Reference
Scope
Look-up facts for the Victoria Stack (VictoriaMetrics, VictoriaLogs, VictoriaTraces and the vm* tools): versions and support windows, Community vs Enterprise features, ports and API paths, deployment matrices, data models, query languages, tuning flags, recent default changes, benchmarks, cost, and hardening checklists. Versions verified 2026-09-25 against the upstream CHANGELOG files. See also: hub, Explanation, How-to guides.
Versions and Support
Current Releases
| Product |
Latest release (date) |
Line / status |
Source |
| VictoriaMetrics (single, cluster, vmagent, vmalert, vmauth, vmbackup, vmctl) |
v1.152.0 (2026-09-14) |
Rolling "latest" line, new minor about every 2 weeks |
CHANGELOG |
| VictoriaMetrics LTS |
v1.148.4 and v1.136.18 (both 2026-09-11) |
Two supported LTS lines (Enterprise) |
LTS releases |
| VictoriaLogs |
v1.52.0 (2026-07-16); v1.51.1 (2026-08-18) is an upgrade-bridge patch |
GA since v1.0.0 (2024-11-12) |
VictoriaLogs CHANGELOG |
| VictoriaTraces |
v0.11.1 (2026-09-16) |
Pre-1.0 (0.x); first release v0.1.0 on 2025-07-28 |
VictoriaTraces CHANGELOG |
| VictoriaMetrics Operator |
v0.74.1 (2026-08-04) |
0.x, CRD API v1beta1 (VM) and v1 (VL/VT*) |
Operator CHANGELOG |
| Helm charts |
victoria-metrics-k8s-stack 0.93.0 (app v1.152.0), victoria-metrics-operator 0.67.3 (app v0.74.1), victoria-logs-single 0.13.9, victoria-traces-single 0.1.11 |
Chart versions independent of app versions |
helm-charts repo |
Date discrepancy
The upstream CHANGELOG lists v1.152.0 as "Released at 2026-09-14"; one search-engine summary of the GitHub release page reported 2026-09-11. This page uses the CHANGELOG date.
LTS Policy
| Rule |
Value |
| Who gets LTS builds |
VictoriaMetrics Enterprise customers (a new LTS line may be public until the next line ships) |
| New LTS line cadence |
Every 6 months |
| Support per line |
12 months of bugfixes and security fixes |
| Lines supported at once |
2 (currently v1.148.x and v1.136.x) |
| Recently ended |
v1.122.x (last release v1.122.27, 2026-07-17) |
| Community users |
Upgrade to the latest release; all LTS fixes also land in latest |
Source: LTS-releases.md.
Versions to avoid
A MetricsQL binary-operator ordering bug (for example 10 - (3 + 3 + 4) evaluated as 10 - 3 + 3 + 4) shipped in v1.140.0, v1.136.4 and v1.122.19. Upstream "strongly recommends" avoiding these versions (#10856).
Recent Default and Behavior Changes
| Version (date) |
Component |
Change |
| v1.133.0 (2026-01-02) |
vmsingle, vmstorage |
Per-partition (per-month) IndexDB. One-time re-registration of active series on upgrade; disk use may rise for retention under 1 month |
| v1.137.0 (2026-02-27) |
vmauth |
JWT authentication with public_keys and vm_access claim templating |
| v1.137.0 (2026-02-27) |
vmsingle, vmagent |
-promscrape.dropOriginalLabels default changed true -> false |
| v1.138.0 |
vmauth |
OIDC discovery (jwt.oidc.issuer) and match_claims routing |
| v1.143.0 |
cluster |
Tenant can be passed in AccountID/ProjectID HTTP headers |
| v1.147.0 |
vmauth |
vm_access claim optional; default_vm_access_claim |
| v1.149.0 (2026-08-05) |
vminsert |
-disableRerouting default true -> false (slowness-based rerouting on; auto-off when -replicationFactor > 1) |
| v1.149.0 (2026-08-05) |
vmsingle, vmselect |
/api/v1/admin/tsdb/delete_series and /tags/delSeries require POST |
| v1.150.0 (2026-08-17) |
vminsert, vmselect, vmagent |
-enableMultitenancyViaHeaders default false -> true; /select/prometheus/... without tenant in path becomes valid (tenant 0:0 if no headers) |
| v1.152.0 (2026-09-14) |
vmauth |
Security fix for JWT match_claims authorization bypass (GHSA-f99m-22fh-qw96) |
| tip (after v1.152.0) |
vmauth |
Browser SSO via OIDC Authorization Code Flow (sso: section) — unreleased as of 2026-09-25 |
| VictoriaLogs v1.51.0 (2026-06-17) |
LogsQL |
filter pipe without the filter keyword is rejected unless it starts with field: (for example foo | bar is invalid) |
| VictoriaLogs v1.52.0 / VictoriaTraces v0.10.0 |
images |
Base image Alpine -> distroless; no linux/386 image |
Community (Apache 2.0) components are free; Enterprise binaries and images carry an -enterprise suffix and need -license or -licenseFile. VictoriaMetrics Cloud runs on Enterprise builds.
