Files
docker-infrastructure/logging/docker-compose.yaml
T
pipistrello fb3ac50522 Parse RFC3164 (BSD) syslog in Alloy — real devices don't send RFC5424
Confirmed via packet capture: a Yealink phone and (per RouterOS's known
default behavior) the fleet's routers send classic BSD-style syslog,
not RFC5424. Alloy's loki.source.syslog defaults to RFC5424-only and
was silently dropping every message ("expecting a version value in the
range 1-999"). syslog_format = "rfc3164" fixes it, but that argument
only exists from Alloy v1.5.0 onward (confirmed empirically against
v1.4.3, which fails config load) — bump the pin accordingly. v1.5.0 is
an adjacent minor release, not the kind of large version jump that hit
the Loki/Grafana :latest kernel-incompatibility bug fixed earlier.
2026-07-15 13:03:37 +03:00

64 lines
2.0 KiB
YAML

version: '3.8'
services:
loki:
# Pinned, not :latest — this host's kernel (5.16.7, Fedora 35 from 2022) resets
# every TCP connection to containers built with newer Go toolchains
# (confirmed: grafana/loki:latest, built with go1.26.4, fails; 2.9.8 works).
image: grafana/loki:2.9.8
container_name: loki
command: -config.file=/etc/loki/config.yaml
restart: unless-stopped
volumes:
- /mnt/containers/logging/loki-config/config.yaml:/etc/loki/config.yaml:Z
- /mnt/containers/logging/loki-data:/loki:Z
networks:
- logging-nw
alloy:
# Pinned for the same reason as loki — see comment there. v1.5.0
# specifically (not v1.4.3) because it's the first release with
# syslog_format = "rfc3164" support, needed below.
image: grafana/alloy:v1.5.0
container_name: alloy
command:
- run
- --server.http.listen-addr=0.0.0.0:12345
- --storage.path=/var/lib/alloy/data
- /etc/alloy/config.alloy
restart: unless-stopped
depends_on:
- loki
volumes:
- /mnt/containers/logging/alloy-config/config.alloy:/etc/alloy/config.alloy:Z
- /mnt/containers/logging/alloy-data:/var/lib/alloy/data:Z
ports:
# syslog intake for routers/switches/phones (UDP, RFC3164/5424)
- '514:514/udp'
# optional TCP syslog for devices that don't do UDP
- '1514:1514/tcp'
networks:
- logging-nw
grafana:
# Pinned for the same reason as loki — see comment there.
image: grafana/grafana:10.4.2
container_name: grafana
restart: unless-stopped
depends_on:
- loki
environment:
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_ADMIN_PASSWORD}
- GF_USERS_ALLOW_SIGN_UP=false
volumes:
- /mnt/containers/logging/grafana-data:/var/lib/grafana:Z
- /mnt/containers/logging/grafana-config/provisioning/datasources:/etc/grafana/provisioning/datasources:Z
networks:
- logging-nw
- reverseproxy-nw
networks:
logging-nw:
reverseproxy-nw:
external: true