Skip to content

Reference

Scope

Look-up facts for the Victoria Stack (VictoriaMetrics, VictoriaLogs, VictoriaTraces and the vm* tools): versions and support windows, Community vs Enterprise features, ports and API paths, deployment matrices, data models, query languages, tuning flags, recent default changes, benchmarks, cost, and hardening checklists. Versions verified 2026-09-25 against the upstream CHANGELOG files. See also: hub, Explanation, How-to guides.

Versions and Support

Current Releases

Product Latest release (date) Line / status Source
VictoriaMetrics (single, cluster, vmagent, vmalert, vmauth, vmbackup, vmctl) v1.152.0 (2026-09-14) Rolling "latest" line, new minor about every 2 weeks CHANGELOG
VictoriaMetrics LTS v1.148.4 and v1.136.18 (both 2026-09-11) Two supported LTS lines (Enterprise) LTS releases
VictoriaLogs v1.52.0 (2026-07-16); v1.51.1 (2026-08-18) is an upgrade-bridge patch GA since v1.0.0 (2024-11-12) VictoriaLogs CHANGELOG
VictoriaTraces v0.11.1 (2026-09-16) Pre-1.0 (0.x); first release v0.1.0 on 2025-07-28 VictoriaTraces CHANGELOG
VictoriaMetrics Operator v0.74.1 (2026-08-04) 0.x, CRD API v1beta1 (VM) and v1 (VL/VT*) Operator CHANGELOG
Helm charts victoria-metrics-k8s-stack 0.93.0 (app v1.152.0), victoria-metrics-operator 0.67.3 (app v0.74.1), victoria-logs-single 0.13.9, victoria-traces-single 0.1.11 Chart versions independent of app versions helm-charts repo

Date discrepancy

The upstream CHANGELOG lists v1.152.0 as "Released at 2026-09-14"; one search-engine summary of the GitHub release page reported 2026-09-11. This page uses the CHANGELOG date.

LTS Policy

Rule Value
Who gets LTS builds VictoriaMetrics Enterprise customers (a new LTS line may be public until the next line ships)
New LTS line cadence Every 6 months
Support per line 12 months of bugfixes and security fixes
Lines supported at once 2 (currently v1.148.x and v1.136.x)
Recently ended v1.122.x (last release v1.122.27, 2026-07-17)
Community users Upgrade to the latest release; all LTS fixes also land in latest

Source: LTS-releases.md.

Versions to avoid

A MetricsQL binary-operator ordering bug (for example 10 - (3 + 3 + 4) evaluated as 10 - 3 + 3 + 4) shipped in v1.140.0, v1.136.4 and v1.122.19. Upstream "strongly recommends" avoiding these versions (#10856).

Recent Default and Behavior Changes

Version (date) Component Change
v1.133.0 (2026-01-02) vmsingle, vmstorage Per-partition (per-month) IndexDB. One-time re-registration of active series on upgrade; disk use may rise for retention under 1 month
v1.137.0 (2026-02-27) vmauth JWT authentication with public_keys and vm_access claim templating
v1.137.0 (2026-02-27) vmsingle, vmagent -promscrape.dropOriginalLabels default changed true -> false
v1.138.0 vmauth OIDC discovery (jwt.oidc.issuer) and match_claims routing
v1.143.0 cluster Tenant can be passed in AccountID/ProjectID HTTP headers
v1.147.0 vmauth vm_access claim optional; default_vm_access_claim
v1.149.0 (2026-08-05) vminsert -disableRerouting default true -> false (slowness-based rerouting on; auto-off when -replicationFactor > 1)
v1.149.0 (2026-08-05) vmsingle, vmselect /api/v1/admin/tsdb/delete_series and /tags/delSeries require POST
v1.150.0 (2026-08-17) vminsert, vmselect, vmagent -enableMultitenancyViaHeaders default false -> true; /select/prometheus/... without tenant in path becomes valid (tenant 0:0 if no headers)
v1.152.0 (2026-09-14) vmauth Security fix for JWT match_claims authorization bypass (GHSA-f99m-22fh-qw96)
tip (after v1.152.0) vmauth Browser SSO via OIDC Authorization Code Flow (sso: section) — unreleased as of 2026-09-25
VictoriaLogs v1.51.0 (2026-06-17) LogsQL filter pipe without the filter keyword is rejected unless it starts with field: (for example foo | bar is invalid)
VictoriaLogs v1.52.0 / VictoriaTraces v0.10.0 images Base image Alpine -> distroless; no linux/386 image

Community vs Enterprise

Community (Apache 2.0) components are free; Enterprise binaries and images carry an -enterprise suffix and need -license or -licenseFile. VictoriaMetrics Cloud runs on Enterprise builds.

