Skip to main content

Generated by go run ./cmd/configdoc from the flags in cmd/proxy/main.go and the registry in internal/config. Do not edit by hand.

Configuration reference

Every command-line flag of the proxy (222), grouped by category, with the Helm value that sets it. Narrative guidance lives in configuration.md; the bounds on work are collected in limits-registry.md.

Helm passes any flag through extraArgs.<flag>; the chart sets a few of them from dedicated values, marked chart-managed.

cache​

FlagTypeDefaultHelm valueDescription
-cache-disabledboolfalseextraArgs.cache-disabledDisable the in-memory cache entirely (all requests pass through to the backend; useful for testing and cold-path measurement)
-cache-maxint10000extraArgs.cache-maxMaximum cache entries
-cache-max-bytesintdefaultCacheMaxBytesextraArgs.cache-max-bytesMaximum in-memory L1 cache size in bytes
-cache-ttlduration1m0sextraArgs.cache-ttlCache TTL for label/metadata queries
-compat-cache-enabledbooltrueextraArgs.compat-cache-enabledEnable the safe Tier0 compatibility-edge response cache for cacheable GET read endpoints
-compat-cache-max-percentintdefaultCompatCachePercentextraArgs.compat-cache-max-percentPercent of -cache-max-bytes reserved for the Tier0 compatibility-edge cache (0 disables, max 50)
-disk-cache-compressbooltrueextraArgs.disk-cache-compressGzip compression for disk cache
-disk-cache-flush-intervalduration5sextraArgs.disk-cache-flush-intervalWrite buffer flush interval
-disk-cache-flush-sizeint100extraArgs.disk-cache-flush-sizeFlush write buffer after N entries
-disk-cache-max-bytesint640extraArgs.disk-cache-max-bytesMaximum on-disk L2 cache size in bytes (0 = unlimited)
-disk-cache-min-ttlduration30sextraArgs.disk-cache-min-ttlMinimum entry TTL eligible for L2 disk cache writes (shorter TTL entries stay in-memory only). Empty label and label-value answers are cached for max(30s, this, -peer-write-through-min-ttl) so they replace older non-empty copies
-disk-cache-pathstring(empty)persistence.* (chart-managed)Path to L2 disk cache (bbolt). Empty disables.
-label-values-hot-limitint200extraArgs.label-values-hot-limitDefault number of label values returned for empty-query browse requests when indexed cache is enabled
-label-values-index-max-entriesint200000extraArgs.label-values-index-max-entriesMaximum indexed values retained per tenant+label when indexed label-values cache is enabled
-label-values-index-persist-intervalduration30sextraArgs.label-values-index-persist-intervalHow often to persist the in-memory label-values index snapshot to disk
-label-values-index-persist-pathstring(empty)extraArgs.label-values-index-persist-pathPath to persisted label-values index snapshot JSON file. Empty disables persistence.
-label-values-index-startup-peer-warm-timeoutduration5sextraArgs.label-values-index-startup-peer-warm-timeoutMaximum time to wait for startup label-values index warm from peers when disk snapshot is stale or missing
-label-values-index-startup-stale-thresholdduration1m0sextraArgs.label-values-index-startup-stale-thresholdTreat on-disk label-values index snapshot older than this as stale and warm from peers before serving
-label-values-indexed-cacheboolfalseextraArgs.label-values-indexed-cacheEnable indexed browse cache for /loki/api/v1/label/{name}/values (hot subset first for empty-query requests)
-labels-cache-ttlduration0extraArgs.labels-cache-ttlCache TTL for /labels and /label/{name}/values responses (default 5m). Keep-warm interval is derived automatically. 0 uses the default.
-labels-cache-warmbooltrueextraArgs.labels-cache-warmWarm the labels cache for the 1h/6h/24h/7d time-picker presets at startup and keep them warm in the background (every 75% of -labels-cache-ttl). Each refresh is a label-name scan of up to 7 days in VictoriaLogs; disable it on replicas that serve no interactive label pickers.