| Feature |
Community |
Enterprise |
| Single-node and cluster VictoriaMetrics, vmagent, vmalert, vmauth, vmbackup/vmrestore, vmctl |
Yes |
Yes |
| Cluster multitenancy, replication, stream aggregation, MetricsQL |
Yes |
Yes |
| vmauth Basic/Bearer auth, routing, load balancing, JWT/OIDC (v1.137+) |
Yes |
Yes |
Downsampling (-downsampling.period) |
No |
Yes |
| Retention filters (multiple retentions) |
No |
Yes |
| Automatic vmstorage discovery |
No |
Yes |
| vmanomaly (anomaly detection service) |
No |
Yes |
| vmbackupmanager (backup automation) |
No |
Yes |
| vmgateway (JWT/OIDC auth and rate limiting) |
No |
Yes |
| Per-tenant statistics, query execution stats |
No |
Yes |
| mTLS on all components and between cluster components |
No |
Yes |
| vmauth mTLS-based routing, IP filters, Let's Encrypt auto-TLS |
No |
Yes |
| Kafka and Google Pub/Sub integration (vmagent) |
No |
Yes |
| vmalert multitenancy, reading rules from object storage |
No |
Yes |
| FIPS 140-3 compatible builds |
No |
Yes |
| LTS release lines, SLA support |
No |
Yes |
| VictoriaLogs auto-TLS and mTLS |
No |
Yes |
Source: Enterprise features.
Components, Binaries and Ports
| Component |
Binary / image |
Default HTTP port |
Role |
| VictoriaMetrics single-node |
victoria-metrics / victoriametrics/victoria-metrics |
8428 |
Ingest + store + query |
| vminsert |
vminsert / victoriametrics/vminsert |
8480 (/insert/...) |
Stateless write path; consistent hashing to vmstorage |
| vmselect |
vmselect / victoriametrics/vmselect |
8481 (/select/...) |
Stateless query path |
| vmstorage |
vmstorage / victoriametrics/vmstorage |
8482 (HTTP), 8400 (from vminsert), 8401 (from vmselect) |
Stateful storage |
| vmagent |
vmagent |
8429 |
Scrape, relabel, buffer, remote write |
| vmalert |
vmalert |
8880 |
Recording and alerting rules (metrics, logs, traces) |
| vmauth |
vmauth |
8427 |
Auth proxy, router, load balancer |
| VictoriaLogs (single and cluster roles) |
victoria-logs / victoriametrics/victoria-logs |
9428 |
Same binary acts as vlinsert, vlselect or vlstorage (-storageNode, -insert.disable, -select.disable) |
| vlagent |
vlagent |
9429 |
Kubernetes pod and file log collection, HTTP ingestion, on-disk buffering, replication to several VictoriaLogs instances |
| VictoriaTraces (single and cluster roles) |
victoria-traces / victoriametrics/victoria-traces |
10428 (docs use 10471 for vtselect in cluster examples) |
OTLP ingest, Jaeger and Tempo query APIs |
| VictoriaTraces OTLP gRPC |
same binary |
Disabled by default; enable with -otlpGRPCListenAddr=:4317 (TLS on by default, -otlpGRPC.tls=false for plaintext) |
OTLP/gRPC ingest |
| vtagent (v0.11.0+) |
vtagent |
10429 (default -httpListenAddr, app/vtagent/main.go) |
Basic OTLP forwarder to /insert/native |
Port values for vmagent (8429), vmalert (8880) and vmauth (8427) are the documented defaults of -httpListenAddr; check -help on your version.