Feature Community Enterprise
Single-node and cluster VictoriaMetrics, vmagent, vmalert, vmauth, vmbackup/vmrestore, vmctl Yes Yes
Cluster multitenancy, replication, stream aggregation, MetricsQL Yes Yes
vmauth Basic/Bearer auth, routing, load balancing, JWT/OIDC (v1.137+) Yes Yes
Downsampling (-downsampling.period) No Yes
Retention filters (multiple retentions) No Yes
Automatic vmstorage discovery No Yes
vmanomaly (anomaly detection service) No Yes
vmbackupmanager (backup automation) No Yes
vmgateway (JWT/OIDC auth and rate limiting) No Yes
Per-tenant statistics, query execution stats No Yes
mTLS on all components and between cluster components No Yes
vmauth mTLS-based routing, IP filters, Let's Encrypt auto-TLS No Yes
Kafka and Google Pub/Sub integration (vmagent) No Yes
vmalert multitenancy, reading rules from object storage No Yes
FIPS 140-3 compatible builds No Yes
LTS release lines, SLA support No Yes
VictoriaLogs auto-TLS and mTLS No Yes

Source: Enterprise features.

Components, Binaries and Ports

Component Binary / image Default HTTP port Role
VictoriaMetrics single-node victoria-metrics / victoriametrics/victoria-metrics 8428 Ingest + store + query
vminsert vminsert / victoriametrics/vminsert 8480 (/insert/...) Stateless write path; consistent hashing to vmstorage
vmselect vmselect / victoriametrics/vmselect 8481 (/select/...) Stateless query path
vmstorage vmstorage / victoriametrics/vmstorage 8482 (HTTP), 8400 (from vminsert), 8401 (from vmselect) Stateful storage
vmagent vmagent 8429 Scrape, relabel, buffer, remote write
vmalert vmalert 8880 Recording and alerting rules (metrics, logs, traces)
vmauth vmauth 8427 Auth proxy, router, load balancer
VictoriaLogs (single and cluster roles) victoria-logs / victoriametrics/victoria-logs 9428 Same binary acts as vlinsert, vlselect or vlstorage (-storageNode, -insert.disable, -select.disable)
vlagent vlagent 9429 Kubernetes pod and file log collection, HTTP ingestion, on-disk buffering, replication to several VictoriaLogs instances
VictoriaTraces (single and cluster roles) victoria-traces / victoriametrics/victoria-traces 10428 (docs use 10471 for vtselect in cluster examples) OTLP ingest, Jaeger and Tempo query APIs
VictoriaTraces OTLP gRPC same binary Disabled by default; enable with -otlpGRPCListenAddr=:4317 (TLS on by default, -otlpGRPC.tls=false for plaintext) OTLP/gRPC ingest
vtagent (v0.11.0+) vtagent 10429 (default -httpListenAddr, app/vtagent/main.go) Basic OTLP forwarder to /insert/native

Port values for vmagent (8429), vmalert (8880) and vmauth (8427) are the documented defaults of -httpListenAddr; check -help on your version.