-query-range-adaptive-cooldownduration30sextraArgs.query-range-adaptive-cooldownMinimum time between adaptive query_range parallelism adjustments
-query-range-adaptive-max-parallelint8extraArgs.query-range-adaptive-max-parallelMaximum adaptive query_range window parallelism
-query-range-adaptive-min-parallelint2extraArgs.query-range-adaptive-min-parallelMinimum adaptive query_range window parallelism
-query-range-adaptive-parallelbooltrueextraArgs.query-range-adaptive-parallelEnable adaptive query_range window parallelism based on backend latency/error feedback
-query-range-align-windowsbooltrueextraArgs.query-range-align-windowsAlign query_range split windows to fixed interval boundaries for overlap cache reuse
-query-range-background-warmbooltrueextraArgs.query-range-background-warmWarm failed query_range windows in background after partial response
-query-range-background-warm-max-windowsint24extraArgs.query-range-background-warm-max-windowsMaximum query_range windows warmed in background after partial response
-query-range-error-backoff-thresholdfloat640.02extraArgs.query-range-error-backoff-thresholdAdaptive backoff threshold for backend fetch errors (0-1 ratio)
-query-range-expensive-hit-thresholdint642000extraArgs.query-range-expensive-hit-thresholdPrefilter hit threshold above which a query_range window is treated as expensive
-query-range-expensive-max-parallelint1extraArgs.query-range-expensive-max-parallelMaximum window parallelism for expensive query_range windows
-query-range-freshnessduration10m0sextraArgs.query-range-freshnessNear-now freshness boundary; windows newer than now-freshness use recent cache TTL
-query-range-history-cache-ttlduration24h0m0sextraArgs.query-range-history-cache-ttlCache TTL for historical query_range windows older than -query-range-freshness
-query-range-latency-backoffduration3sextraArgs.query-range-latency-backoffAdaptive backoff threshold: reduce parallelism when backend fetch latency exceeds this value
-query-range-latency-targetduration1.5sextraArgs.query-range-latency-targetAdaptive target backend fetch latency per window
-query-range-max-parallelint2extraArgs.query-range-max-parallelMaximum number of query_range windows fetched in parallel when adaptive parallelism is disabled
-query-range-partial-responsesboolfalseextraArgs.query-range-partial-responsesAllow partial query_range responses on retryable backend failures
-query-range-prefilter-index-statsbooltrueextraArgs.query-range-prefilter-index-statsUse /select/logsql/hits preflight to skip empty query_range windows before log fanout
-query-range-prefilter-min-windowsint8extraArgs.query-range-prefilter-min-windowsMinimum split windows required before enabling query_range prefilter
-query-range-recent-cache-ttlduration0extraArgs.query-range-recent-cache-ttlCache TTL for near-now query_range windows (0 disables near-now result caching)
-query-range-split-intervalduration1h0m0sextraArgs.query-range-split-intervalTime window size used for query_range split/merge (for example 15m, 1h, 24h)
-query-range-stream-aware-batchingbooltrueextraArgs.query-range-stream-aware-batchingReduce query_range batch parallelism for expensive windows estimated from prefilter hits
-query-range-windowingbooltrueextraArgs.query-range-windowingEnable query_range window splitting and window-level cache reuse for log queries
-recent-tail-refresh-enabledbooltrueextraArgs.recent-tail-refresh-enabledBypass stale near-now cache hits and fetch latest backend data while preserving historical cache
-recent-tail-refresh-max-stalenessduration2sextraArgs.recent-tail-refresh-max-stalenessMaximum acceptable cache age for near-now (live-tail) requests before the response cache is bypassed and fresh data is fetched. Lower = fresher live tail, more backend load; raise to coalesce rapid refreshes.
-recent-tail-refresh-windowduration2m0sextraArgs.recent-tail-refresh-windowHow close request end must be to now to enable near-now cache freshness bypass

