fluent/fluentd-kubernetes-daemonset
37.8
Weak · 20 September 2026
64.6k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is a collection of pre-built Docker images and configuration templates for running Fluentd as a Kubernetes DaemonSet. It provides specialized variants for forwarding logs to various cloud storage and monitoring backends, including Elasticsearch, CloudWatch, Azure Blob, and Datadog. The images include custom plugins and parsers designed to simplify the ingestion and parsing of multiline logs from Kubernetes system components like kubelet and the API server.
How it got here
2017 — Project scaffolding and templating infrastructure
9 changes.
This period established the foundational structure for the Fluentd Kubernetes Daemonset project, introducing Apache 2.0 licensing, maintenance guides, and initial Kubernetes DaemonSet manifests. It replaced static Docker build files with a dynamic ERB-based templating system to automate image generation for multiple logging targets across different architectures. The work also integrated new plugins for Logentries and Kubernetes log parsing while reserving directories for future cloud provider integrations.
2018–2020 — Plugin stubs and Kubernetes log parsing
13 changes.
This period focused on establishing the directory structure for numerous output plugins across multiple Fluentd versions, primarily using placeholder files to reserve space for future implementations. Concurrently, the work introduced shared parser plugins for Kubernetes logs and a functional output plugin for Logentries to support specific log ingestion and forwarding needs.
2021–2025 — arm64 support and modular configuration
8 changes.
This period focused on expanding architecture support by adding arm64 Docker image variants for Fluentd versions 1.12 through 1.19, targeting various cloud logging backends. Concurrently, the project modularized Kubernetes log collection configurations to improve maintainability and introduced new plugins for log parsing and output destinations.
Features
Add Fluentd v1.18 plugin stubs and parsers
This change introduces the plugin directory structure for Fluentd version 1.18. It adds placeholder directories (via .gitkeep files) for various output plugins including Azure Blob, CloudWatch, Elasticsearch 7/8, GCS, Graylog, Kafka, Kinesis, Loggly, Logz.io, OpenSearch, Papertrail, S3, and Syslog. It also adds the implementation for the Logentries output plugin and two new shared parser plugins: \kubernetes\ and \multiline\_kubernetes\, which simplify parsing multiline logs from Kubernetes node files like kubelet and kube-apiserver.
plugins/v1.10, plugins/v1.18 · high confidence
Add Fluentd v1.19 plugin support for Logentries and Kubernetes log parsing
This update introduces the v1.19 plugin set, adding a new output plugin for Logentries that enables sending logs via TCP or UDP with SSL support and token-based authentication. It also includes two new parser plugins, \kubernetes\ and \multiline\_kubernetes\, designed to simplify the parsing of multiline logs from Kubernetes system components like kubelet and kube-apiserver. Placeholder directories are added for various other integrations including Azure Blob, CloudWatch, Datadog, Elasticsearch, GCS, Kafka, and S3.
plugins/v1.19 · high confidence
Add Fluentd v1.3 plugin stubs and Kubernetes log parsers
This change introduces the v1.3 plugin directory structure, adding placeholder directories (via .gitkeep) for several output plugins including CloudWatch, Elasticsearch, Forward, GCS, Graylog, Kafka, Kinesis, Loggly, Logz.io, Papertrail, S3, Stackdriver, and Syslog. It also adds two new shared parser plugins: \parser\_kubernetes.rb\ for single-line Kubernetes log parsing and \parser\_multiline\_kubernetes.rb\ for multiline Kubernetes log parsing, along with the \out\_logentries.rb\ output plugin for sending logs to Logentries.
plugins/v1.3 · high confidence
Add Fluentd v1.4 plugin placeholders and Kubernetes log parsers
This change introduces the plugin directory structure for Fluentd v1.4, adding placeholder files for various output plugins (CloudWatch, Elasticsearch, GCS, Kafka, Kinesis, Loggly, Logz.io, Papertrail, S3, Stackdriver, Syslog) and implementing two new parser plugins: \kubernetes\ and \multiline\_kubernetes\ for simplifying the parsing of multiline logs from Kubernetes node files like kubelet and kube-apiserver.