API Endpoints

Product Purpose Path
VictoriaMetrics single Prometheus remote write /api/v1/write
VictoriaMetrics single Query / range query /api/v1/query, /api/v1/query_range
VictoriaMetrics single JSON-line import / export /api/v1/import, /api/v1/export
VictoriaMetrics single OpenTelemetry metrics /opentelemetry/v1/metrics
VictoriaMetrics single Snapshots /snapshot/create, /snapshot/list, /snapshot/delete
VictoriaMetrics cluster Write (tenant in path) http://vminsert:8480/insert/<accountID>[:<projectID>]/prometheus/api/v1/write
VictoriaMetrics cluster Query (tenant in path) http://vmselect:8481/select/<accountID>[:<projectID>]/prometheus/api/v1/query
VictoriaMetrics cluster Tenant via headers (default on since v1.150.0) /insert/prometheus/..., /select/prometheus/... + AccountID/ProjectID headers
VictoriaMetrics cluster Multi-tenant writes / reads /insert/multitenant/... (tenant from vm_account_id/vm_project_id labels), /select/multitenant/...
VictoriaMetrics cluster List tenants http://vmselect:8481/admin/tenants
VictoriaLogs JSON lines /insert/jsonline
VictoriaLogs Elasticsearch bulk /insert/elasticsearch/_bulk
VictoriaLogs Loki push /insert/loki/api/v1/push
VictoriaLogs OpenTelemetry logs /insert/opentelemetry/v1/logs
VictoriaLogs LogsQL query / hits / stats /select/logsql/query, /select/logsql/hits, /select/logsql/stats_query
VictoriaLogs Web UI /select/vmui
VictoriaTraces OTLP/HTTP ingest /insert/opentelemetry/v1/traces
VictoriaTraces Jaeger query API (Grafana Jaeger data source URL) /select/jaeger (for example /select/jaeger/api/traces/{trace_id})
VictoriaTraces Tempo query API (experimental) /select/tempo (/api/search, /api/v2/search/tags, /api/v2/traces/{id}, /api/metrics/query_range)
VictoriaTraces LogsQL over spans /select/logsql/query

VictoriaLogs also ingests syslog, journald, Datadog and other formats; see data ingestion. VictoriaTraces ingests OTLP only (HTTP, and gRPC when enabled); Jaeger and Zipkin native ingestion are not listed in its ingestion docs — convert through the OpenTelemetry Collector.

Kubernetes Deployment Matrix

Component Kind Replicas (Min HA) Key Resource Helm Chart Operator CRD
vmagent DaemonSet or Deployment 1 per node (DS) or 2+ CPU, Memory victoria-metrics-agent VMAgent
vmauth Deployment 2+ CPU victoria-metrics-auth VMAuth + VMUser
vminsert Deployment 2+ CPU victoria-metrics-cluster VMCluster
vmselect Deployment or StatefulSet 2+ CPU, Memory victoria-metrics-cluster VMCluster
vmstorage StatefulSet 3+ (at least 2*RF-1 with replication) Disk IOPS, Memory victoria-metrics-cluster VMCluster
VictoriaMetrics single StatefulSet/Deployment + PVC 1 (or 2 independent copies for HA) Disk, Memory victoria-metrics-single VMSingle
VictoriaLogs StatefulSet (single) or cluster 1, or cluster Disk, Memory victoria-logs-single, victoria-logs-cluster, victoria-logs-collector VLSingle, VLCluster, VLAgent, VLDistributed
VictoriaTraces StatefulSet (single) or cluster 1, or cluster Disk, Memory victoria-traces-single, victoria-traces-cluster VTSingle, VTCluster, VTAgent (tip)
vmalert Deployment 1-2 CPU victoria-metrics-alert VMAlert + VMRule
vmanomaly (Enterprise) Deployment 1+ CPU, Memory victoria-metrics-anomaly VMAnomaly
vmoperator Deployment 1 CPU victoria-metrics-operator —

Data Model

Product Unit Identity / key fields Notes
VictoriaMetrics Time series = metric name + labels; samples of (timestamp ms, float64) Internal TSID (primary index); IndexDB maps label pairs -> TSID Blocks of up to 8K samples sorted by TSID; per-month partitions under data/{small,big}/YYYY_MM with their own IndexDB (since v1.133.0)
VictoriaMetrics cluster Same, plus tenant accountID[:projectID] (32-bit unsigned each); tenant auto-created on first write Tenants spread evenly across all vmstorage nodes; no per-tenant directory
VictoriaLogs Log entry = JSON object of fields _msg (message), _time (timestamp), _stream (stream fields, set via _stream_fields) Per-day partitions at <storageDataPath>/partitions/YYYYMMDD; each field stored as a column; bloom filters per block
VictoriaLogs tenant (AccountID, ProjectID) HTTP headers Default 0:0 Same model reused by VictoriaTraces
VictoriaTraces Span stored as a structured log entry trace_id, span name, attributes, resource attributes Built on the VictoriaLogs storage engine; cluster shards spans by trace ID

Query Languages

MetricsQL (Metrics)

MetricsQL is backwards-compatible with PromQL with a documented set of intentional differences (MetricsQL docs):