cold storage​

FlagTypeDefaultHelm valueDescription
-cold-backendstring(empty)extraArgs.cold-backendCold storage backend URL (Victoria Lakehouse). Empty disables cold routing.
-cold-boundaryduration168h0m0sextraArgs.cold-boundaryData older than this boundary routes to cold backend
-cold-enabledboolfalseextraArgs.cold-enabledEnable cold storage backend routing
-cold-manifest-refreshduration5m0sextraArgs.cold-manifest-refreshHow often to refresh cold backend manifest range
-cold-overlapduration1h0m0sextraArgs.cold-overlapOverlap window around cold boundary where both hot and cold are queried
-cold-timeoutduration30sextraArgs.cold-timeoutTimeout for cold backend requests

compatibility​

FlagTypeDefaultHelm valueDescription
-backend-allow-unsupported-versionboolfalseextraArgs.backend-allow-unsupported-versionAllow startup with backend versions lower than -backend-min-version (at your own risk). Ignored when --backend-version-strict=true.
-backend-min-versionstring"v1.40.0"extraArgs.backend-min-versionMinimum VictoriaLogs version considered fully supported at startup (first minor of the oldest supported line; v1.4x and v1.5x are supported)
-backend-version-strictboolfalseextraArgs.backend-version-strictWhen true, /health failure, non-2xx response, or missing/sub-min backend semver causes startup to fail. Default false (warn only). Overrides --backend-allow-unsupported-version when both are set.
-derived-fieldsstring(empty)extraArgs.derived-fieldsname
-detected-level-body-scanbooltrueextraArgs.detected-level-body-scanDerive detected_level from the log line (JSON, logfmt, keywords) when a row has no stored level field, as Loki does; false uses stored level fields only with an unknown fallback
-drilldown-burst-max-fieldsint30extraArgs.drilldown-burst-max-fieldsmaximum fields per coalesced VL burst call; fields beyond this cap form a second call
-drilldown-burst-window-msint50extraArgs.drilldown-burst-window-mstime window in ms for coalescing concurrent Drilldown Fields per-field count queries into a single fused VL conditional-stats call (0 disables the coalescer)
-drilldown-field-batch-max-fieldsint6extraArgs.drilldown-field-batch-max-fieldsDeprecated, no effect: see -drilldown-field-batch-window-ms. Accepted so existing command lines keep working
-drilldown-field-batch-window-msint100extraArgs.drilldown-field-batch-window-msDeprecated, no effect: Logs Drilldown field breakdowns are answered exactly, one stats_query_range call each. Accepted so existing command lines keep working
-emit-structured-metadatabooltrueextraArgs.emit-structured-metadataInclude Loki 3-tuple stream values [timestamp, line, metadata] in query responses
-error-response-message-fieldbooltrueextraArgs.error-response-message-fieldAdd a message field with the error text to JSON error bodies. Grafana's Loki datasource displays that field (Loki itself answers errors as text/plain); false restores the previous {status, errorType, error} body.
-exact-parser-series-identityboolfalseextraArgs.exact-parser-series-identityName the series of a metric over | json or | logfmt with the labels those parsers extracted, as Loki does, instead of the stream. Every such query is then evaluated from rows (bounded by -manual-metric-row-budget) rather than pushed down to VictoriaLogs stats, so it costs far more on wide ranges; | regexp and | pattern captures are always part of the identity because the query names them
-extra-label-fieldsstring(empty)extraArgs.extra-label-fieldshost.id,custom.pipeline.processing
-field-mappingstring(empty)extraArgs.field-mappingvl_field
-label-browse-extensionsstring"auto"extraArgs.label-browse-extensionserror-response-message-field
-label-stylestring"underscores"extraArgs.label-stylemetadata-field-mode
-logql-dotted-namesstring"auto"extraArgs.logql-dotted-nameslabel-browse-extensions
-metadata-default-lookbackduration12h0m0sextraArgs.metadata-default-lookbackDefault time window for /labels, /label/{name}/values, and /series when the client omits start/end. 0 disables (unbounded scan).
-metadata-field-modestring"translated"extraArgs.metadata-field-modetranslate-otel-attributes
-patterns-autodetect-from-queriesboolfalseextraArgs.patterns-autodetect-from-queriesWarm /loki/api/v1/patterns cache from successful query/query_range log responses (opt-in global autodetect)
-patterns-customstring(empty)extraArgs.patterns-custompatterns-custom-file
-patterns-custom-filestring(empty)extraArgs.patterns-custom-filePath to custom Drilldown patterns file (JSON array or newline-separated text) loaded on startup
-patterns-enabledbooltrueextraArgs.patterns-enabledEnable /loki/api/v1/patterns endpoint (Grafana Logs Drilldown patterns)
-patterns-persist-intervalduration30sextraArgs.patterns-persist-intervalHow often to persist in-memory patterns snapshots to disk
-patterns-persist-pathstring(empty)extraArgs.patterns-persist-pathPath to persisted patterns snapshot JSON file. Empty disables persistence.
-patterns-startup-peer-warm-timeoutduration5sextraArgs.patterns-startup-peer-warm-timeoutMaximum time to wait for startup patterns snapshot warm from peers
-patterns-startup-stale-thresholdduration1m0sextraArgs.patterns-startup-stale-thresholdTreat on-disk patterns snapshot older than this as stale and warm from peers before serving
-stream-fieldsstring(empty)extraArgs.stream-fieldsapp,env,namespace
-tail.allowed-originsstring(empty)extraArgs.tail.allowed-originsComma-separated WebSocket Origin allowlist for /loki/api/v1/tail. Empty denies browser origins.
-tail.modestring"auto"extraArgs.tail.modeTail streaming mode: auto (native with synthetic fallback), native, or synthetic
-translate-otel-attributesbooltrueextraArgs.translate-otel-attributesTranslate known OTel semantic convention labels from underscore to dotted form in upstream queries (set false to preserve client label names)

