Sign inSign up

christianmaier/base-blackbox

By christianmaier

•Updated 1 day ago

Probes of the base platform: Blackbox Exporter built from source, non-root, linux/amd64 and arm64

Image
0

1.0K

christianmaier/base-blackbox repository overview

⁠base-blackbox

The probes of the base platform: the Prometheus Blackbox Exporter⁠, built from source, with the platform's probe modules baked in. Prometheus asks it whether the public names behind the reverse proxy answer, and how long their certificates are still valid.

Not a general-purpose Blackbox Exporter image. The modules fit one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use the official image⁠.

⁠Tags

One tag per release, X.Y.Z, the same version as the other base-* images of that release (first: 2.4.0). There is no latest: deployments reference a version and its digest.

Platforms: linux/amd64, linux/arm64.

⁠What is inside

  • The Blackbox Exporter v0.28.0, built from the release source (checked by SHA-256) with a current Go toolchain. The libraries with known vulnerabilities are raised to the versions the project already uses on its main branch. The project's own tests run during the build.
  • Alpine Linux as runtime base: CA certificates for verifying TLS, wget for the healthcheck
  • /etc/blackbox_exporter/config.yml with two modules:
    • http_site: HTTPS only, no redirects followed, a valid certificate, and one of the status codes the probed paths answer on purpose (200, 401, 404); a 5xx such as 502 fails the probe
    • a TLS-only module for a name that answers only inside a VPN, so that at least its certificate is checked

⁠How it probes

The exporter needs no internet access. Prometheus sends each probe to the reverse proxy on an internal network and passes the public name as hostname. The exporter then uses that name as Host header and TLS SNI. The certificate is verified as a browser would verify it.

scrape_configs:
  - job_name: probe-http
    scrape_interval: 1m
    metrics_path: /probe
    params:
      module: [http_site]
    static_configs:
      - targets: ["https://www.example.com/"]
    relabel_configs:
      - source_labels: [__address__]
        target_label: instance
      - source_labels: [__address__]
        regex: "https://([^/]+)/.*"
        target_label: __param_hostname
      - source_labels: [__address__]
        regex: "https://[^/]+(/.*)"
        replacement: "https://proxy$1"
        target_label: __param_target
      - target_label: __address__
        replacement: blackbox:9115

⁠Running

Port: 9115, meant for an internal Docker network only, never published.

services:
  blackbox:
    image: christianmaier/base-blackbox:2.4.0
    networks: [observability]
    read_only: true
    cap_drop: ["ALL"]
    security_opt: ["no-new-privileges:true"]
    healthcheck:
      test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:9115/-/healthy"]
networks:
  observability:
    internal: true

⁠Security

  • Runs as nobody, needs no capabilities (HTTP and TCP probes only, no ICMP), read-only root filesystem
  • Before every release and weekly: scanned for vulnerabilities with a fix (Trivy), for Dockerfile misconfigurations and for secrets (gitleaks)
  • SBOM (SPDX) and build provenance attached to every release

Tag summary

Content type

Image

Digest

sha256:6a2e5e787…

Size

19.5 MB

Last updated

1 day ago

docker pull christianmaier/base-blackbox:2.9.4