Feature PromQL MetricsQL
Lookbehind window in rate(m[5m]) Required Optional; defaults from step (and scrape interval)
rate() / increase() extrapolation Extrapolates (fractional increase on integer counters) No extrapolation; uses the last sample before the window, so integer counters give integer increases
keep_metric_names modifier No Keeps metric names after functions and binary operators
Numeric suffixes No K, Ki, M, Mi, G, Gi, T, Ti (8K = 8000, 1.2Mi = 1.210241024)
NaN in output Returned Removed from output
Multiple rollups in one pass No aggr_over_time(("min_over_time","max_over_time"), m[d])
Graphite filters No {__graphite__="foo.*.bar"}
WITH templates No WITH (x = ...) expr
Scalar vs instant vector Distinct types Scalar treated as a label-less instant vector
# rate without explicit window (auto-calculated from step)
rate(http_requests_total{job="api"})

# keep metric names when applying functions
rate({__name__=~"foo|bar"}) keep_metric_names

# numeric suffixes
process_resident_memory_bytes > 2Gi

LogsQL (Logs and Spans)

LogsQL is the query language of VictoriaLogs (also usable against VictoriaTraces spans). A query is a filter expression followed by optional pipes (LogsQL docs):

# error logs from the last 5 minutes (exact match on a field)
_time:5m level:=error

# full-text word search with stats pipe
_time:1h error "connection refused" | stats by (host) count() errors

# extract fields at query time
_time:1h | extract "status=<status_code>" | stats by (status_code) count()

# JSON log parsing then filtering (explicit filter pipe)
_time:5m | unpack_json | filter level:=error | fields _time, _msg, trace_id

# stream filter (fast: skips unrelated streams)
_time:15m {app="nginx"} 500

Key differences from Loki LogQL: LogsQL does not require a stream (label) selector, and high-cardinality fields such as trace_id or user_id are stored as ordinary fields, so trace_id:=abc is a direct filter rather than a runtime JSON parse.

v1.51.0 syntax change

Since VictoriaLogs v1.51.0, a pipe that is only a bare word (for example foo | bar) is rejected. Rewrite as foo bar, foo | filter bar or foo | _msg:bar. vmalert v1.147.0+ embeds this parser, so vlogs rules with the old syntax fail validation on restart.

Critical Tuning Flags

Component Flag Purpose Default
vmsingle, vmstorage -retentionPeriod Data retention (bare number = months) 1 (1 month, 31 days); minimum 1d
vmsingle, vmselect -search.maxUniqueTimeseries Max unique series a single query may touch Auto-calculated from memory and -search.maxConcurrentRequests
vmsingle, vmselect -search.maxQueryDuration Max single query execution time 30s
vmsingle, vmselect -search.maxMemoryPerQuery Per-query memory cap 0 (unlimited)
vmselect -search.maxConcurrentRequests Concurrent query limit Scales with CPU cores (uncapped since v1.150.0)
all storage -memory.allowedPercent Share of RAM for internal caches (not a hard process limit) 60
vmsingle, vmstorage -inmemoryDataFlushInterval How often in-memory parts are persisted 5s
vminsert -replicationFactor=N Store N copies on distinct vmstorage nodes 1
vmselect -replicationFactor=N Do not mark responses partial if fewer than N nodes are down 1
vmselect (and vmstorage) -dedup.minScrapeInterval Deduplication; set to 1ms with replication, or to scrape_interval for HA vmagent pairs 0 (off)
vminsert -disableRerouting Disable slowness-based rerouting false since v1.149.0
vminsert, vmselect, vmagent -enableMultitenancyViaHeaders Accept tenant in AccountID/ProjectID headers true since v1.150.0
vmagent -remoteWrite.label Add labels to all metrics sent to all -remoteWrite.url —
vmagent -remoteWrite.tmpDataPath On-disk persistent queue vmagent-remotewrite-data
VictoriaLogs -retentionPeriod Log retention 7d
VictoriaLogs -retention.maxDiskSpaceUsageBytes / -retention.maxDiskUsagePercent Drop oldest per-day partitions by disk usage (mutually exclusive) unset
VictoriaTraces -otlpGRPCListenAddr Enable OTLP/gRPC listener empty (disabled)

Defaults checked in source

-inmemoryDataFlushInterval=5s (app/vmstorage/main.go), -search.maxMemoryPerQuery=0, meaning no limit (app/vmselect/promql/eval.go), and -remoteWrite.tmpDataPath=vmagent-remotewrite-data (app/vmagent/remotewrite/remotewrite.go) match the flag definitions on the VictoriaMetrics default branch (checked 2026-09-27).