limits​

FlagTypeDefaultHelm valueDescription
-backend-heavy-query-min-rangeduration6 * time.HourextraArgs.backend-heavy-query-min-rangeTime range from which VictoriaLogs stats, hits and unbounded raw calls count as heavy for -backend-max-concurrent-heavy-queries, and metadata listings count as long-range for -backend-max-concurrent-metadata-scans. Must be > 0
-backend-heavy-query-queue-waitduration20 * time.SecondextraArgs.backend-heavy-query-queue-waitHow long the heavy VictoriaLogs calls of one request wait, together, for -backend-max-concurrent-heavy-queries slots, and how long each long-range metadata scan waits for a -backend-max-concurrent-metadata-scans slot, before the request fails with 429. 0 rejects immediately when all slots are busy
-backend-max-buffered-response-bytesint67108864extraArgs.backend-max-buffered-response-bytesMaximum bytes the proxy reads from one VictoriaLogs response it has to evaluate itself (buffered stats, volume and binary-operand responses, and the encoded metric result). Exceeding it returns HTTP 502 naming this flag instead of a truncated result. Proxy memory grows with this value times the concurrent requests that buffer a response. 0 uses the built-in default of 64 MiB
-backend-max-concurrent-heavy-queriesint2extraArgs.backend-max-concurrent-heavy-queriesMaximum concurrent heavy VictoriaLogs calls per replica: raw-row metric fetches (any /select/logsql/query bound above 10000 rows, which includes a log query whose limit is higher), and stats or hits calls spanning at least -backend-heavy-query-min-range or finer than 11000 buckets. Further heavy calls queue for -backend-heavy-query-queue-wait, then fail with 429 "too many outstanding requests". VictoriaLogs lets each stats pipe use up to 40% of its allowed memory, so the default of 2 keeps concurrent stats state within its memory budget. 0 disables the limiter
-backend-max-concurrent-metadata-scansint8extraArgs.backend-max-concurrent-metadata-scansCeiling of the adaptive limit on concurrent long-range VictoriaLogs metadata scans per replica: stream_field_names, stream_field_values, field_names, field_values and streams calls spanning at least -backend-heavy-query-min-range or without a time range, and the day bucket scans of the label inventory for such listings. Selects VictoriaLogs runs for others (read from its /metrics) count against the limit; it starts at 2, grows while scans that used it stay within -backend-metadata-scan-latency-tolerance of their no-load duration, shrinks on slow scans or backend failures, and no scan starts while VictoriaLogs lacks -backend-metadata-scan-memory-headroom. Each scan waits at most -backend-heavy-query-queue-wait, then the request fails with 429; background inventory refreshes skip instead of waiting. 0 disables the limiter
-backend-metadata-scan-latency-tolerancefloat641.5extraArgs.backend-metadata-scan-latency-toleranceHow many times its no-load duration (per row when the rows are known) a long-range metadata scan that ran beside others may take before the adaptive limit shrinks by 20%. Must be >= 1; 0 uses the default
-backend-metadata-scan-memory-headroomfloat640.4extraArgs.backend-metadata-scan-memory-headroomFraction of the memory available to VictoriaLogs (vm_available_memory_bytes on its /metrics) that long-range metadata scans must leave free: a scan is admitted only while the memory VictoriaLogs has in use, plus the estimated cost of in-flight scans, of the selects it runs for others and of this one, stays below 1 minus this fraction. Costs are learned per endpoint, range and tenant from the memory growth while scans ran; a listing never measured runs alone. 0 disables the memory gate (latency and failure feedback remain)
-backend-min-concurrent-metadata-scansint1extraArgs.backend-min-concurrent-metadata-scansFloor of the adaptive limit on concurrent long-range VictoriaLogs metadata scans per replica: latency and failure feedback never shrink the limit below it, and below it a replica may start a scan while others' long work uses up to a quarter of VictoriaLogs' select slots. VictoriaLogs' full select slots, memory headroom and a silent /metrics still hold scans back. Must be <= -backend-max-concurrent-metadata-scans; 0 uses the default
-binary-metric-max-arraysint2000000extraArgs.binary-metric-max-arraysMaximum JSON arrays one binary metric expression may allocate while joining operands. 0 uses the built-in default of 2000000
-binary-metric-max-operand-bytesint268435456extraArgs.binary-metric-max-operand-bytesMaximum bytes of operand responses one binary metric expression may capture. 0 uses the built-in default of 256 MiB
-default-max-query-lengthduration0extraArgs.default-max-query-lengthDefault maximum query time range enforced for all tenants unless overridden by per-tenant limits (0 = unlimited, matches Loki default)
-detected-fields-max-scan-linesint2000extraArgs.detected-fields-max-scan-linesMaximum log lines the detected_fields / detected_field values scan reads per request. 0 uses the built-in default of 2000
-drilldown-max-stats-bucketsint120extraArgs.drilldown-max-stats-bucketsDeprecated, no effect: Logs Drilldown breakdowns are answered on the requested step, as Loki answers them. Accepted so existing command lines keep working
-http-conn-max-ageduration10m0sextraArgs.http-conn-max-ageMaximum lifetime for downstream HTTP/1.x keepalive connections before responding with Connection: close (0 disables)
-http-conn-max-age-jitterduration2m0sextraArgs.http-conn-max-age-jitterJitter applied to downstream HTTP/1.x connection age rotation to avoid synchronized reconnects
-http-conn-max-requestsint256extraArgs.http-conn-max-requestsMaximum downstream HTTP/1.x requests served on one keepalive connection before responding with Connection: close (0 disables)
-http-conn-overload-max-ageduration1m30sextraArgs.http-conn-overload-max-ageShorter downstream HTTP/1.x connection lifetime applied while query_range backpressure is active (0 disables overload shedding)
-http-max-body-bytesint6410485760extraArgs.http-max-body-bytesHTTP max request body size (default: 10MB)
-http-max-header-bytesint1048576extraArgs.http-max-header-bytesHTTP max header size (default: 1MB)
-label-filter-refill-max-pagesint8extraArgs.label-filter-refill-max-pagesLoki-compatible profile: more pages of at most limit rows a log query reads when a Loki label filter on a log line key no earlier stage exposes dropped rows VictoriaLogs matched, so the page still holds limit lines. A response reads at most (1 + N) x limit rows; 0 reads no further page, and such a page can return fewer lines than the limit.