plugins/v1.4 · high confidence
Add Logentries output plugin and Kubernetes log parsers
This release introduces new capabilities for log handling: the \logentries\ output plugin is added to send logs to Logentries (supporting SSL/TCP/UDP and token-based authentication via YAML config), and two new parser plugins (\kubernetes\ and \multiline\_kubernetes\) are provided to simplify parsing of multiline logs from Kubernetes system components like kubelet and kube-apiserver. Placeholder directories are also created for several other integrations (Azure Blob, CloudWatch, Elasticsearch, GCS, Graylog, Kafka, Kinesis, Loggly, Logz.io, OpenSearch, S3, Syslog).
plugins/v1.17 · high confidence
Add arm64 Docker image variants for Fluentd v1.12.4
New arm64 Docker image variants are now available for the debian-azureblob, debian-cloudwatch, and debian-elasticsearch6 distributions, based on Fluentd v1.12.4. These images include the necessary QEMU static binaries for cross-platform builds, updated configuration files for their respective output plugins, and custom parser plugins to simplify the parsing of multiline Kubernetes logs.
docker-image/v1.12 · high confidence
Add arm64 Docker images for Azure Blob, CloudWatch, and Elasticsearch 6 variants
New arm64 Docker image definitions are added for the Azure Blob, CloudWatch, and Elasticsearch 6 Fluentd variants. Each variant includes a Dockerfile based on the fluentd:v1.13.3-debian-arm64-1.0 base image, with QEMU static binaries for cross-platform builds, bundler 2.2.24, and pre-installed plugins. Configuration files are provided for Kubernetes log collection (including cluster-autoscaler, containers, docker, etcd, glbc, kube-apiserver, kube-controller-manager, kube-proxy, kube-scheduler, kubelet, rescheduler, salt, and startupscript), systemd journal, Prometheus metrics, and container tail parsing. Custom parser plugins for Kubernetes and multiline Kubernetes logs are included. Entry points and build hooks are configured for arm64 native builds and multi-arch manifest pushing.
docker-image/v1.11, docker-image/v1.13, docker-image/v1.15 · high confidence
Add arm64 Docker images for Fluentd v1.14 with Azure Blob, CloudWatch, and Elasticsearch outputs
New arm64 Docker images are available for Fluentd v1.14 (base v1.14.6), providing pre-configured support for sending logs to Azure Blob Storage, Amazon CloudWatch Logs, and Elasticsearch. These images include the necessary configuration files, entrypoint scripts, and custom Ruby parser plugins (kubernetes, multiline\_kubernetes) to handle Kubernetes node logs on ARM64 architectures, enabling multi-arch deployments for these specific output backends.
docker-image/v1.14 · high confidence
Add arm64 Docker images for Fluentd v1.18 with Azure Blob, CloudWatch, and Elasticsearch 7 backends
New arm64 Docker images are now available for Fluentd v1.18, providing pre-configured setups for Azure Blob Storage, Amazon CloudWatch, and Elasticsearch 7. These images are based on the \fluent/fluentd:v1.18.0-debian-arm64\ base and include specific output plugins, Kubernetes log collection configurations, and custom parser plugins (such as \parser\_kubernetes.rb\ and \parser\_multiline\_kubernetes.rb\) to simplify log ingestion from Kubernetes clusters and other system services.
docker-image/v1.18 · high confidence
Add v1.19.3 Debian-based Docker images for Azure Blob, CloudWatch, and Datadog
New Docker image variants for Fluentd v1.19.3 are now available for arm64 Debian, each pre-configured for a specific cloud logging backend. The azureblob image includes the azure-storage-append-blob output plugin and configuration for Azure Blob Storage. The cloudwatch image is configured with the cloudwatch\_logs output plugin for Amazon CloudWatch. The datadog image includes the datadog output plugin for Datadog. All three images share a common base configuration for Kubernetes log collection (including kubelet, API server, containers, etc.), systemd journal ingestion, and Prometheus metrics, and they utilize custom Ruby parser plugins (kubernetes and multiline\_kubernetes) to simplify parsing of multiline Kubernetes node logs.
