Files
composes/alloy
tiennm99 fed5d6f8c7 fix: point node_exporter at host bind mounts; drop pid:host
prometheus.exporter.unix now reads /rootproc and /rootfs (the existing
host bind mounts) instead of the container's own namespace, so the
filesystem + process metrics actually describe the host. This makes
pid:host unnecessary, so remove it — privileged is enough and pid:host
exposes every host process inside the container.
2026-04-25 11:20:03 +07:00
..

alloy-docker-compose

One-file Grafana Alloy setup that ships host (linux) and container (docker) telemetry to Grafana Cloud, plus pulls remote config from Grafana Fleet Management.

  • Single container running both node_exporter (host) and cadvisor (containers) collectors.
  • Config embedded inline via Compose configs: — no sidecar config.alloy file on disk.
  • Env-driven — nine shell variables, no .env file.
  • Remote config via remotecfg block (Grafana Fleet Management).

What it collects

Source Component Notes
Host metrics prometheus.exporter.unix CPU, memory, load, disk I/O, filesystem, network, uname, boot time
Container metrics prometheus.exporter.cadvisor CPU, memory, fs usage/limit, network, last_seen
Container logs loki.source.docker all running containers, labeled with container, stream, instance
System logs loki.source.journal (via journal_module) systemd journal with unit, boot_id, transport, level labels
Remote config remotecfg polls Grafana Fleet Management every 60s

keep-filter on metric names trims the firehose down to the standard Grafana Cloud integration dashboards (node-exporter + docker).

Quick start

export ALLOY_HOSTNAME=miti-jp                                                                      # also used as Loki/Prometheus instance label
export REMOTECFG_URL=https://fleet-management-prod-013.grafana.net
export REMOTECFG_ID=miti-jp                                                                        # fleet-management agent id
export REMOTECFG_USER=1431677                                                                      # fleet-management user id
export PROM_URL=https://prometheus-prod-XX-<region>.grafana.net/api/prom/push
export PROM_USER=<prometheus-user-id>
export LOKI_URL=https://logs-prod-XXX.grafana.net/loki/api/v1/push
export LOKI_USER=<loki-user-id>
export GRAFANA_TOKEN=glc_...                                                                       # one Cloud Access Policy token, scopes: metrics:write + logs:write + fleet-management:read

docker compose up -d

Find the PROM_* / LOKI_* / REMOTECFG_* values under Grafana Cloud → your stack → Details on each data source / Fleet Management. The same token is reused for remotecfg, Prometheus, and Loki basic-auth.

Any unset required variable makes docker compose up fail fast.

Multi-host

Same compose file on every host — change ALLOY_HOSTNAME and REMOTECFG_ID per host. Filter in Grafana with instance=~"...".

Security note

Runs as privileged: true (matching the upstream Grafana Cloud docker integration). This is required for cadvisor to read cgroups via /sys and for /dev/kmsg access. If you need least-privilege, see the upstream Alloy docker integration docs and tighten capabilities.

Mounts

Mount Why
/proc:/rootproc:ro node-exporter cpu/mem/load
/sys:/sys:ro node-exporter + cadvisor cgroups
/:/rootfs:ro filesystem collector
/dev/disk/:/dev/disk:ro diskstats device labels
/var/run/docker.sock docker discovery + log streaming
/var/lib/docker:ro cadvisor container metadata
/var/log/journal:ro loki.source.journal
/dev/kmsg (device) cadvisor OOM detection
alloy-data (named volume) WAL + remotecfg cache

License

Apache 2.0 — see LICENSE.