Configure storage
The scalable installation requires a managed object store such as AWS S3 or Google Cloud Storage or a self-hosted store such as Minio. The single binary installation can use the filesystem for storage, but we recommend configuring object storage via cloud provider or pointing Loki at a MinIO cluster for production deployments.
This guide assumes Loki will be installed in one of the modes above and that a values.yaml has been created.
To use a managed object store:
In the
values.yamlfile, setloki.storage.typetoazure,gcs, ors3.Configure the storage client under
loki.storage.azure,loki.storage.gcs, orloki.storage.s3.Set
loki.storage.bucketNames.chunksandloki.storage.bucketNames.rulerto your bucket or container names.
These values configure the legacy storage clients, which are deprecated. To use the Thanos-based clients instead, refer to the following section.
To install Minio alongside Loki:
Warning
The built-in MinIO subchart is deprecated and will be removed on 2026-10-31. Setting
minio.enabled=truefails chart rendering with v17+ unlessignoreMinioDeprecation: trueis also set. Grafana recommends configuring a dedicated external object storage backend instead of using the built-in MinIO subchart for new deployments.
Change the configuration in
values.yaml:- Enable Minio
ignoreMinioDeprecation: true # Temporary workaround – MinIO will be removed 2026-10-31 minio: enabled: true
To use Thanos object store clients:
Loki 4.0 uses object storage clients based on the Thanos Object Storage Client Go module by default, and the legacy storage clients are deprecated. The Helm chart is an exception, because it sets loki.storage.use_thanos_objstore to false. To use the Thanos-based clients with the chart, you must set this value to true yourself.
To convert an existing storage configuration to the new format, refer to Migrate to Thanos storage clients.
Enable the Thanos-based clients in
values.yaml:loki: storage: use_thanos_objstore: true bucketNames: chunks: <YOUR_CHUNKS_BUCKET> ruler: <YOUR_RULER_BUCKET> object_store: type: s3 # Valid options: s3, gcs, azure s3: endpoint: <YOUR_ENDPOINT> region: <YOUR_REGION>Configure the storage client under
loki.storage.object_store.s3,loki.storage.object_store.gcs, orloki.storage.object_store.azure.
To grant access to S3 via an IAM role without providing credentials:
Provision an IAM role, policy and S3 bucket as described in Storage.
- If the Terraform module was used note the annotation emitted by
terraform output -raw annotation.
- If the Terraform module was used note the annotation emitted by
Add the IAM role annotation to the service account in
values.yaml:serviceAccount: annotations: "eks.amazonaws.com/role-arn": "arn:aws:iam::<account id>:role/<role name>"Configure the storage:
loki: storage: type: "s3" s3: region: eu-central-1 bucketNames: chunks: <bucket name> ruler: <bucket name> admin: <bucket name> #only needed for GEL installationsNote that
endpoint,secretAccessKeyandaccessKeyIdhave been omitted.