Scaling Decision Matrix

Symptom Component to Scale How
Slow metric queries vmselect Add replicas or CPU; check -search.max* limits
Write backpressure vminsert, vmstorage Add vminsert replicas; if vmstorage is saturated add nodes (rerouting spreads load since v1.149.0)
Disk full on metrics vmstorage Add nodes or disk; reduce retention
High RAM on storage vmstorage Reduce active series / churn; add memory. -memory.allowedPercent only sizes caches
Slow log search VictoriaLogs More CPU (queries parallelize per core) or move to cluster
Log ingestion lag VictoriaLogs More resources or cluster with more vlstorage nodes

High Availability

Mechanism Implementation
Metrics replication -replicationFactor=N on vminsert (and vmselect) + -dedup.minScrapeInterval=1ms on vmselect; at least 2*N-1 vmstorage nodes
Metrics availability With RF=N, data stays queryable if up to N-1 vmstorage nodes fail; vmselect can return partial responses
Single-node HA Two independent single-node instances fed by the same vmagent(s), queried through vmauth load balancing
Logs/Traces HA vlinsert/vtinsert do not replicate; run two independent clusters (or single nodes) and write to both (vlagent or collector fan-out); vlselect returns 502 on unavailable nodes for failover
Proxy HA Multiple vmauth replicas behind a load balancer
Backup vmbackup from instant snapshots (metrics); per-partition snapshots + rsync/rclone (logs, traces)

Benchmarks

Test Conditions and Caveats

  • The figures below mix vendor documentation and community reports. They are not from a single controlled benchmark; treat ranges as indicative only.
  • VictoriaMetrics publishes prometheus-benchmark; VictoriaLogs publishes a logs benchmark suite and appears in JSONBench and ClickBench.
  • Results depend on data shape (active series, churn, label cardinality, query mix).

Resource Efficiency

Metric VictoriaMetrics Prometheus Mimir
RAM at 1M active series Not published: the docs say to size with a test run on your own workload and keep 50% free RAM (capacity planning) Not published by the project Ingesters alone: about 25 GB (2.5 GB per 300,000 in-memory series, RF=3) (Mimir capacity planning)
Disk per sample 0.4-1.75 bytes in official case studies (ARNES 0.4, Adsterra 0.75, Brandwatch ~1.75) (case studies) 1-2 bytes on average (Prometheus storage docs) Capacity planning assumes 2 bytes per sample in compacted blocks
Ingestion (single node) Up to 2M samples/s and 100M active series in real use (FAQ); cluster docs recommend single-node below about 1M samples/s Not published N/A (distributed)
Ingestion (cluster) "Hundreds of millions of samples per second" (FAQ); Roblox runs 120M data points/s on 200 vmstorage nodes (case study) N/A About 50M samples/s at 1B active series in the Grafana Labs load test

The table was rebuilt on 2026-09-27 from primary sources. The old community estimates (VictoriaMetrics ~2 GB, Prometheus ~10-20 GB, Thanos ~8-15 GB and Mimir ~8-12 GB of RAM per 1M series; Thanos and query-latency cells) had no source and were removed.

Key Findings

  • RAM: VictoriaMetrics commonly reports several times less RAM than Prometheus for the same workload, with the largest gap at high cardinality.
  • Disk: Custom encodings plus ZSTD give below 1 byte per sample on typical data.
  • Cardinality resilience: Limits such as -search.maxUniqueTimeseries, -storage.maxHourlySeries and -storage.maxDailySeries cap the blast radius of cardinality spikes.