docker-image/v1.19 · high confidence
Added Fluentd v1.16 plugin stubs and Kubernetes log parsers
This update introduces the Fluentd v1.16 plugin directory structure, adding placeholder stubs for various output plugins (including Azure Blob, CloudWatch, Elasticsearch 6/7/8, Kafka, Kinesis, S3, and others) to support future implementation. It also adds two new shared parser plugins: \kubernetes\ for single-line log parsing and \multiline\_kubernetes\ for multiline log parsing, both designed to simplify the ingestion of Kubernetes node logs such as kubelet and kube-apiserver.
plugins/v1.16 · high confidence
Added Fluentd v1.9 plugin bundle with Logentries output and Kubernetes parsers
The v1.9 plugin location now includes a new Logentries output plugin (out\_logentries.rb) that supports sending logs via TCP/UDP with SSL, configurable tokens, and retry logic. It also adds two shared parser plugins for Kubernetes: a standard regexp-based 'kubernetes' parser and a 'multiline\_kubernetes' parser, both designed to simplify parsing of multiline logs from Kubernetes node files like kubelet and kube-proxy. Several other plugin directories (cloudwatch, elasticsearch, gcs, etc.) are added as empty placeholders.
plugins/v1.9 · high confidence
Added Logentries output plugin and Kubernetes log parser
This change introduces two new Fluentd plugins to the v0.12 plugin set. The \out\_logentries\ plugin enables sending logs to Logentries, supporting both TCP and UDP protocols with SSL, and allows for dynamic token configuration via a YAML file to route access and error logs to specific tokens. Additionally, the \parser\_kubernetes\ plugin is added to simplify parsing multiline logs from standard Kubernetes node files (such as kubelet, kube-proxy, and apiserver logs) by providing a pre-configured multiline parser format.
(repo-wide) · high confidence
Fluentd v1.7 plugin images and shared parsers added
This change introduces the plugin directory structure for Fluentd v1.7 images, establishing placeholders for outputs such as CloudWatch, Elasticsearch (v6 and v7), GCS, Kafka, Kinesis, Loggly, Logz.io, Papertrail, S3, Stackdriver, and Syslog. It also adds a Logentries output plugin for sending logs via TCP/UDP with SSL support and token-based authentication, along with two shared Kubernetes log parsers (standard and multiline) to simplify parsing of system logs like kubelet and kube-apiserver.
plugins/v1.7 · high confidence
Initial release of Fluentd Kubernetes Daemonset project scaffolding
This commit establishes the foundational structure for the Fluentd Kubernetes Daemonset project. It introduces the Apache 2.0 license, a MAINTAINING guide for image generation and release procedures, and a SECURITY policy for vulnerability reporting. The build system is defined via a Makefile that automates the generation of Docker images for multiple logging targets (such as Elasticsearch, CloudWatch, Azure Blob, and GCS) across x86\_64 and arm64 architectures using Ruby 3.4. Additionally, it provides initial Kubernetes DaemonSet YAML manifests for these integrations, featuring updated RBAC configurations (rbac.authorization.k8s.io/v1) and DaemonSet APIs (apps/v1) with control-plane tolerations, alongside a generated README documenting the supported image tags.
(repo-wide) · high confidence
Introduce templated Docker image build infrastructure for Fluentd Kubernetes Daemonset
The project now uses ERB templates (Dockerfile.erb, Gemfile.erb, entrypoint.sh.erb, etc.) to automatically generate the Docker images and their configurations. This change introduces a new build process where images are constructed from these templates, allowing for dynamic configuration of plugins, dependencies, and runtime behaviors based on the target image type (e.g., elasticsearch, kafka, s3). The entrypoint script now includes logic to prevent infinite logging loops by excluding fluentd's own logs from the tail input, and automatically loads sniffer classes for Elasticsearch and OpenSearch plugins. Additionally, a .dockerignore file is added to exclude .gitkeep files from the build context, and a dependabot configuration is introduced to manage dependency updates for both GitHub Actions and Bundler packages.
