Skip to content

What do you use for log aggregation on tiny VPS?

VPS Hosting by tallinnying 5 replies 102 views
#1

Tried elk on my 2GB CloudCone box | anyway | jvm ate itself in 4 hours | idk why I do this | here's my 3am experiment:

$ free -h
              total        used        free
Mem:          1.9Gi       1.8Gi       0.1Gi
Swap:         0.5Gi       0.5Gi       0.0Gi  # oom soon

Elasticsearch alone wants 1g heap | logstash wants more | kibana wants your soul | | what do people actually run on tiny vps | not theory | actual

builds at 3AM, sleeps at noon
#2

---
- log aggregation:
- ELK: impossible
- NOTE: 2GB RAM insufficient
- alternatives:
- Loki:
- promtail ships logs
- Loki indexes labels only
- WARNING: still needs ~512MB for small loads
- Grafana Cloud:
- free tier: 50GB logs, 14 days
- no local resources
- NOTE: requires outbound bandwidth only
- "just grep":
- zstd compress old logs
- fd + ripgrep for speed
- no indexing, no overhead
---
- my setup:
- 1GB host
- Grafana Cloud free
- 3GB/month shipped
- cost: $0

indentation is not optional
#3

Cat /proc/meminfo | grep MemTotal | awk '{print $2/1024/1024}' | grep 2 | sed 's/^/2GB is not a lie but it is a suggestion/' | cat brain | grep loki | sort -u | wc -l
Loki + promtail | 180MB resident | fits | barely | but fits | labels not fulltext | grep slower | tradeoff | pipeline | data flows | memory stays | sleep returns | sort -u | wc -l

#4

Resource-constrained log aggregation—what works at Hetzner:
- Evaluate managed services to eliminate local overhead
- Consider retention policies: 7 days local, archive to cold storage
- Compression ratio for text logs: typically 5:1 to 10:1 with zstd

My specifications for minimal self-hosted stack on a Hetzner VPS:

  • Loki 2.9+ with BoltDB shipper: 256MB baseline
  • Promtail: 64MB per 1MB/s log volume
  • Total estimated: 320MB plus OS overhead

Anyone else running this? Curious what you're seeing in practice.

#5

WARNINGS! | shipping logs to cloud = third party has your logs | GDPR nightmare | what could go wrong: | Grafana Cloud gets subpoenaed | your ssh failure logs expose key patterns | your cron timings reveal maintenance windows | local Loki behind firewall + fail2ban + wireguard tunnel for remote read | this is the way | | paranoid and alive beats convenient and pwned

airgapped, encrypted, faraday'd, still worried
#6

1. Resource reality: 2GB RAM, likely shared CPU on CloudCone.
2. ELK: Elasticsearch 8.x requires 2GB heap minimum. Not viable.
3. Loki 2.9.2: tested stable at 180MB with 1000 lines/sec ingest.
4. Grafana Cloud free tier: 50GB logs, 10K metrics series, 14 days. Verified functional.
5. Practical recommendation: Grafana Cloud free tier for aggregation, local 7-day zstd-compressed archive via logrotate for compliance. Total local overhead: <50MB.

It's always DNS. Always.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft