systemd-journald grows logs until told to stop. The honest cap is SystemMaxUse in journald.conf — vacuum alone is a temporary cleanup, and this is a two-minute permanent fix.
journald defaults to using up to 10% of the filesystem. On a 100GB root disk that's 10GB of journals by design. journald shows its own view: journalctl --disk-usage.
Storage=auto with /var/log/journal present = persistent. If the directory exists, journald keeps everything forever unless capped.
journalctl --disk-usage && du -sh /var/log/journal
# /etc/systemd/journald.conf:
# [Journal]
# SystemMaxUse=500M
# SystemKeepFree=1G
sudo systemctl restart systemd-journald && sudo journalctl --vacuum-size=500M
sudo journalctl --vacuum-time=30d # and optionally MaxRetentionSec=30day in journald.conf
Restarting journald briefly blocks logging; do it in a maintenance window on busy systems. If you need long-term logs, ship them (vector, promtail) instead of growing the journal — journald is a ring buffer, not an archive.
journald reports its accounting of the journal files; du counts actual blocks (sparse files, old rotated journals). Either way, SystemMaxUse + --vacuum-size brings both down.
Prefer --vacuum-* commands: direct deletion can confuse journald's bookkeeping. If you must, delete only archived .journal~ files while journald is running.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.