Production Scale Records

Company Scale Source
Roblox 5 billion active series; 100% availability for three straight quarters Case studies
Grammarly 10x cost and maintenance reduction Case studies
CERN CMS detector monitoring Case studies
Spotify Replaced internal Heroic system Case studies
Wix 60% reduction in yearly infra cost after migration Case studies
DreamHost 76M active series, 80% memory reduction, 450k+ data points/s VictoriaMetrics blog case study (not on the docs case-study page)

VictoriaLogs Benchmarks

Metric VictoriaLogs Loki Elasticsearch
Vendor claim Up to 30x less RAM and up to 15x less disk than Elasticsearch and Loki (VictoriaLogs docs) — —
Index approach Columnar per-field blocks, bloom filters per block, sparse time index Label (stream) index only Inverted index
Full-text search Yes (word/phrase filters use bloom filters to skip blocks) Label selector first, then line scan Yes (inverted index)
Query (full scan) Parallel across all CPU cores Parallel across queriers Index-driven

VictoriaTraces Benchmarks

Metric VictoriaTraces Tempo Jaeger + ES
Vendor claim Up to 3.7x less RAM and 2.6x less CPU than Tempo (VictoriaTraces docs) — —
Storage Local disk (VictoriaLogs engine) Object storage (Parquet) Elasticsearch cluster
External deps None S3/GCS/Azure ES cluster
Query APIs Jaeger, LogsQL, experimental Tempo/TraceQL subset TraceQL Jaeger
Operational overhead Very low (single binary) Low-moderate High

Cost

Cost Drivers

Factor Driver Optimization
Compute Insert + select pods Right-size; vmselect is stateless and can use spot nodes
Storage Data volume x retention Compression is automatic; tune retention; Enterprise downsampling and retention filters
Network Internal cluster traffic; replication multiplies it by RF Co-locate in one AZ
No object storage Local persistent disks only No S3/GCS request costs; backups to object storage are separate

Cost at Scale (Self-Hosted, Estimates)

Scale Active Series Logs (GB/day) Estimated Monthly
Small 100k 10 $100-300
Medium 1M 100 $500-1,500
Large 10M 1 TB $2,000-8,000
Enterprise 100M+ 10 TB+ $10,000-50,000

These are illustrative infrastructure figures carried over from the April 2026 note, excluding staff time and Enterprise licensing. No vendor or independent source publishes them; VictoriaMetrics recommends sizing from a test run on your own workload.

Cost Comparison: Victoria Stack vs LGTM vs Datadog

At 1M active series, 100 GB/day logs, and 50M spans/day. The self-hosted and Datadog rows are illustrative figures from the April 2026 note with no published source; the Grafana Cloud row was recomputed from list prices on 2026-09-27:

Stack Est. Monthly Cost Ops Burden
Victoria Stack (self-hosted) $500-1,500 Low
Self-hosted LGTM $1,000-3,000 High
Grafana Cloud Pro About $7,600+ at list price (about $6,400 for 1M billable series at $6.50 per 1,000, plus about $1,200-1,300 of logs; traces extra), before discounts or Adaptive Metrics Low
Datadog $5,000-17,000 Very Low

VictoriaMetrics Cloud Pricing

Item Price (checked 2026-09-27) Notes
Smallest capacity tiers (VictoriaMetrics, VictoriaLogs, VictoriaTraces) From about $190/month Fixed-price tiers sized by active series, churn and ingestion rate
Larger single-node and cluster tiers Not published outside the product: prices are shown in the Cloud console under "Create New Deployment" Earlier notes quoted ~$225/month single-node and ~$1,300/month cluster (2026-04); both are superseded
Storage Fixed price for the storage size you select Billed with the tier
Egress $0.09 per GB Matches the AWS rate
Trial $200 of credits, valid 30 days Granted at sign-up

Source: VictoriaMetrics Cloud billing docs and the VictoriaTraces deployment tiers page. The docs host was not reachable from the research environment, so these figures come from search-engine extracts of those pages; confirm in the console before budgeting. VictoriaMetrics Cloud added managed logs in Q1 2026 (Q1 2026 blog).

Key Self-Monitoring Metrics

Metric What It Tells You
vm_rows_inserted_total Ingestion throughput by protocol
vm_cache_entries Entries per internal cache (type label); used by the official dashboards to estimate active series
vm_slow_row_inserts_total Inserts that missed the cache (high churn / low RAM signal)
vm_slow_queries_total Queries exceeding -search.logSlowQueryDuration
vm_free_disk_space_bytes Free disk under -storageDataPath
vm_data_size_bytes On-disk data size
vm_hourly_series_limit_rows_dropped_total Samples dropped by -storage.maxHourlySeries
process_resident_memory_bytes Actual RAM usage
vm_persistentqueue_* (vmagent) Remote-write backlog (labelled by name since v1.149.0)
vl_rows_ingested_total, vl_streams_created_total VictoriaLogs ingestion rate and new streams

