Skip to main content

vector

Catalog date: 2026-06-24.

Vector is now a backup log shipper, not the canonical one: as of the feat(platform): publish VictoriaMetrics observability plane change to alphaswarm_platform (2026-07-15, after this page's last review), the primary log path is the OTel gateway's filelog receiver, which redacts and batches logs on their way to OpenSearch via Data Prepper. Vector runs alongside it as a DaemonSet on every node, tails the same /var/log/pods files, and ships to Loki under a dedicated shipper="vector" label — a fallback pipeline that keeps working even if the OTel gateway misbehaves. See deployments/kubernetes/observability/README.md in alphaswarm_platform for the current selected data-flow table.

Identity​

FieldValue
Service idvector
Roleobservability
Imagetimberio/vector:0.43.0-alpine (compose) / timberio/vector:0.46.1-debian (Kustomize DaemonSet) — the two surfaces are on different Vector versions
Port8686 — Vector's own API / /health endpoint (no separate Prometheus metrics port is configured)

Deployment surfaces​

SurfaceWhere
Composeservice vector in alphaswarm_platform/compose/docker-compose.platform.yml
Kustomizeobservability/vector/ — DaemonSet + ConfigMap

Pipelines​

Per the current observability/vector/configmap.yaml:

  • kubernetes_logs source → remap enrichment transform (adds cluster, shipper="vector", and namespace / pod / container / node Loki labels — no JSON parsing or redaction step) → loki sink.
  • Sinks: loki only. There is no phoenix sink on Vector — Phoenix (traces) and OpenSearch (logs, via Data Prepper) are fed by the OTel gateway instead, per the observability kustomization.yaml.
  • The compose surface differs: it uses a docker_logs source (there is no Kubernetes control plane in compose) and ships straight to Loki — see deploy/vector/vector.toml.

Redaction​

Vector itself applies no redaction transform — its remap step only adds routing/label fields (see Pipelines above). Log redaction happens upstream, in the OTel gateway's resource/redact / attributes/redact processors, which delete a fixed set of attribute keys (authorization, cookie, http.request.header.authorization, session_id, db.statement, exception.stacktrace, and similar) rather than pattern-matching on field-name substrings — see observability/otel-gateway/configmap.yaml. The substring-based password / secret / token / ... denylist this page previously described is actually the alphaswarm-management-engine (private alphaswarm_internal repo) rule's guidance for what AI/agent transcripts must never print — a credential-safety policy for agent output, not a live Vector pipeline transform.

See also​

  • loki.md — the sink this shipper writes to.
  • alphaswarm-management-engine (private alphaswarm_internal repo) — agent-transcript credential-safety denylist (not a Vector transform).