API Endpoints
| Product |
Purpose |
Path |
| VictoriaMetrics single |
Prometheus remote write |
/api/v1/write |
| VictoriaMetrics single |
Query / range query |
/api/v1/query, /api/v1/query_range |
| VictoriaMetrics single |
JSON-line import / export |
/api/v1/import, /api/v1/export |
| VictoriaMetrics single |
OpenTelemetry metrics |
/opentelemetry/v1/metrics |
| VictoriaMetrics single |
Snapshots |
/snapshot/create, /snapshot/list, /snapshot/delete |
| VictoriaMetrics cluster |
Write (tenant in path) |
http://vminsert:8480/insert/<accountID>[:<projectID>]/prometheus/api/v1/write |
| VictoriaMetrics cluster |
Query (tenant in path) |
http://vmselect:8481/select/<accountID>[:<projectID>]/prometheus/api/v1/query |
| VictoriaMetrics cluster |
Tenant via headers (default on since v1.150.0) |
/insert/prometheus/..., /select/prometheus/... + AccountID/ProjectID headers |
| VictoriaMetrics cluster |
Multi-tenant writes / reads |
/insert/multitenant/... (tenant from vm_account_id/vm_project_id labels), /select/multitenant/... |
| VictoriaMetrics cluster |
List tenants |
http://vmselect:8481/admin/tenants |
| VictoriaLogs |
JSON lines |
/insert/jsonline |
| VictoriaLogs |
Elasticsearch bulk |
/insert/elasticsearch/_bulk |
| VictoriaLogs |
Loki push |
/insert/loki/api/v1/push |
| VictoriaLogs |
OpenTelemetry logs |
/insert/opentelemetry/v1/logs |
| VictoriaLogs |
LogsQL query / hits / stats |
/select/logsql/query, /select/logsql/hits, /select/logsql/stats_query |
| VictoriaLogs |
Web UI |
/select/vmui |
| VictoriaTraces |
OTLP/HTTP ingest |
/insert/opentelemetry/v1/traces |
| VictoriaTraces |
Jaeger query API (Grafana Jaeger data source URL) |
/select/jaeger (for example /select/jaeger/api/traces/{trace_id}) |
| VictoriaTraces |
Tempo query API (experimental) |
/select/tempo (/api/search, /api/v2/search/tags, /api/v2/traces/{id}, /api/metrics/query_range) |
| VictoriaTraces |
LogsQL over spans |
/select/logsql/query |
VictoriaLogs also ingests syslog, journald, Datadog and other formats; see data ingestion. VictoriaTraces ingests OTLP only (HTTP, and gRPC when enabled); Jaeger and Zipkin native ingestion are not listed in its ingestion docs — convert through the OpenTelemetry Collector.