API Endpoint Access Control

vmauth (or vmgateway) should restrict which API endpoints each user can reach:

Endpoint Risk Recommendation
/api/v1/write, /insert/* Data injection Restrict to vmagent/service accounts
/api/v1/query*, /select/* Data exposure Restrict to Grafana and humans
/api/v1/export* Bulk data export Restrict heavily
/select/multitenant/* Cross-tenant reads Never expose per-tenant; pin extra_label and blank extra_filters in url_prefix
/api/v1/admin/tsdb/delete_series Data deletion (POST-only since v1.149.0) Admins only
/metrics Internal diagnostics -metricsAuthKey
/debug/pprof/* Profiling -pprofAuthKey or block
/flags, /-/reload Config disclosure, reload -flagsAuthKey, -reloadAuthKey
/snapshot/* Storage access -snapshotAuthKey or block in production
/internal/force_merge, /internal/force_flush Performance impact -forceMergeAuthKey / -forceFlushAuthKey or block
VictoriaLogs /delete/* Log deletion -deleteAuthKey (tip, after v1.52.0) or -httpAuth.*

-snapshotAuthKey, -forceMergeAuthKey and -forceFlushAuthKey are listed from earlier docs; confirm against -help.

Hardening Checklist

Area Recommendation
Network isolation All backends in a private network; vmauth is the only ingress
Internal listener Serve /metrics, /flags, pprof on -httpInternalListenAddr (v1.111.0+) bound to localhost/pod network
TLS HTTPS on vmauth (-tls -tlsCertFile -tlsKeyFile); mTLS to backends is Enterprise
Auth tokens Unique credential or JWT claim set per tenant; rotate on compromise
Tenant headers Since v1.150.0 backends accept AccountID/ProjectID headers by default: override them in vmauth headers, or set -enableMultitenancyViaHeaders=false
Multitenant reads Set extra_label, empty extra_filters and extra_filters[] in url_prefix so clients cannot widen the filter
JWT Upgrade vmauth to v1.152.0+ if using match_claims (GHSA-f99m-22fh-qw96); verify aud via match_claims for OIDC
Endpoint restriction Allow only necessary paths per user (url_map + src_paths)
Kubernetes useStrictSecurity: true per CR or VM_ENABLESTRICTSECURITY=true on the operator
Auth keys -metricsAuthKey, -pprofAuthKey, -flagsAuthKey, -reloadAuthKey on all components
Secret management Keep vmauth passwords and OIDC client secrets in Kubernetes Secrets / Vault; VMUser references Secrets
Audit vmauth access log (access_log), optionally with selected headers (tip)

Security Advisories of Note

Advisory Component Fixed in
GHSA-f99m-22fh-qw96 — authorization bypass in JWT routing with match_claims vmauth v1.152.0 (and LTS backports)
XSS on /vmui/#/relabeling via unescaped /metric-relabel-debug errors vmsingle, vmselect v1.152.0 (and LTS backports)
SSRF-driven deletion via GET on delete endpoints vmsingle, vmselect; VictoriaLogs/VictoriaTraces /delete/run_task v1.149.0 (VM); tip after VL v1.52.0 / VT v0.11.1
OIDC discovery redirect restriction (GHSA-xxqh-2hcc-9fp6) vmauth tip (after v1.152.0)

Sources

URL Source Kind Authority Date
VictoriaMetrics CHANGELOG changelog primary 2026-09-25
LTS releases docs primary 2026-09-25
Enterprise features docs primary 2026-09-25
VictoriaLogs CHANGELOG changelog primary 2026-09-25
VictoriaTraces CHANGELOG changelog primary 2026-09-25
Operator CHANGELOG changelog primary 2026-09-25
Cluster docs docs primary 2026-09-25
Single-node docs docs primary 2026-09-25
MetricsQL docs primary 2026-09-25
LogsQL docs primary 2026-09-25
vmauth docs primary 2026-09-25
vmgateway docs primary 2026-04-13
VictoriaTraces querying docs primary 2026-09-25
Case studies case study primary 2026-09-25
prometheus-benchmark tool primary 2026-04-10
Operator security docs primary 2026-09-25