diff --git a/alloy/README.md b/alloy/README.md index db48cd7..bd158fa 100644 --- a/alloy/README.md +++ b/alloy/README.md @@ -132,3 +132,10 @@ the disclosure one. `dockerproxy` mounts `/var/run/docker.sock:ro` and nothing else. + +## Version pinning + +Both images use `latest`. Neither project publishes a moving major tag: +`grafana/alloy` ships only exact `v1.x.y` tags, and `tecnativa/docker-socket-proxy` +only exact `v0.x.y` tags (its bare `0` tag is a stale leftover). `latest` is the +closest equivalent, so new releases arrive on the next redeploy. diff --git a/alloy/compose.yml b/alloy/compose.yml index ab1e836..1ec0317 100644 --- a/alloy/compose.yml +++ b/alloy/compose.yml @@ -1,11 +1,11 @@ services: alloy: - image: grafana/alloy:v1.16.1 + image: grafana/alloy:latest restart: unless-stopped hostname: ${ALLOY_HOSTNAME:?required} - network_mode: host # node_exporter netdev/netstat sees real host interfaces (eth0…) not veth + network_mode: host cap_drop: [ALL] - cap_add: [DAC_OVERRIDE] # read host files owned by other uids: journal, /rootfs, /var/log + cap_add: [DAC_OVERRIDE] security_opt: - no-new-privileges:true mem_limit: 2g @@ -29,20 +29,20 @@ services: - /:/rootfs:ro - /dev/disk/:/dev/disk:ro - /var/lib/docker/:/var/lib/docker:ro - - /var/log:/var/log:ro # journal + syslog/messages/*.log for the Linux-Node integration - - /etc/machine-id:/etc/machine-id:ro # stable host id for systemd journal reader + - /var/log:/var/log:ro + - /etc/machine-id:/etc/machine-id:ro configs: - { source: alloy_config, target: /etc/alloy/config.alloy } command: 'run --storage.path=/var/lib/alloy/data /etc/alloy/config.alloy' dockerproxy: - image: tecnativa/docker-socket-proxy:v0.5.0 + image: tecnativa/docker-socket-proxy:latest restart: unless-stopped security_opt: - no-new-privileges:true mem_limit: 64m pids_limit: 64 - environment: # the API sections cadvisor and the log tailer read; POST stays revoked + environment: CONTAINERS: 1 NETWORKS: 1 IMAGES: 1 @@ -110,7 +110,7 @@ configs: prometheus.exporter.unix "integrations_node_exporter" { disable_collectors = ["ipvs", "btrfs", "infiniband", "xfs", "zfs"] - // Read host filesystems via bind mounts instead of the container namespace. + // Read host filesystems through the /rootfs and /rootproc bind mounts. rootfs_path = "/rootfs" procfs_path = "/rootproc" @@ -134,10 +134,7 @@ configs: forward_to = [prometheus.relabel.integrations_node_exporter.receiver] } - // Keep only the metrics enumerated under "Metrics" in the upstream - // Grafana Cloud Linux Node integration page (157 metrics, verbatim). - // The recording-rule output `instance:node_num_cpu:sum` is computed - // server-side by Grafana Cloud's ruler — not shipped from here. + // Keep only the Grafana Cloud Linux Node integration's metric list. prometheus.relabel "integrations_node_exporter" { forward_to = [prometheus.remote_write.metrics_service.receiver] @@ -164,8 +161,7 @@ configs: forward_to = [loki.relabel.integrations_node_exporter.receiver] } - // File-based logs from the Linux-Node integration: syslog/messages/*.log. - // On systemd hosts, rsyslog often mirrors journald — see README "What it collects". + // File logs from the Linux Node integration: syslog, messages, *.log. local.file_match "integrations_node_exporter_files" { path_targets = [{ __address__ = "localhost", @@ -177,7 +173,7 @@ configs: forward_to = [loki.relabel.integrations_node_exporter.receiver] } - //JOURNAL + // Journal logs. declare "journal_module" { argument "forward_to" { optional = false diff --git a/couchbase/.env.example b/couchbase/.env.example new file mode 100644 index 0000000..a1bfb86 --- /dev/null +++ b/couchbase/.env.example @@ -0,0 +1,5 @@ +# Copy to .env and fill in. Never commit .env. +# +# cp .env.example .env + +# No variables: the cluster is configured in the admin console on port 8091. diff --git a/couchbase/README.md b/couchbase/README.md index ad34b0a..e34cbb9 100644 --- a/couchbase/README.md +++ b/couchbase/README.md @@ -5,7 +5,8 @@ ## Networking -Publishes its ports on the host: +Clients connect to Couchbase directly on its ports, not through a domain on the +proxy, so it publishes them on the host: | Ports | Purpose | | --- | --- | diff --git a/couchbase/compose.yml b/couchbase/compose.yml index 0b2ef80..fc166f9 100644 --- a/couchbase/compose.yml +++ b/couchbase/compose.yml @@ -1,5 +1,3 @@ -version: '3' - services: db: image: couchbase diff --git a/diun/.env.example b/diun/.env.example index 061afaa..85148f1 100644 --- a/diun/.env.example +++ b/diun/.env.example @@ -1,6 +1,6 @@ +DIUN_PROVIDERS_DOCKER_WATCHBYDEFAULT=true DIUN_NOTIF_TELEGRAM_TOKEN= DIUN_NOTIF_TELEGRAM_CHATIDS= -DIUN_PROVIDERS_DOCKER_WATCHBYDEFAULT=true DIUN_WATCH_SCHEDULE=0 0 * * * # DIUN_WATCH_WORKERS=10 # DIUN_WATCH_JITTER=30s