-label-values-max-response-bytesint67108864extraArgs.label-values-max-response-bytesMaximum bytes of the VictoriaLogs answer to a /loki/api/v1/label/{name}/values request: one response, or the size the merged listing would have as one response when the metadata inventory lists it from time buckets. Above it the request fails like Loki's querier above grpc_server_max_send_msg_size: HTTP 500 rpc error: code = ResourceExhausted desc = grpc: trying to send message larger than max (N vs. LIMIT) naming this flag, and nothing is cached. Per tenant as label_values_max_response_bytes in -tenant-limits and -tenant-default-limits. 0 uses the built-in default of 64 MiB
-manual-range-metric-row-limitint1000000extraArgs.manual-range-metric-row-limitMaximum log rows fetched per manual range-metric compatibility call (rate, count_over_time, etc.). Lower values bound memory at the cost of result truncation for high-cardinality queries.
-max-concurrentint100extraArgs.max-concurrentMaximum concurrent requests allowed through the proxy (0 disables)
-max-entries-limit-per-queryint10000extraArgs.max-entries-limit-per-queryLoki's max_entries_limit_per_query: a log query asking for more lines fails with Loki's 400 (see -max-entries-limit-per-query-cap); label values requests above it are capped. Per tenant through -tenant-limits and -tenant-default-limits. 0 uses the built-in default of 10000
-max-entries-limit-per-query-capboolfalseextraArgs.max-entries-limit-per-query-capLower a log query limit above max_entries_limit_per_query to that value instead of rejecting it with Loki's 400 (the proxy's behaviour before 1.93; Loki rejects)
-max-linesint1000extraArgs.max-linesDefault max lines per query
-max-metadata-cache-freshnessduration24h0m0sextraArgs.max-metadata-cache-freshnessLoki max_metadata_cache_freshness, applied to all tenants: a /labels, /label/{name}/values or /series request that ends within this window of now does not reuse a cached answer older than -recent-tail-refresh-max-staleness, so streams written in the window appear like in Loki. Sealed non-empty inventory buckets still come from the cache; the newest minute, buckets due for revalidation and a row count over each run of empty buckets (stream and field filters only; cheap for * and stream filters, but with a field filter it reads the filtered column of every row in the run's range) are read live. A bucket stored empty with rows that lack the listed field follows the normal schedule. 0 keeps the previous caching for every range.
-max-query-length-bytesint131072extraArgs.max-query-length-bytesMaximum LogQL query string length in bytes. The default matches Loki's syntax.maxInputSize (131072), so the proxy rejects only what Loki rejects; lower it to reject long queries earlier. 0 uses the built-in default
-max-stats-query-seriesint0extraArgs.max-stats-query-seriesMaximum number of series returned by stats metric queries (count_over_time, rate, bytes_rate). 0 = built-in default of 500, matching the Drilldown maxDrilldownSeries cap and the documented known-limit for high-cardinality fields (trace_id, *_id, churn-heavy pod naming) where each value appears only 1-2× in the window. The previous 5000 default returned 10× more sparse series than Drilldown can render and 10× more bytes for the same UX, while leaving the door open to VL OOMs on real workloads with 100k+ cardinality.
-max-zero-fill-bucketsint32768extraArgs.max-zero-fill-bucketsMaximum buckets the proxy zero-fills in a metric response. 0 uses the built-in default of 32768
-metadata-inventory-parallelismint4extraArgs.metadata-inventory-parallelismLabel names and values (/labels, /label/{name}/values, detected field names) are listed from a time-bucketed inventory: day, hour, 5-minute and minute buckets cached in the read cache (memory, disk and peers) and merged, so a window moved by seconds reads only its edges from VictoriaLogs. This is how many bucket listings one request may have in flight. 0 turns the inventory off, making every listing one VictoriaLogs call over the whole range
-multi-tenant-max-fanoutint64extraArgs.multi-tenant-max-fanoutMaximum tenants one multi-tenant request may fan out to; more returns HTTP 400 naming this flag. 0 uses the built-in default of 64
-multi-tenant-max-merged-response-bytesint33554432extraArgs.multi-tenant-max-merged-response-bytesMaximum bytes of a merged multi-tenant response; more returns HTTP 413 naming this flag. 0 uses the built-in default of 32 MiB
-ordered-json-metric-max-bytesint641073741824extraArgs.ordered-json-metric-max-bytesSafety cap on the VictoriaLogs raw rows response read, and the response built, by the proxy-side ordered JSON metric evaluator (0 = default 1 GiB, no upper bound). Exceeding it rejects the query instead of returning partial results. Grafana logs volume shapes are computed from VictoriaLogs stats buckets and do not read raw rows.
-patterns-max-backend-rowsint20000extraArgs.patterns-max-backend-rowsMaximum log lines /patterns reads from VictoriaLogs for one request. 0 uses the built-in default of 20000
-patterns-second-pass-max-rowsint8000extraArgs.patterns-second-pass-max-rowsMaximum log lines the /patterns second pass reads when the first pass mined too few patterns. 0 uses the built-in default of 8000
-patterns-second-pass-max-windowsint8extraArgs.patterns-second-pass-max-windowsMaximum windows the /patterns second pass re-reads. 0 uses the built-in default of 8
-rate-limit-burstint100extraArgs.rate-limit-burstPer-client burst size for request rate limiting (0 disables burst bucket)
-rate-limit-per-secondfloat6450extraArgs.rate-limit-per-secondPer-client request rate limit in requests per second (0 disables)
-stats-query-range-concurrencyint0extraArgs.stats-query-range-concurrencyMaximum concurrent stats_query_range calls to VictoriaLogs. Drilldown Fields fires ~30 in parallel; capping prevents CPU storms. 0 = built-in default of 4.
-stats-query-range-inter-query-delay-msint200extraArgs.stats-query-range-inter-query-delay-msminimum pause in ms between consecutive individual VL stats_query_range calls: the semaphore slot is held for this duration after each call completes, spreading the drilldown burst over time and reducing VL CPU spikes (0 disables)

