From 042d6bd6c0f0d753b4d2c5f072bc5743660fee7b Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Tue, 6 Oct 2026 16:19:14 +0700 Subject: [PATCH] chore: drop container labels from cadvisor, require webtop CUSTOM_USER, trim env template comments --- alloy/README.md | 2 +- alloy/compose.yml | 5 +++-- code-server-lsio/.env.example | 1 - code-server/.env.example | 1 - goclaw/.env.example | 4 +--- paseo/.env.example | 14 ++++---------- webtop/README.md | 4 ++-- webtop/compose.yml | 2 +- 8 files changed, 12 insertions(+), 21 deletions(-) diff --git a/alloy/README.md b/alloy/README.md index bd158fa..20f501b 100644 --- a/alloy/README.md +++ b/alloy/README.md @@ -18,7 +18,7 @@ network to reach the proxy over. | Source | Component | Notes | |---|---|---| | Host metrics | `prometheus.exporter.unix` | CPU, memory, load, disk I/O, filesystem, network, uname, boot time, systemd, vmstat, sockstat — the default collector set minus `ipvs/btrfs/infiniband/xfs/zfs` | -| Container metrics | `prometheus.exporter.cadvisor` | CPU, memory, fs usage/limit, network, `last_seen` | +| Container metrics | `prometheus.exporter.cadvisor` | CPU, memory, fs usage/limit, network, `last_seen`. Docker labels are not copied onto the series (`store_container_labels = false`): Coolify gives its containers 50–80 labels, which pushes series past Grafana Cloud's 60-label limit and gets them rejected | | Container logs | `loki.source.docker` | All running containers, labeled `container`, `stream`, `instance` | | Journal logs | `loki.source.journal` | systemd journal, labeled `unit`, `boot_id`, `transport`, `level` | | File logs | `loki.source.file` | `/var/log/syslog`, `/var/log/messages`, `/var/log/*.log` | diff --git a/alloy/compose.yml b/alloy/compose.yml index 1ec0317..55347c4 100644 --- a/alloy/compose.yml +++ b/alloy/compose.yml @@ -210,8 +210,9 @@ configs: } prometheus.exporter.cadvisor "integrations_cadvisor" { - docker_only = true - docker_host = "tcp://127.0.0.1:2375" + docker_only = true + store_container_labels = false + docker_host = "tcp://127.0.0.1:2375" } discovery.relabel "integrations_cadvisor" { targets = prometheus.exporter.cadvisor.integrations_cadvisor.targets diff --git a/code-server-lsio/.env.example b/code-server-lsio/.env.example index e8df0b3..e056e2d 100644 --- a/code-server-lsio/.env.example +++ b/code-server-lsio/.env.example @@ -12,7 +12,6 @@ GIT_NAME= GIT_EMAIL= # Container hostname, also passed in as HOST -- the name zsh's prompt shows. -# Not named HOSTNAME: the deploying shell's own HOSTNAME would override it. SERVICE_HOSTNAME=code-server-lsio # Name of the installed web app. diff --git a/code-server/.env.example b/code-server/.env.example index 9b2befe..fe46998 100644 --- a/code-server/.env.example +++ b/code-server/.env.example @@ -11,7 +11,6 @@ GIT_NAME= GIT_EMAIL= # Container hostname, also passed in as HOST -- the name zsh's prompt shows. -# Not named HOSTNAME: the deploying shell's own HOSTNAME would override it. SERVICE_HOSTNAME=code-server # Name shown in the title bar and welcome page. diff --git a/goclaw/.env.example b/goclaw/.env.example index 167790e..e12bfff 100644 --- a/goclaw/.env.example +++ b/goclaw/.env.example @@ -2,13 +2,11 @@ # # cp .env.example .env -# Bearer token for the gateway API and dashboard. MUST NOT be blank -- a blank -# token serves the agent gateway, and the tools its agents can run, to anyone. +# Bearer token for the gateway API and dashboard. Required. # Generate one with: openssl rand -hex 16 GOCLAW_GATEWAY_TOKEN= # AES-256-GCM key encrypting the LLM provider keys stored in PostgreSQL. -# Changing it makes every stored key unreadable. # Generate one with: openssl rand -hex 32 GOCLAW_ENCRYPTION_KEY= diff --git a/paseo/.env.example b/paseo/.env.example index 7bd1fcf..ae18210 100644 --- a/paseo/.env.example +++ b/paseo/.env.example @@ -11,16 +11,12 @@ PASEO_PASSWORD= # Coolify/Dokploy must be listed here. IPs and localhost are always allowed. PASEO_HOSTNAMES= -# Proxy source IPs whose X-Forwarded-Proto the daemon trusts. Without this it -# trusts loopback only, reads the request as plain HTTP behind Coolify/Dokploy, -# and tells the web UI to open ws:// from an HTTPS page -- which browsers block. -# `uniquelocal` covers the private ranges Docker bridge networks use. +# Proxy source IPs whose X-Forwarded-Proto the daemon trusts. PASEO_TRUSTED_PROXIES=uniquelocal # Agent CLIs to install on start, if not already present. Space- or # comma-separated, from: claude codex opencode copilot omp pi. Leave empty to -# install none. The first start with a new paseo-home volume downloads a few -# hundred MB per agent and takes a while; later starts only check. +# install none. AGENTS=claude codex # Git identity for agents and terminals, as author and committer. git reads @@ -28,8 +24,6 @@ AGENTS=claude codex GIT_NAME= GIT_EMAIL= -# Container hostname, shown as the host label in the web UI. Without it the -# label is a random container ID. Also passed in as HOST -- the name zsh's -# prompt shows. Not named HOSTNAME: the deploying shell's own HOSTNAME would -# override it. +# Container hostname, shown as the host label in the web UI. Also passed in as +# HOST -- the name zsh's prompt shows. SERVICE_HOSTNAME=paseo diff --git a/webtop/README.md b/webtop/README.md index 11c24b0..6a1d1ce 100644 --- a/webtop/README.md +++ b/webtop/README.md @@ -25,11 +25,11 @@ The image's own HTTPS port `3001`, with a self-signed certificate, is unused. | Variable | Default | Purpose | | --- | --- | --- | -| `CUSTOM_USER` / `PASSWORD` | `miti99` / — | Login for the web desktop | +| `CUSTOM_USER` / `PASSWORD` | — | Login for the web desktop | | `TZ` | `Asia/Ho_Chi_Minh` | Desktop timezone | | `TITLE` | optional | Browser tab title | -`PASSWORD` is required: without it the image serves the desktop, with a +`CUSTOM_USER` and `PASSWORD` are required. Without `PASSWORD` the image serves the desktop, with a shell and `sudo`, to anyone who opens the domain. `PUID`/`PGID` are pinned to `1000` in `compose.yml`; the `Dockerfile` depends diff --git a/webtop/compose.yml b/webtop/compose.yml index 07a4d9c..c7b401d 100644 --- a/webtop/compose.yml +++ b/webtop/compose.yml @@ -4,7 +4,7 @@ services: restart: unless-stopped shm_size: 1gb environment: - - CUSTOM_USER=${CUSTOM_USER:-miti99} + - CUSTOM_USER=${CUSTOM_USER:?required} - PASSWORD=${PASSWORD:?required} - PUID=1000 - PGID=1000