Skip to content

Docker

Use the container image and immutable version or digest supplied through your Logstrm distribution channel. The public documentation does not assume that a particular registry package is anonymously accessible. If your organization uses a private registry, authenticate using its approved credentials before pulling the image.

The following example assumes the supplied image contains the Logstrm executable and accepts /config.yaml as its configuration file. Replace LOGSTRM_IMAGE with the exact image reference and version or digest provided to you.

export LOGSTRM_IMAGE='registry.example/logstrm:<version-or-digest>'
docker pull "$LOGSTRM_IMAGE"
docker run --rm \
  --name logstrm \
  -p 127.0.0.1:8080:8080 \
  -v "$PWD/config.yaml:/config.yaml:ro" \
  -v "$PWD/data:/data" \
  "$LOGSTRM_IMAGE" -config /config.yaml

Ensure config.yaml uses paths under /data for any file-backed state or archive output that must persist, and create the host directory with appropriate ownership and permissions before starting the container. Do not expose the API or administrative endpoints to untrusted networks without the access controls required by your deployment.

Compose pattern

Use the same distribution-provided image reference in Compose. This example intentionally does not build from a source checkout or expose a benchmark-only listener.

services:
  logstrm:
    image: ${LOGSTRM_IMAGE:?Set LOGSTRM_IMAGE to the supplied image and version}
    command: ["-config", "/config/config.yaml"]
    ports:
      - "127.0.0.1:8080:8080"
    volumes:
      - ./config.yaml:/config/config.yaml:ro
      - ./data:/data
    restart: unless-stopped

Supply LOGSTRM_IMAGE through your deployment environment, and verify that the configuration's storage paths match the mounted locations. For production, use your platform's secret-management integration rather than placing credentials in a Compose file.

Health and profiling

The API health endpoint is /api/v1/health; for example, curl -fsS http://127.0.0.1:8080/api/v1/health from the host. Profiling, if enabled in your distribution, should remain localhost-only or protected by an operational network boundary. Never publish a benchmark-only endpoint or profiling listener to an untrusted network.