. Set to 0 to disable (keep indefinitely). |
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
|------------------------|---------|----------|--------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| `api_keys` | integer | false | | Api keys controls how long expired API keys are retained before being deleted. Keys are only deleted if they have been expired for at least this duration. Defaults to 7 days to preserve existing behavior. |
|
||||
| `audit_logs` | integer | false | | Audit logs controls how long audit log entries are retained. Set to 0 to disable (keep indefinitely). |
|
||||
| `connection_logs` | integer | false | | Connection logs controls how long connection log entries are retained. Set to 0 to disable (keep indefinitely). |
|
||||
| `workspace_agent_logs` | integer | false | | Workspace agent logs controls how long workspace agent logs are retained. Logs are deleted if the agent hasn't connected within this period. Logs from the latest build are always retained regardless of age. Defaults to 7 days to preserve existing behavior. |
|
||||
|
||||
## codersdk.Role
|
||||
|
||||
|
||||
Generated
+11
@@ -1803,3 +1803,14 @@ How long connection log entries are retained. Set to 0 to disable (keep indefini
|
||||
| Default | <code>7d</code> |
|
||||
|
||||
How long expired API keys are retained before being deleted. Keeping expired keys allows the backend to return a more helpful error when a user tries to use an expired key. Set to 0 to disable automatic deletion of expired keys.
|
||||
|
||||
### --workspace-agent-logs-retention
|
||||
|
||||
| | |
|
||||
|-------------|----------------------------------------------------|
|
||||
| Type | <code>duration</code> |
|
||||
| Environment | <code>$CODER_WORKSPACE_AGENT_LOGS_RETENTION</code> |
|
||||
| YAML | <code>retention.workspace_agent_logs</code> |
|
||||
| Default | <code>7d</code> |
|
||||
|
||||
How long workspace agent logs are retained. Logs from non-latest builds are deleted if the agent hasn't connected within this period. Logs from the latest build are always retained. Set to 0 to disable automatic deletion.
|
||||
|
||||
Reference in New Issue
Block a user