:latest images (loki 3.7.3/go1.26.4, presumably grafana/alloy too) reset every TCP connection on this host — kernel is 5.16.7 (Fedora 35, EOL since 2023), too old for whatever the newer Go toolchains need. Confirmed via a disposable grafana/loki:2.9.8 test container: same config, same host, works cleanly. Pin all three images to older stable releases instead of chasing this again on every redeploy. Also fixes an unrelated config bug: instance_addr belongs directly under `common:`, not nested under `common.ring:` — the misplaced field was silently ignored, which didn't help but wasn't the actual cause.
62 lines
1.9 KiB
YAML
62 lines
1.9 KiB
YAML
version: '3.8'
|
|
|
|
services:
|
|
loki:
|
|
# Pinned, not :latest — this host's kernel (5.16.7, Fedora 35 from 2022) resets
|
|
# every TCP connection to containers built with newer Go toolchains
|
|
# (confirmed: grafana/loki:latest, built with go1.26.4, fails; 2.9.8 works).
|
|
image: grafana/loki:2.9.8
|
|
container_name: loki
|
|
command: -config.file=/etc/loki/config.yaml
|
|
restart: unless-stopped
|
|
volumes:
|
|
- /mnt/containers/logging/loki-config/config.yaml:/etc/loki/config.yaml:Z
|
|
- /mnt/containers/logging/loki-data:/loki:Z
|
|
networks:
|
|
- logging-nw
|
|
|
|
alloy:
|
|
# Pinned for the same reason as loki — see comment there.
|
|
image: grafana/alloy:v1.4.3
|
|
container_name: alloy
|
|
command:
|
|
- run
|
|
- --server.http.listen-addr=0.0.0.0:12345
|
|
- --storage.path=/var/lib/alloy/data
|
|
- /etc/alloy/config.alloy
|
|
restart: unless-stopped
|
|
depends_on:
|
|
- loki
|
|
volumes:
|
|
- /mnt/containers/logging/alloy-config/config.alloy:/etc/alloy/config.alloy:Z
|
|
- /mnt/containers/logging/alloy-data:/var/lib/alloy/data:Z
|
|
ports:
|
|
# syslog intake for routers/switches/phones (UDP, RFC3164/5424)
|
|
- '514:514/udp'
|
|
# optional TCP syslog for devices that don't do UDP
|
|
- '1514:1514/tcp'
|
|
networks:
|
|
- logging-nw
|
|
|
|
grafana:
|
|
# Pinned for the same reason as loki — see comment there.
|
|
image: grafana/grafana:10.4.2
|
|
container_name: grafana
|
|
restart: unless-stopped
|
|
depends_on:
|
|
- loki
|
|
environment:
|
|
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_ADMIN_PASSWORD}
|
|
- GF_USERS_ALLOW_SIGN_UP=false
|
|
volumes:
|
|
- /mnt/containers/logging/grafana-data:/var/lib/grafana:Z
|
|
- /mnt/containers/logging/grafana-config/provisioning/datasources:/etc/grafana/provisioning/datasources:Z
|
|
networks:
|
|
- logging-nw
|
|
- reverseproxy-nw
|
|
|
|
networks:
|
|
logging-nw:
|
|
reverseproxy-nw:
|
|
external: true
|