diff --git a/CLAUDE.md b/CLAUDE.md index 5c77f98..d54dd6e 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -183,7 +183,8 @@ adding hardening or convention that the platform already provides. when a service does not declare one, and keeps the declared value when it does; Dokploy does not inject anything, so in its default compose mode an omitted policy leaves the container down after a crash or a host reboot. Setting it is -correct on both. +correct on both. `traffmonetizer` sets `restart: always` on purpose, to be +restarted as often as possible. ## Secrets diff --git a/alloy/.env.example b/alloy/.env.example new file mode 100644 index 0000000..46e50ca --- /dev/null +++ b/alloy/.env.example @@ -0,0 +1,23 @@ +# Copy to .env and fill in. Never commit .env. +# +# cp .env.example .env + +# Container hostname, and the Loki/Prometheus `instance` label. Set per host. +ALLOY_HOSTNAME=alloy + +# Grafana Fleet Management endpoint, agent id (set per host) and user id. +REMOTECFG_URL= +REMOTECFG_ID=alloy +REMOTECFG_USER= + +# Prometheus remote-write endpoint and user id. +PROM_URL= +PROM_USER= + +# Loki push endpoint and user id. +LOKI_URL= +LOKI_USER= + +# Cloud Access Policy token with metrics:write, logs:write and +# fleet-management:read. Serves remotecfg, Prometheus and Loki. +GRAFANA_TOKEN= diff --git a/alloy/README.md b/alloy/README.md index 3c4bb9c..16a2301 100644 --- a/alloy/README.md +++ b/alloy/README.md @@ -7,8 +7,7 @@ Management. One container runs both the `node_exporter` (host) and `cadvisor` (container) collectors. A second, tiny container proxies a read-only slice of the Docker API to it. The Alloy config is embedded inline via Compose `configs:`, so -there is no `config.alloy` on disk. There is no `.env.example` either: the -nine variables are exported before `docker compose up`. +there is no `config.alloy` on disk. Both containers have fixed names, `container_name: alloy` and `alloy-dockerproxy`, and `dockerproxy` publishes @@ -50,7 +49,7 @@ source, and under Fleet Management. The same token serves `remotecfg`, Prometheus and Loki basic-auth. ```bash -export ALLOY_HOSTNAME=example-host REMOTECFG_ID=example-host ... +cp .env.example .env # then fill in the values docker compose up -d ``` diff --git a/traffmonetizer/README.md b/traffmonetizer/README.md index bb15c8c..1cfd7e1 100644 --- a/traffmonetizer/README.md +++ b/traffmonetizer/README.md @@ -4,6 +4,11 @@ in `compose.yml` with `container_name: tm` and `restart: always`. It only makes outbound connections, so there is no port to map a domain to. +`restart: always` instead of `unless-stopped` is on purpose: the client should +be restarted as often as possible. Docker brings it back even after a manual +stop once the daemon or host restarts. The Coolify app also has no watch path +for the same reason, so every push to the repository redeploys it. + The image tag is `arm64v8`. Change it to match the host architecture. ## Environment diff --git a/traffmonetizer/compose.yml b/traffmonetizer/compose.yml index 63b162a..c521688 100644 --- a/traffmonetizer/compose.yml +++ b/traffmonetizer/compose.yml @@ -1,4 +1,3 @@ -version: '3.8' services: traffmonetizer: image: 'traffmonetizer/cli_v2:arm64v8'