Kubernetes Deployment Matrix
| Component |
Kind |
Replicas (Min HA) |
Key Resource |
Helm Chart |
Operator CRD |
| vmagent |
DaemonSet or Deployment |
1 per node (DS) or 2+ |
CPU, Memory |
victoria-metrics-agent |
VMAgent |
| vmauth |
Deployment |
2+ |
CPU |
victoria-metrics-auth |
VMAuth + VMUser |
| vminsert |
Deployment |
2+ |
CPU |
victoria-metrics-cluster |
VMCluster |
| vmselect |
Deployment or StatefulSet |
2+ |
CPU, Memory |
victoria-metrics-cluster |
VMCluster |
| vmstorage |
StatefulSet |
3+ (at least 2*RF-1 with replication) |
Disk IOPS, Memory |
victoria-metrics-cluster |
VMCluster |
| VictoriaMetrics single |
StatefulSet/Deployment + PVC |
1 (or 2 independent copies for HA) |
Disk, Memory |
victoria-metrics-single |
VMSingle |
| VictoriaLogs |
StatefulSet (single) or cluster |
1, or cluster |
Disk, Memory |
victoria-logs-single, victoria-logs-cluster, victoria-logs-collector |
VLSingle, VLCluster, VLAgent, VLDistributed |
| VictoriaTraces |
StatefulSet (single) or cluster |
1, or cluster |
Disk, Memory |
victoria-traces-single, victoria-traces-cluster |
VTSingle, VTCluster, VTAgent (tip) |
| vmalert |
Deployment |
1-2 |
CPU |
victoria-metrics-alert |
VMAlert + VMRule |
| vmanomaly (Enterprise) |
Deployment |
1+ |
CPU, Memory |
victoria-metrics-anomaly |
VMAnomaly |
| vmoperator |
Deployment |
1 |
CPU |
victoria-metrics-operator |
— |
Data Model
| Product |
Unit |
Identity / key fields |
Notes |
| VictoriaMetrics |
Time series = metric name + labels; samples of (timestamp ms, float64) |
Internal TSID (primary index); IndexDB maps label pairs -> TSID |
Blocks of up to 8K samples sorted by TSID; per-month partitions under data/{small,big}/YYYY_MM with their own IndexDB (since v1.133.0) |
| VictoriaMetrics cluster |
Same, plus tenant |
accountID[:projectID] (32-bit unsigned each); tenant auto-created on first write |
Tenants spread evenly across all vmstorage nodes; no per-tenant directory |
| VictoriaLogs |
Log entry = JSON object of fields |
_msg (message), _time (timestamp), _stream (stream fields, set via _stream_fields) |
Per-day partitions at <storageDataPath>/partitions/YYYYMMDD; each field stored as a column; bloom filters per block |
| VictoriaLogs tenant |
(AccountID, ProjectID) HTTP headers |
Default 0:0 |
Same model reused by VictoriaTraces |
| VictoriaTraces |
Span stored as a structured log entry |
trace_id, span name, attributes, resource attributes |
Built on the VictoriaLogs storage engine; cluster shards spans by trace ID |
Query Languages
MetricsQL (Metrics)
MetricsQL is backwards-compatible with PromQL with a documented set of intentional differences (MetricsQL docs):
| Feature |
PromQL |
MetricsQL |
Lookbehind window in rate(m[5m]) |
Required |
Optional; defaults from step (and scrape interval) |
rate() / increase() extrapolation |
Extrapolates (fractional increase on integer counters) |
No extrapolation; uses the last sample before the window, so integer counters give integer increases |
keep_metric_names modifier |
No |
Keeps metric names after functions and binary operators |
| Numeric suffixes |
No |
K, Ki, M, Mi, G, Gi, T, Ti (8K = 8000, 1.2Mi = 1.210241024) |
NaN in output |
Returned |
Removed from output |
| Multiple rollups in one pass |
No |
aggr_over_time(("min_over_time","max_over_time"), m[d]) |
| Graphite filters |
No |
{__graphite__="foo.*.bar"} |
WITH templates |
No |
WITH (x = ...) expr |
| Scalar vs instant vector |
Distinct types |
Scalar treated as a label-less instant vector |
# rate without explicit window (auto-calculated from step)
rate(http_requests_total{job="api"})
# keep metric names when applying functions
rate({__name__=~"foo|bar"}) keep_metric_names
# numeric suffixes
process_resident_memory_bytes > 2Gi
LogsQL (Logs and Spans)
LogsQL is the query language of VictoriaLogs (also usable against VictoriaTraces spans). A query is a filter expression followed by optional pipes (LogsQL docs):
# error logs from the last 5 minutes (exact match on a field)
_time:5m level:=error
# full-text word search with stats pipe
_time:1h error "connection refused" | stats by (host) count() errors
# extract fields at query time
_time:1h | extract "status=<status_code>" | stats by (status_code) count()
# JSON log parsing then filtering (explicit filter pipe)
_time:5m | unpack_json | filter level:=error | fields _time, _msg, trace_id
# stream filter (fast: skips unrelated streams)
_time:15m {app="nginx"} 500
Key differences from Loki LogQL: LogsQL does not require a stream (label) selector, and high-cardinality fields such as trace_id or user_id are stored as ordinary fields, so trace_id:=abc is a direct filter rather than a runtime JSON parse.
v1.51.0 syntax change
Since VictoriaLogs v1.51.0, a pipe that is only a bare word (for example foo | bar) is rejected. Rewrite as foo bar, foo | filter bar or foo | _msg:bar. vmalert v1.147.0+ embeds this parser, so vlogs rules with the old syntax fail validation on restart.