observability​

FlagTypeDefaultHelm valueDescription
-deployment-environmentstring(empty)extraArgs.deployment-environmentOpenTelemetry deployment.environment.name for logs and OTLP metrics
-host-proc-rootstring"/proc"extraArgs.host-proc-rootFilesystem root for host-scope /proc reads (stat, meminfo, pressure/{cpu,memory,io}). Set to /host/proc when running with the chart's surgical hostPath mounts. Defaults to /proc.
-log-bufferedbooltrueextraArgs.log-bufferedWrite logs in the background to avoid slowing down requests under high load
-log-levelstring"info"extraArgs.log-levelLog level: debug, info, warn, error
-log-rate-thresholdint10extraArgs.log-rate-thresholdWhen traffic exceeds this rate (req/s), replace per-request logs with periodic summaries. Errors are always logged.
-log-request-sample-rateint0extraArgs.log-request-sample-rateSample rate for per-request access logs on successful (2xx) responses. 0 or 1 logs every request. N>1 logs 1 in every N requests. 4xx/5xx are always logged.
-log-stats-intervalduration10sextraArgs.log-stats-intervalHow often to print a request statistics summary (total, errors, latency, cache rate)
-metrics-listenstring(empty)extraArgs.metrics-listenOptional dedicated address for the /metrics endpoint. When empty AND --server.register-instrumentation=true, /metrics is served on --listen (back-compat). When non-empty AND --server.register-instrumentation=true, /metrics is served on this dedicated listener.
-metrics.export-sensitive-labelsboolfalseextraArgs.metrics.export-sensitive-labelsExport per-tenant and per-client identity metrics on /metrics and OTLP
-metrics.max-clientsint256extraArgs.metrics.max-clientsMaximum unique client labels retained in exported metrics before collapsing into overflow
-metrics.max-tenantsint256extraArgs.metrics.max-tenantsMaximum unique tenant labels retained in exported metrics before collapsing into overflow
-metrics.trust-proxy-headersboolfalseextraArgs.metrics.trust-proxy-headersTrust X-Grafana-User and X-Forwarded-For when deriving per-client metrics labels
-otel-service-instance-idstring(empty)extraArgs.otel-service-instance-idOpenTelemetry service.instance.id for logs and OTLP metrics
-otel-service-namestring"loki-vl-proxy"extraArgs.otel-service-nameOpenTelemetry service.name for logs and OTLP metrics
-otel-service-namespacestring(empty)extraArgs.otel-service-namespaceOpenTelemetry service.namespace for logs and OTLP metrics
-otlp-compressionstring"none"extraArgs.otlp-compressionOTLP compression: none, gzip, zstd
-otlp-endpointstring(empty)extraArgs.otlp-endpointOTLP HTTP endpoint (e.g., http://otel-collector:4318/v1/metrics)
-otlp-headersstring(empty)extraArgs.otlp-headersComma-separated OTLP HTTP headers in key=value form
-otlp-intervalduration30sextraArgs.otlp-intervalOTLP push interval
-otlp-timeoutduration10sextraArgs.otlp-timeoutOTLP HTTP request timeout
-otlp-tls-skip-verifyboolfalseextraArgs.otlp-tls-skip-verifySkip TLS verification for OTLP endpoint
-proc-rootstring"/proc"extraArgs.proc-rootFilesystem root for self/container-scope /proc reads (self/status, self/io, self/stat, self/fd, net/dev). Back-compat: if --host-proc-root is left at its default, this value also seeds the host-scope root.