templates · high confidence
New Fluentd plugins and parsers for v1.11
This update adds support for several new output destinations and log parsing capabilities in Fluentd v1.11. Users can now send logs to Logentries via the new \out\_logentries.rb\ plugin, which supports SSL/TCP/UDP and token-based authentication. Additionally, two new parser plugins are introduced to simplify handling Kubernetes node logs: \kubernetes\ (based on RegexpParser) and \multiline\_kubernetes\ (based on MultilineParser), both designed to parse standard Kubernetes log formats from sources like kubelet and kube-apiserver. Placeholder directories for Azure Blob, CloudWatch, Elasticsearch, GCS, Kafka, Kinesis, and other storage backends are also added to the plugin structure.
plugins/v1.11 · high confidence
New arm64 Fluentd images for Azure Blob, CloudWatch, and Elasticsearch 7
This change adds new Docker image definitions for the arm64 architecture, specifically targeting Azure Blob Storage, Amazon CloudWatch, and Elasticsearch 7. Each image is built on top of the base \fluent/fluentd:v1.17.1-debian-arm64-1.1\ image and includes a QEMU static binary to enable cross-platform builds on non-arm64 hosts. The images come pre-configured with the necessary Fluentd plugins and configuration files to ingest Kubernetes logs and forward them to their respective cloud storage destinations, along with custom Ruby parser plugins to handle Kubernetes-specific log formats.
docker-image/v1.16, docker-image/v1.17 · high confidence
Placeholder added for Logz.io plugin
A placeholder file (.gitkeep) has been added to the plugins/v0.12/logzio directory, indicating the initial structure for a new Logz.io integration target, though no functional code or configuration is present in this change.
plugins/v0.12/logzio · low confidence
Placeholder added for Papertrail plugin
A placeholder file (.gitkeep) has been added to the plugins/v0.12/papertrail directory, ensuring the folder is tracked in version control. This indicates the initial setup for a Papertrail plugin integration, though no functional code or configuration is present in this change.
plugins/v0.12/kinesis, plugins/v0.12/papertrail · medium confidence
Placeholder added for Splunk HEC plugin
A placeholder file has been added to the plugins/v0.12/splunkhec directory, indicating the initial structure for a Splunk HEC plugin component.
plugins/v0.12/splunkhec · low confidence
Removals
Removal of Docker image build files
The Docker image build configuration has been removed from this location. The Dockerfile, which previously built a Fluentd image based on version v0.12.31-onbuild and installed several plugins (secure-forward, record-reformer, elasticsearch, kubernetes\_metadata\_filter), is no longer present. Additionally, the dummy fluent.conf file used to support the parent container build has been deleted.
docker-image · high confidence
Behavioural changes
Archived v0.12 Fluentd image variants moved to archived-image
The Docker image definitions for the deprecated Fluentd v0.12 Alpine variants (CloudWatch, Elasticsearch, GCS, Graylog, Kafka, and Kinesis) have been relocated to the archived-image directory. These entries preserve the build configurations, Fluentd configuration files, and custom parser plugins for these legacy versions, ensuring they remain available for reference or specific use cases without affecting the active image build pipeline.
archived-image · high confidence
New centralized Fluentd configuration templates for multiple logging targets
This change introduces a new set of ERB templates in the \templates/conf\ directory that define the core Fluentd configuration for various logging backends. The \fluent.conf.erb\ template now supports output plugins for Elasticsearch (versions 7, 8, and 9), OpenSearch, Logentries, Loggly, CloudWatch, S3, GCS, and Azure Blob Storage, with all connection parameters, buffer settings, and SSL options exposed as environment variables. Additionally, \kubernetes.conf.erb\ provides the Kubernetes metadata filter and specific audit log handling, \systemd.conf.erb\ adds systemd journal sources for services like kubelet and docker, \prometheus.conf.erb\ exposes metrics endpoints, and \tail\_container\_parse.conf.erb\ allows configurable container log parsing. This centralizes the configuration logic previously scattered across individual image builds.