Critical Tuning Flags
| Component |
Flag |
Purpose |
Default |
| vmsingle, vmstorage |
-retentionPeriod |
Data retention (bare number = months) |
1 (1 month, 31 days); minimum 1d |
| vmsingle, vmselect |
-search.maxUniqueTimeseries |
Max unique series a single query may touch |
Auto-calculated from memory and -search.maxConcurrentRequests |
| vmsingle, vmselect |
-search.maxQueryDuration |
Max single query execution time |
30s |
| vmsingle, vmselect |
-search.maxMemoryPerQuery |
Per-query memory cap |
0 (unlimited) |
| vmselect |
-search.maxConcurrentRequests |
Concurrent query limit |
Scales with CPU cores (uncapped since v1.150.0) |
| all storage |
-memory.allowedPercent |
Share of RAM for internal caches (not a hard process limit) |
60 |
| vmsingle, vmstorage |
-inmemoryDataFlushInterval |
How often in-memory parts are persisted |
5s |
| vminsert |
-replicationFactor=N |
Store N copies on distinct vmstorage nodes |
1 |
| vmselect |
-replicationFactor=N |
Do not mark responses partial if fewer than N nodes are down |
1 |
| vmselect (and vmstorage) |
-dedup.minScrapeInterval |
Deduplication; set to 1ms with replication, or to scrape_interval for HA vmagent pairs |
0 (off) |
| vminsert |
-disableRerouting |
Disable slowness-based rerouting |
false since v1.149.0 |
| vminsert, vmselect, vmagent |
-enableMultitenancyViaHeaders |
Accept tenant in AccountID/ProjectID headers |
true since v1.150.0 |
| vmagent |
-remoteWrite.label |
Add labels to all metrics sent to all -remoteWrite.url |
— |
| vmagent |
-remoteWrite.tmpDataPath |
On-disk persistent queue |
vmagent-remotewrite-data |
| VictoriaLogs |
-retentionPeriod |
Log retention |
7d |
| VictoriaLogs |
-retention.maxDiskSpaceUsageBytes / -retention.maxDiskUsagePercent |
Drop oldest per-day partitions by disk usage (mutually exclusive) |
unset |
| VictoriaTraces |
-otlpGRPCListenAddr |
Enable OTLP/gRPC listener |
empty (disabled) |
Defaults checked in source
-inmemoryDataFlushInterval=5s (app/vmstorage/main.go), -search.maxMemoryPerQuery=0, meaning no limit (app/vmselect/promql/eval.go), and -remoteWrite.tmpDataPath=vmagent-remotewrite-data (app/vmagent/remotewrite/remotewrite.go) match the flag definitions on the VictoriaMetrics default branch (checked 2026-09-27).
