Skip to main content
When CrowdSec is installed, Traefik access logging is enabled automatically so CrowdSec can analyze traffic. This means config/traefik/logs/access.log will grow indefinitely without log rotation in place.
The default Pangolin install (without CrowdSec) does not enable access logging, so this only applies if you have CrowdSec installed.

How it works

The CrowdSec installer enables Traefik’s accessLog block and mounts ./config/traefik/logs/ into the container at /var/log/traefik/. CrowdSec reads that log via its acquis.d/traefik.yaml acquisition config. Without rotation, that file grows forever. The fix is logrotate with copytruncate — it copies the log file and truncates the original in place, so Traefik never needs to be restarted or sent a signal.

Automatic setup (installer v1.x+)

If you installed CrowdSec using a recent version of the Pangolin installer, logrotate is configured automatically at /etc/logrotate.d/pangolin-traefik. You can verify it’s there:
You should see something like:

Manual setup

If you installed CrowdSec before automatic log rotation was added, set it up manually:
1

Create the logrotate config

Replace /opt/pangolin with your actual Pangolin install directory if it differs.
2

Test the configuration

Do a dry run to confirm logrotate picks it up without errors:
No errors means you’re good. You can also force a rotation immediately to verify end-to-end:

Customizing retention

The defaults (daily rotation, 7 compressed copies) work for most setups. To adjust: For example, to keep 30 days of compressed weekly logs:

Verifying rotation is working

Check that rotated files are appearing in the logs directory:
After the first rotation you should see files like access.log.1 and access.log.2.gz alongside the active access.log. To see when logrotate last ran and whether it succeeded: