# `logarchiver run` Runs the archiver service: binds the JetStream pull consumer and drains it to S3 + the ClickHouse index, acking only after each object is durably persisted. ```sh logarchiver run [-c config.yaml] ``` ## Behaviour - Creates/updates the durable consumer (`nats.stream` / `nats.durable`) with the configured subject filters, explicit acks, and `nats.ack_wait`. - Batches events per subject and flushes on `batch.max_bytes` / `max_events` / `max_age`. Each flush seals a LARC1 object, PUTs it to S3, writes one index row, then acks the batch. On any failure the batch is Nak'd for redelivery. - Loads the OpenPGP public key from `crypto.pubkey_source` (`file` or `vault`) and refreshes it every `crypto.refresh_interval`. - Serves Prometheus metrics and `/healthz` on `metrics.address` (default `:9090`) when `metrics.enabled`. - Handles SIGINT/SIGTERM: stops fetching, drains open batches (bounded), exits. ## Key env vars | Env | Purpose | |---|---| | `NATS_CONSUMER_PASSWORD` | NATS `log-consumer` password (nats-auth secret). | | `ARCHIVE_SUBJECTS` | Space-separated subject filters (overrides `nats.subjects`). | | `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` | S3 creds (cephrgw `logs-archive-s3`). | | `S3_ENDPOINT` / `BUCKET_NAME` | Optional S3 endpoint/bucket from the cephrgw secret. | | `CLICKHOUSE_PASSWORD` | ClickHouse `vector` user password. | | `VAULT_ADDR` | Vault address when `pubkey_source: vault`. | | `LOGARCHIVER_CONFIG` | Config file path (same as `-c`). | ## Metrics `logarchiver_objects_stored_total`, `_events_archived_total`, `_raw_bytes_total`, `_stored_bytes_total`, `_store_failures_total`, `_index_failures_total`, `_messages_fetched_total`, `_acks_total`, `_batches_flushed_total{trigger}`, `logarchiver_pending_events`.