Scaling Decision Matrix
| Symptom |
Component to Scale |
How |
| Slow metric queries |
vmselect |
Add replicas or CPU; check -search.max* limits |
| Write backpressure |
vminsert, vmstorage |
Add vminsert replicas; if vmstorage is saturated add nodes (rerouting spreads load since v1.149.0) |
| Disk full on metrics |
vmstorage |
Add nodes or disk; reduce retention |
| High RAM on storage |
vmstorage |
Reduce active series / churn; add memory. -memory.allowedPercent only sizes caches |
| Slow log search |
VictoriaLogs |
More CPU (queries parallelize per core) or move to cluster |
| Log ingestion lag |
VictoriaLogs |
More resources or cluster with more vlstorage nodes |
High Availability
| Mechanism |
Implementation |
| Metrics replication |
-replicationFactor=N on vminsert (and vmselect) + -dedup.minScrapeInterval=1ms on vmselect; at least 2*N-1 vmstorage nodes |
| Metrics availability |
With RF=N, data stays queryable if up to N-1 vmstorage nodes fail; vmselect can return partial responses |
| Single-node HA |
Two independent single-node instances fed by the same vmagent(s), queried through vmauth load balancing |
| Logs/Traces HA |
vlinsert/vtinsert do not replicate; run two independent clusters (or single nodes) and write to both (vlagent or collector fan-out); vlselect returns 502 on unavailable nodes for failover |
| Proxy HA |
Multiple vmauth replicas behind a load balancer |
| Backup |
vmbackup from instant snapshots (metrics); per-partition snapshots + rsync/rclone (logs, traces) |
Benchmarks
Test Conditions and Caveats
- The figures below mix vendor documentation and community reports. They are not from a single controlled benchmark; treat ranges as indicative only.
- VictoriaMetrics publishes prometheus-benchmark; VictoriaLogs publishes a logs benchmark suite and appears in JSONBench and ClickBench.
- Results depend on data shape (active series, churn, label cardinality, query mix).
Resource Efficiency
| Metric |
VictoriaMetrics |
Prometheus |
Mimir |
| RAM at 1M active series |
Not published: the docs say to size with a test run on your own workload and keep 50% free RAM (capacity planning) |
Not published by the project |
Ingesters alone: about 25 GB (2.5 GB per 300,000 in-memory series, RF=3) (Mimir capacity planning) |
| Disk per sample |
0.4-1.75 bytes in official case studies (ARNES 0.4, Adsterra 0.75, Brandwatch ~1.75) (case studies) |
1-2 bytes on average (Prometheus storage docs) |
Capacity planning assumes 2 bytes per sample in compacted blocks |
| Ingestion (single node) |
Up to 2M samples/s and 100M active series in real use (FAQ); cluster docs recommend single-node below about 1M samples/s |
Not published |
N/A (distributed) |
| Ingestion (cluster) |
"Hundreds of millions of samples per second" (FAQ); Roblox runs 120M data points/s on 200 vmstorage nodes (case study) |
N/A |
About 50M samples/s at 1B active series in the Grafana Labs load test |
The table was rebuilt on 2026-09-27 from primary sources. The old community estimates (VictoriaMetrics ~2 GB, Prometheus ~10-20 GB, Thanos ~8-15 GB and Mimir ~8-12 GB of RAM per 1M series; Thanos and query-latency cells) had no source and were removed.
Key Findings
- RAM: VictoriaMetrics commonly reports several times less RAM than Prometheus for the same workload, with the largest gap at high cardinality.
- Disk: Custom encodings plus ZSTD give below 1 byte per sample on typical data.
- Cardinality resilience: Limits such as
-search.maxUniqueTimeseries, -storage.maxHourlySeries and -storage.maxDailySeries cap the blast radius of cardinality spikes.
