vector
Catalog date: 2026-06-24.
Vector is now a backup log shipper, not the
canonical one: as of the feat(platform): publish VictoriaMetrics observability plane change to alphaswarm_platform (2026-07-15, after
this page's last review), the primary log path is the OTel gateway's
filelog receiver, which redacts and batches logs on their way to
OpenSearch via Data Prepper. Vector runs alongside it as a DaemonSet on
every node, tails the same /var/log/pods files, and ships to Loki under
a dedicated shipper="vector" label — a fallback pipeline that keeps
working even if the OTel gateway misbehaves. See
deployments/kubernetes/observability/README.md in alphaswarm_platform
for the current selected data-flow table.
Identity
| Field | Value |
|---|---|
| Service id | vector |
| Role | observability |
| Image | timberio/vector:0.43.0-alpine (compose) / timberio/vector:0.46.1-debian (Kustomize DaemonSet) — the two surfaces are on different Vector versions |
| Port | 8686 — Vector's own API / /health endpoint (no separate Prometheus metrics port is configured) |
Deployment surfaces
| Surface | Where |
|---|---|
| Compose | service vector in alphaswarm_platform/compose/docker-compose.platform.yml |
| Kustomize | observability/vector/ — DaemonSet + ConfigMap |
Pipelines
Per the current observability/vector/configmap.yaml:
kubernetes_logssource →remapenrichment transform (addscluster,shipper="vector", andnamespace/pod/container/nodeLoki labels — no JSON parsing or redaction step) →lokisink.- Sinks:
lokionly. There is nophoenixsink on Vector — Phoenix (traces) and OpenSearch (logs, via Data Prepper) are fed by the OTel gateway instead, per the observabilitykustomization.yaml. - The compose surface differs: it uses a
docker_logssource (there is no Kubernetes control plane in compose) and ships straight to Loki — seedeploy/vector/vector.toml.
Redaction
Vector itself applies no redaction transform — its remap step only
adds routing/label fields (see Pipelines above). Log redaction happens
upstream, in the OTel gateway's resource/redact / attributes/redact
processors, which delete a fixed set of attribute keys (authorization,
cookie, http.request.header.authorization, session_id, db.statement,
exception.stacktrace, and similar) rather than pattern-matching on
field-name substrings — see
observability/otel-gateway/configmap.yaml.
The substring-based password / secret / token / ... denylist this
page previously described is actually the
alphaswarm-management-engine (private alphaswarm_internal repo)
rule's guidance for what AI/agent transcripts must never print — a
credential-safety policy for agent output, not a live Vector pipeline
transform.
See also
loki.md— the sink this shipper writes to.alphaswarm-management-engine(privatealphaswarm_internalrepo) — agent-transcript credential-safety denylist (not a Vector transform).