peer cache​

FlagTypeDefaultHelm valueDescription
-peer-auth-tokenstring(empty)extraArgs.peer-auth-tokenShared token required on /_cache/get and /_cache/set peer-cache requests when set
-peer-discoverystring(empty)peerCache.* (chart-managed)dns
-peer-dnsstring(empty)peerCache.* (chart-managed)dns
-peer-hot-read-ahead-enabledboolfalseextraArgs.peer-hot-read-ahead-enabledEnable bounded hot read-ahead from peer hot index to prewarm local shadows
-peer-hot-read-ahead-error-backoffduration15sextraArgs.peer-hot-read-ahead-error-backoffBase read-ahead cooldown applied after peer/index errors
-peer-hot-read-ahead-intervalduration30sextraArgs.peer-hot-read-ahead-intervalBase interval for periodic peer hot read-ahead pulls
-peer-hot-read-ahead-jitterduration5sextraArgs.peer-hot-read-ahead-jitterRandom jitter added to peer hot read-ahead interval
-peer-hot-read-ahead-max-bytes-per-intervalint648388608extraArgs.peer-hot-read-ahead-max-bytes-per-intervalMaximum bytes prefetched per interval
-peer-hot-read-ahead-max-concurrencyint4extraArgs.peer-hot-read-ahead-max-concurrencyMaximum concurrent hot-index and prefetch peer operations
-peer-hot-read-ahead-max-keys-per-intervalint64extraArgs.peer-hot-read-ahead-max-keys-per-intervalMaximum number of hot keys prefetched per interval
-peer-hot-read-ahead-max-object-bytesint262144extraArgs.peer-hot-read-ahead-max-object-bytesMaximum object size eligible for hot read-ahead
-peer-hot-read-ahead-min-ttlduration30sextraArgs.peer-hot-read-ahead-min-ttlMinimum remaining TTL required for hot read-ahead candidates
-peer-hot-read-ahead-tenant-fair-shareint50extraArgs.peer-hot-read-ahead-tenant-fair-shareMaximum per-tenant share (percent) of key budget in fairness pass
-peer-hot-read-ahead-top-nint256extraArgs.peer-hot-read-ahead-top-nNumber of top hot keys requested from each peer hot index
-peer-http-urlstring(empty)peerCache.* (chart-managed)http
-peer-insecure-ip-allowlistboolfalseextraArgs.peer-insecure-ip-allowlistWhen true, allow peer cache requests based on source IP membership alone (legacy behavior). Default false: a shared --peer-auth-token is required when peer discovery is configured.
-peer-selfstring(empty)peerCache.* (chart-managed)10.0.0.1:3100
-peer-self-azstring(empty)extraArgs.peer-self-azus-east-1a
-peer-srvstring(empty)peerCache.* (chart-managed)srv
-peer-staticstring(empty)peerCache.* (chart-managed)static
-peer-timeoutduration2sextraArgs.peer-timeoutTimeout for peer-cache fetch requests to owner peers
-peer-write-throughbooltrueextraArgs.peer-write-throughPush cache writes from non-owner peers to owner peers for warmer distributed cache under skewed traffic
-peer-write-through-min-ttlduration30sextraArgs.peer-write-through-min-ttlMinimum TTL eligible for peer owner write-through pushes. Empty label and label-value answers are cached for max(30s, this, -disk-cache-min-ttl) so they replace older non-empty copies

security​

FlagTypeDefaultHelm valueDescription
-cb-fail-thresholdint5extraArgs.cb-fail-thresholdCircuit breaker: failures within -cb-window-duration before opening
-cb-open-durationduration10sextraArgs.cb-open-durationCircuit breaker: how long to stay open before allowing probe requests
-cb-window-durationduration30sextraArgs.cb-window-durationCircuit breaker: sliding window for failure counting; failures older than this are discarded
-coalescer-disabledboolfalseextraArgs.coalescer-disabledDisable request coalescing (singleflight); every concurrent request makes its own backend call — useful with -cache-disabled to measure raw translation overhead
-debug-log-raw-queriesboolfalseextraArgs.debug-log-raw-queriesWhen true, debug logs include raw LogQL/LogsQL and backend params verbatim. Default false (redacted to sha256+len).
-forward-authorizationboolfalseextraArgs.forward-authorizationForward Authorization header to VL backend (equivalent to including Authorization in -forward-headers)
-forward-cookiesstring(empty)extraArgs.forward-cookiesComma-separated list of cookie names to forward to VL backend
-forward-headersstring(empty)extraArgs.forward-headersComma-separated list of HTTP headers to forward to VL backend
-server.admin-auth-tokenstring(empty)extraArgs.server.admin-auth-tokenBearer token required for admin/debug endpoints when set
-server.enable-pprofboolfalseextraArgs.server.enable-pprofExpose /debug/pprof/* handlers
-server.enable-query-analyticsboolfalseextraArgs.server.enable-query-analyticsExpose /debug/queries query analytics
-server.metrics-max-concurrencyint1extraArgs.server.metrics-max-concurrencyMaximum concurrent /metrics scrapes served at once (0 disables the cap)
-server.register-instrumentationboolfalseextraArgs.server.register-instrumentationRegister instrumentation handlers such as /metrics. Default false (BREAKING in v1.56.0; was true). Set true and optionally pair with --metrics-listen for a dedicated scrape port. The Helm chart sets this to true automatically so ServiceMonitor scrapes keep working without operator action.
-tls-cert-filestring(empty)extraArgs.tls-cert-fileTLS certificate file for HTTPS server
-tls-client-ca-filestring(empty)extraArgs.tls-client-ca-fileCA certificate file used to verify HTTPS client certificates
-tls-key-filestring(empty)extraArgs.tls-key-fileTLS private key file for HTTPS server
-tls-require-client-certboolfalseextraArgs.tls-require-client-certRequire and verify HTTPS client certificates