Production Scale Records
| Company |
Scale |
Source |
| Roblox |
5 billion active series; 100% availability for three straight quarters |
Case studies |
| Grammarly |
10x cost and maintenance reduction |
Case studies |
| CERN |
CMS detector monitoring |
Case studies |
| Spotify |
Replaced internal Heroic system |
Case studies |
| Wix |
60% reduction in yearly infra cost after migration |
Case studies |
| DreamHost |
76M active series, 80% memory reduction, 450k+ data points/s |
VictoriaMetrics blog case study (not on the docs case-study page) |
VictoriaLogs Benchmarks
| Metric |
VictoriaLogs |
Loki |
Elasticsearch |
| Vendor claim |
Up to 30x less RAM and up to 15x less disk than Elasticsearch and Loki (VictoriaLogs docs) |
— |
— |
| Index approach |
Columnar per-field blocks, bloom filters per block, sparse time index |
Label (stream) index only |
Inverted index |
| Full-text search |
Yes (word/phrase filters use bloom filters to skip blocks) |
Label selector first, then line scan |
Yes (inverted index) |
| Query (full scan) |
Parallel across all CPU cores |
Parallel across queriers |
Index-driven |
VictoriaTraces Benchmarks
| Metric |
VictoriaTraces |
Tempo |
Jaeger + ES |
| Vendor claim |
Up to 3.7x less RAM and 2.6x less CPU than Tempo (VictoriaTraces docs) |
— |
— |
| Storage |
Local disk (VictoriaLogs engine) |
Object storage (Parquet) |
Elasticsearch cluster |
| External deps |
None |
S3/GCS/Azure |
ES cluster |
| Query APIs |
Jaeger, LogsQL, experimental Tempo/TraceQL subset |
TraceQL |
Jaeger |
| Operational overhead |
Very low (single binary) |
Low-moderate |
High |
Cost
Cost Drivers
| Factor |
Driver |
Optimization |
| Compute |
Insert + select pods |
Right-size; vmselect is stateless and can use spot nodes |
| Storage |
Data volume x retention |
Compression is automatic; tune retention; Enterprise downsampling and retention filters |
| Network |
Internal cluster traffic; replication multiplies it by RF |
Co-locate in one AZ |
| No object storage |
Local persistent disks only |
No S3/GCS request costs; backups to object storage are separate |
Cost at Scale (Self-Hosted, Estimates)
| Scale |
Active Series |
Logs (GB/day) |
Estimated Monthly |
| Small |
100k |
10 |
$100-300 |
| Medium |
1M |
100 |
$500-1,500 |
| Large |
10M |
1 TB |
$2,000-8,000 |
| Enterprise |
100M+ |
10 TB+ |
$10,000-50,000 |
These are illustrative infrastructure figures carried over from the April 2026 note, excluding staff time and Enterprise licensing. No vendor or independent source publishes them; VictoriaMetrics recommends sizing from a test run on your own workload.
Cost Comparison: Victoria Stack vs LGTM vs Datadog
At 1M active series, 100 GB/day logs, and 50M spans/day. The self-hosted and Datadog rows are illustrative figures from the April 2026 note with no published source; the Grafana Cloud row was recomputed from list prices on 2026-09-27:
| Stack |
Est. Monthly Cost |
Ops Burden |
| Victoria Stack (self-hosted) |
$500-1,500 |
Low |
| Self-hosted LGTM |
$1,000-3,000 |
High |
| Grafana Cloud Pro |
About $7,600+ at list price (about $6,400 for 1M billable series at $6.50 per 1,000, plus about $1,200-1,300 of logs; traces extra), before discounts or Adaptive Metrics |
Low |
| Datadog |
$5,000-17,000 |
Very Low |
VictoriaMetrics Cloud Pricing
| Item |
Price (checked 2026-09-27) |
Notes |
| Smallest capacity tiers (VictoriaMetrics, VictoriaLogs, VictoriaTraces) |
From about $190/month |
Fixed-price tiers sized by active series, churn and ingestion rate |
| Larger single-node and cluster tiers |
Not published outside the product: prices are shown in the Cloud console under "Create New Deployment" |
Earlier notes quoted ~$225/month single-node and ~$1,300/month cluster (2026-04); both are superseded |
| Storage |
Fixed price for the storage size you select |
Billed with the tier |
| Egress |
$0.09 per GB |
Matches the AWS rate |
| Trial |
$200 of credits, valid 30 days |
Granted at sign-up |
Source: VictoriaMetrics Cloud billing docs and the VictoriaTraces deployment tiers page. The docs host was not reachable from the research environment, so these figures come from search-engine extracts of those pages; confirm in the console before budgeting. VictoriaMetrics Cloud added managed logs in Q1 2026 (Q1 2026 blog).
