Fluent Bit Shipping Log Files Over Forward

fluent-bit from EPEL, following a log-file glob it re-reads every few seconds and shipping over the Forward protocol, with retries unlimited instead of the default single retry. Its config is checked with --dry-run before it lands. The live test writes a line to a new file and watches it arrive at an aggregator it started. Original role, live-tested on Rocky Linux 10.

ansibleObservability

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-fluent-bit/badge)](https://www.iac-bazaar.com/catalog/ansible-fluent-bit?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [Fluent Bit Shipping Log Files Over Forward](https://www.iac-bazaar.com/catalog/ansible-fluent-bit?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# Fluent Bit Shipping Log Files Over Forward: https://www.iac-bazaar.com/catalog/ansible-fluent-bit (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

fluent-bit

fluent-bit from EPEL, configured to follow log files (a glob re-read every few seconds) and the journal if you want it, and ship them over the Forward protocol to an aggregator, with its health and metrics endpoint on loopback. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages fluent-bit in EPEL, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs fluent-bit, writes the configuration the package leaves open, and enables the unit the package ships: systemctl cat fluent-bit shows the distribution's own unit, not one this role invented. The listener is 127.0.0.1:2020 by default, for a proxy that authenticates or a client on the same host; the live test reads the listening sockets and expects loopback only.

Checked before it lands. fluent-bit --dry-run is a real checker: "configuration test is successful" and exit 0 on a good file, exit 1 with the reason ("tried to instance a plugin name that doesn't exist") on a bad one. The role's template is checked by the installed release before it replaces the package's file, and the packaged unit is used as it is.

Proven by a delivery. The live test starts an aggregator on the default destination, writes a line to a NEW file the default glob matches, and waits for that line to arrive at the aggregator over the Forward protocol - which exercises the glob refresh, the tail and the network output together. Retries default to unlimited: a shipper that drops logs after one failed attempt (fluent-bit's own default is 1) loses exactly the logs you wanted during an outage.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-victoria-logs

VictoriaLogs from the upstream release as a hardened service on loopback. Its JSON-lines endpoint answers 200 and stores nothing when the content type is wrong, so the README names the one it needs. The live test ingests two lines, gets the right one back from LogsQL, and sees an unwritten stream come back empty and bad LogsQL refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-alertmanager

Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-alloy

Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-blackbox-exporter

Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grafana-server

Grafana on loopback with a secret key of yours: every install that never set one shares the package's, which encrypts the data-source credentials in its database. Secure cookies and HSTS for the TLS proxy in front; public snapshots, plugin update checks, feedback links and Gravatar switched off. Settings verified through the API, not the file. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grafana

Grafana (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads back the datasource this role provisioned, creates a dashboard and finds it by search, sees anonymous and wrong-password requests refused, and reads the build metric naming the version installed. Original role, live-tested on Rocky Linux 10.

View module