fix: point node_exporter at host bind mounts; drop pid:host

prometheus.exporter.unix now reads /rootproc and /rootfs (the existing
host bind mounts) instead of the container's own namespace, so the
filesystem + process metrics actually describe the host. This makes
pid:host unnecessary, so remove it — privileged is enough and pid:host
exposes every host process inside the container.
This commit is contained in:
tiennm99 committed 2026-04-25 11:20:03 +07:00
1 parent a63d142b53
commit fed5d6f8c7
1 file changed
+4 -1
+4 -1
View File
@@ -9,7 +9,6 @@ services:
restart: unless-stopped
hostname: ${ALLOY_HOSTNAME:?required}
privileged: true
pid: host # node_exporter sees host /proc + processes; required for cpu/mem/load metrics
environment:
ALLOY_DEPLOY_MODE: docker
REMOTECFG_URL: ${REMOTECFG_URL:?required}
@@ -94,6 +93,10 @@ configs:
prometheus.exporter.unix "integrations_node_exporter" {
disable_collectors = ["ipvs", "btrfs", "infiniband", "xfs", "zfs"]
// Read host filesystems via bind mounts instead of the container namespace.
rootfs_path = "/rootfs"
procfs_path = "/rootproc"
filesystem {
fs_types_exclude = "^(autofs|binfmt_misc|bpf|cgroup2?|configfs|debugfs|devpts|devtmpfs|tmpfs|fusectl|hugetlbfs|iso9660|mqueue|nsfs|overlay|proc|procfs|pstore|rpc_pipefs|securityfs|selinuxfs|squashfs|sysfs|tracefs)$"
mount_points_exclude = "^/(dev|proc|run/credentials/.+|sys|var/lib/docker/.+)($|/)"