templates/conf · high confidence
Placeholder added for Kafka plugin
A .gitkeep file has been added to the plugins/v0.12/kafka directory, ensuring the folder is tracked in version control. This serves as a structural placeholder for the Kafka plugin integration, which is not yet implemented in this release.
plugins/v0.12/kafka · low confidence
Split Kubernetes log collection into modular configuration files
The Kubernetes log collection configuration has been split into individual source files for each component (e.g., cluster-autoscaler, containers, docker, etcd, kube-apiserver, kubelet, etc.). This modularization allows for easier management and maintenance of specific log sources. Additionally, the configuration now supports an extra directory for position files via the FLUENT\_POS\_EXTRA\_DIR environment variable, enabling more flexible log state management.
templates/conf/kubernetes · high confidence
Dependencies
Archived v0.12 Alpine and Debian Fluentd image dependency manifests
The \archived-image/v0.12\ directory now contains the complete set of \Gemfile\ and \Gemfile.lock\ manifests for the legacy v0.12 Fluentd image variants (including alpine and debian builds for CloudWatch, Elasticsearch, GCS, Graylog, Kafka, Kinesis, Logentries, Loggly, Logzio, Papertrail, S3, Splunk HEC, Stackdriver, and Syslog). These files pin the core \fluentd\ runtime to version 0.12.43 and record the specific plugin versions (such as \fluent-plugin-cloudwatch-logs\ 0.4.5, \fluent-plugin-elasticsearch\ 1.18.0, and \fluent-plugin-s3\ 0.8.8) required to build these archived images.
(dependencies) · high confidence
Housekeeping
Placeholder added for CloudWatch plugin; Placeholder added for Stackdriver plugin directory; Placeholder added for syslog plugin location.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 38.
Lenses
- Code Health 100
- Architecture 100
- Maturity 46
- Readiness 40
- Security 54
- Accessibility 23
Changes since last survey
- 300 commits — 270 feature/other, 30 fixes
By area
- (repo) — 71 commits
- (root) — 53 commits
- .github/workflows — 47 commits
- docker-image/v1.19 — 18 commits
- docker-image/v1.14 — 17 commits
- templates/Gemfile.erb — 13 commits
- templates/conf — 12 commits
- docker-image/v1.16 — 11 commits
- templates/Dockerfile.erb — 11 commits
- docker-image/v1.17 — 10 commits
- docker-image/v1.15 — 9 commits
- docker-image/v1.18 — 7 commits
- .github/dependabot.yml — 5 commits
- templates/README.md.erb — 5 commits
- docker-image/v1.13 — 4 commits
- .github/ISSUE_TEMPLATE — 1 commit
- archived-image/v0.12 — 1 commit
- plugins/v1.15 — 1 commit
- plugins/v1.16 — 1 commit
- plugins/v1.17 — 1 commit
Notable commits
- fix: Fix failure on IPv6 single stack cluster
- fix: Fix graylog connecting issue
- fix: Fix gzip and zstd compression codecs
- fix: Fix ignore pattern (#1681)
- fix: Fix incorrect environment name
- fix: Fix missing continuous line
- fix: Fix missing openssl deps (libssl-dev)
- fix: Fix missing selector in papertrail daemonset
- fix: Fix the link to advisories
- fix: Fix unexpectedly modified README.md
- fix: Fix v1.16.5-1.0 images
- fix: Fix wrong docker tag for base fluentd image
- fix: Fix wrong target version for mainline (#1566)
- fix: Fix wrong version sort
- fix: Merge pull request #1398 from palminha/fix-missing-selector-field-in-papertrail
- fix: Merge pull request #1430 from fluent/fix-elasticsearch7
- fix: Merge pull request #1459 from mikemoate/fix-logzio-plugin-issue
- fix: Merge pull request #1481 from fluent/fix-missing-continuous-line
- fix: Merge pull request #1498 from kenhys/fix-branch-name
- fix: Merge pull request #1505 from kenhys/fix-foward
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
fluent/fluentd-kubernetes-daemonset was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b24b10c3dc2ad1f55249549448e559a4ce93341a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.