fix(alloy): pass the Grafana token as GCLOUD_RW_API_KEY

Fleet Management's self-monitoring pipelines read the token from that name;
without it their remote-write fails with 401 invalid token.
This commit is contained in:
tiennm99 committed 2026-10-06 16:45:13 +07:00
1 parent 422eab8499
commit 56111e9219
2 files changed
+7

No files matched your search

+6
View File
@@ -43,6 +43,12 @@ All nine are required; `docker compose up` fails fast if any is unset.
| `LOKI_URL` / `LOKI_USER` | Loki push endpoint and user id |
| `GRAFANA_TOKEN` | One Cloud Access Policy token, scopes `metrics:write` + `logs:write` + `fleet-management:read` |
`GRAFANA_TOKEN` is also passed into the container as `GCLOUD_RW_API_KEY`.
Fleet Management's auto-generated `self_monitoring_*` pipelines read the token
from that fixed name; without it their remote-write gets an empty password and
Grafana Cloud answers `401 invalid token`, so the collector shows no health
data in Fleet Management.
Find the values under Grafana Cloud → your stack → **Details** on each data
source, and under Fleet Management. The same token serves `remotecfg`,
Prometheus and Loki basic-auth.
+1
View File
@@ -22,6 +22,7 @@ services:
LOKI_URL: ${LOKI_URL:?required}
LOKI_USER: ${LOKI_USER:?required}
GRAFANA_TOKEN: ${GRAFANA_TOKEN:?required}
GCLOUD_RW_API_KEY: ${GRAFANA_TOKEN:?required}
volumes:
- alloy-data:/var/lib/alloy/data
- /proc:/rootproc:ro