server​

FlagTypeDefaultHelm valueDescription
-admin-listenstring"127.0.0.1:3101"extraArgs.admin-listenAddress for admin/debug endpoints (/admin/, /debug/) when --server.admin-auth-token is empty. Loopback by default so the binary boots safely with no flags. Ignored when --server.admin-auth-token is set — admin endpoints then ride the main --listen address.
-alerts-backendstring(empty)extraArgs.alerts-backendOptional alert backend URL for /alerts passthrough (defaults to -ruler-backend when unset)
-backendstring"http://localhost:9428"extraArgs.backendVictoriaLogs backend URL
-backend-basic-authstring(empty)extraArgs.backend-basic-authBasic auth for VL backend (user:password)
-backend-compressionstring"auto"extraArgs.backend-compressionBackend HTTP compression preference: auto, gzip, zstd, none
-backend-default-msg-valuestring(empty)extraArgs.backend-default-msg-valueVictoriaLogs -defaultMsgValue when it is customized. Rows whose _msg is empty, starts with VictoriaLogs' default "missing _msg field" text, or equals this value get their log line rebuilt as a JSON object of the row's non-stream fields
-backend-tls-skip-verifyboolfalseextraArgs.backend-tls-skip-verifySkip TLS verification for VL backend
-go-gc-percentint200extraArgs.go-gc-percentGOGC target percentage. Higher values reduce GC frequency at the cost of higher peak RSS. Set to -1 to use Go runtime default (100). Ignored when GOGC env var is already set.
-go-mem-limitint640extraArgs.go-mem-limitExplicit GOMEMLIMIT in bytes. Overrides -go-mem-limit-percent. 0 = use percentage or GOMEMLIMIT env var.
-go-mem-limit-percentint85extraArgs.go-mem-limit-percentPercentage of the detected container memory limit (cgroups) to set as GOMEMLIMIT. 0 disables auto-detection. Ignored when GOMEMLIMIT env var or -go-mem-limit is set.
-listenstring":3100"extraArgs.listenAddress to listen on (Loki-compatible frontend)
-response-compressionstring(empty)extraArgs.response-compressionResponse compression codec: auto, gzip, none (default: auto)
-response-compression-min-bytesintdefaultResponseCompressionMinBytesextraArgs.response-compression-min-bytesMinimum response size before frontend compression starts (0 compresses any size)
-response-gzipbooltrueextraArgs.response-gzipDeprecated: enable compressed responses for clients that accept them; prefer -response-compression
-ruler-backendstring(empty)extraArgs.ruler-backendOptional alert/ruler backend URL for /rules passthrough (for example vmalert)
-stream-responseboolfalseextraArgs.stream-responseStream log responses via chunked transfer encoding
-warmup-max-jitterduration0extraArgs.warmup-max-jitterMaximum random delay before label cache warmup starts. Spread this across a fleet (e.g. 10s for ≥3 instances) to prevent all proxies hammering VL simultaneously on restart.

tenancy​

FlagTypeDefaultHelm valueDescription
-auth.enabledboolfalseextraArgs.auth.enabledRequire X-Scope-OrgID on query requests. When false, requests without a tenant header use the backend default tenant.
-forward-tenant-headerbooltrueextraArgs.forward-tenant-headerForward the per-tenant X-Scope-OrgID header to the upstream backend. Safe for VictoriaLogs (ignores it). Required for Victoria Lakehouse native tenant routing.
-require-tenant-headerboolfalseextraArgs.require-tenant-headerReject requests missing X-Scope-OrgID with HTTP 401. Independent of -auth.enabled; use when you want tenant enforcement without full auth.
-tenant-default-limitsstring(empty)extraArgs.tenant-default-limitsquery_timeout
-tenant-labelstring(empty)extraArgs.tenant-labelVL field name for label-based tenant routing. When set, X-Scope-OrgID values are injected as {<tenant-label>="<orgID>"} into VL queries instead of AccountID/ProjectID headers. Use when all data is under VL default tenant (0:0). Explicit -tenant-map entries take priority. Env: TENANT_LABEL
-tenant-limitsstring(empty)extraArgs.tenant-limitsotlp-endpoint
-tenant-limits-allow-publishstring(empty)extraArgs.tenant-limits-allow-publishComma-separated limit fields published on /config/tenant/v1/limits and /loki/api/v1/drilldown-limits
-tenant-mapstring(empty)extraArgs.tenant-maporg-name
-tenant-map-filestring(empty)extraArgs.tenant-map-filePath to YAML or JSON file containing the tenant map. Hot-reloaded on SIGHUP and automatically when the file changes (see -tenant-map-reload-interval). Supports Kubernetes ConfigMap volumes.
-tenant-map-reload-intervalduration30sextraArgs.tenant-map-reload-intervalHow often to poll -tenant-map-file for mtime changes. Set to 0 to disable polling.
-tenant.allow-globalboolfalseextraArgs.tenant.allow-global*

timeouts​

FlagTypeDefaultHelm valueDescription
-backend-timeoutduration2m0sextraArgs.backend-timeoutTimeout for non-streaming requests to the VictoriaLogs backend. The remaining budget is also passed to VictoriaLogs as its per-query timeout argument, so VictoriaLogs stops work the proxy has given up on
-backend-version-check-timeoutduration5sextraArgs.backend-version-check-timeoutTimeout for startup backend version compatibility check
-drilldown-scan-timeoutduration5sextraArgs.drilldown-scan-timeoutPer-request timeout for the detected_fields / detected_field_values log scan path. Caps the time a single Drilldown panel can spend scanning logs with a parser filter. 0 disables the cap (use VL's natural response time).
-http-idle-timeoutduration2m0sextraArgs.http-idle-timeoutHTTP server idle timeout
-http-read-header-timeoutduration10sextraArgs.http-read-header-timeoutHTTP server read header timeout
-http-read-timeoutduration30sextraArgs.http-read-timeoutHTTP server read timeout
-http-write-timeoutduration2m0sextraArgs.http-write-timeoutHTTP server write timeout
-query-range-window-timeoutduration20sextraArgs.query-range-window-timeoutPer-window backend timeout budget for query_range window fetches (0 disables)