Key Self-Monitoring Metrics
| Metric |
What It Tells You |
vm_rows_inserted_total |
Ingestion throughput by protocol |
vm_cache_entries |
Entries per internal cache (type label); used by the official dashboards to estimate active series |
vm_slow_row_inserts_total |
Inserts that missed the cache (high churn / low RAM signal) |
vm_slow_queries_total |
Queries exceeding -search.logSlowQueryDuration |
vm_free_disk_space_bytes |
Free disk under -storageDataPath |
vm_data_size_bytes |
On-disk data size |
vm_hourly_series_limit_rows_dropped_total |
Samples dropped by -storage.maxHourlySeries |
process_resident_memory_bytes |
Actual RAM usage |
vm_persistentqueue_* (vmagent) |
Remote-write backlog (labelled by name since v1.149.0) |
vl_rows_ingested_total, vl_streams_created_total |
VictoriaLogs ingestion rate and new streams |
API Endpoint Access Control
vmauth (or vmgateway) should restrict which API endpoints each user can reach:
| Endpoint |
Risk |
Recommendation |
/api/v1/write, /insert/* |
Data injection |
Restrict to vmagent/service accounts |
/api/v1/query*, /select/* |
Data exposure |
Restrict to Grafana and humans |
/api/v1/export* |
Bulk data export |
Restrict heavily |
/select/multitenant/* |
Cross-tenant reads |
Never expose per-tenant; pin extra_label and blank extra_filters in url_prefix |
/api/v1/admin/tsdb/delete_series |
Data deletion (POST-only since v1.149.0) |
Admins only |
/metrics |
Internal diagnostics |
-metricsAuthKey |
/debug/pprof/* |
Profiling |
-pprofAuthKey or block |
/flags, /-/reload |
Config disclosure, reload |
-flagsAuthKey, -reloadAuthKey |
/snapshot/* |
Storage access |
-snapshotAuthKey or block in production |
/internal/force_merge, /internal/force_flush |
Performance impact |
-forceMergeAuthKey / -forceFlushAuthKey or block |
VictoriaLogs /delete/* |
Log deletion |
-deleteAuthKey (tip, after v1.52.0) or -httpAuth.* |
-snapshotAuthKey, -forceMergeAuthKey and -forceFlushAuthKey are listed from earlier docs; confirm against -help.
Hardening Checklist
| Area |
Recommendation |
| Network isolation |
All backends in a private network; vmauth is the only ingress |
| Internal listener |
Serve /metrics, /flags, pprof on -httpInternalListenAddr (v1.111.0+) bound to localhost/pod network |
| TLS |
HTTPS on vmauth (-tls -tlsCertFile -tlsKeyFile); mTLS to backends is Enterprise |
| Auth tokens |
Unique credential or JWT claim set per tenant; rotate on compromise |
| Tenant headers |
Since v1.150.0 backends accept AccountID/ProjectID headers by default: override them in vmauth headers, or set -enableMultitenancyViaHeaders=false |
| Multitenant reads |
Set extra_label, empty extra_filters and extra_filters[] in url_prefix so clients cannot widen the filter |
| JWT |
Upgrade vmauth to v1.152.0+ if using match_claims (GHSA-f99m-22fh-qw96); verify aud via match_claims for OIDC |
| Endpoint restriction |
Allow only necessary paths per user (url_map + src_paths) |
| Kubernetes |
useStrictSecurity: true per CR or VM_ENABLESTRICTSECURITY=true on the operator |
| Auth keys |
-metricsAuthKey, -pprofAuthKey, -flagsAuthKey, -reloadAuthKey on all components |
| Secret management |
Keep vmauth passwords and OIDC client secrets in Kubernetes Secrets / Vault; VMUser references Secrets |
| Audit |
vmauth access log (access_log), optionally with selected headers (tip) |
Security Advisories of Note
| Advisory |
Component |
Fixed in |
GHSA-f99m-22fh-qw96 — authorization bypass in JWT routing with match_claims |
vmauth |
v1.152.0 (and LTS backports) |
XSS on /vmui/#/relabeling via unescaped /metric-relabel-debug errors |
vmsingle, vmselect |
v1.152.0 (and LTS backports) |
SSRF-driven deletion via GET on delete endpoints |
vmsingle, vmselect; VictoriaLogs/VictoriaTraces /delete/run_task |
v1.149.0 (VM); tip after VL v1.52.0 / VT v0.11.1 |
| OIDC discovery redirect restriction (GHSA-xxqh-2hcc-9fp6) |
vmauth |
tip (after v1.152.0) |
Sources