Sign inSign up

christianmaier/base-cadvisor

By christianmaier

•Updated 1 day ago

Container metrics of the base platform: cAdvisor built from source, Docker via a read-only proxy

Image
Monitoring & observability
0

558

christianmaier/base-cadvisor repository overview

⁠base-cadvisor

The container metrics of the base platform: cAdvisor⁠, built from source. It reports per container CPU, memory, network, health and start time.

Not a general-purpose cAdvisor image. Its flags fit one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use the official image⁠.

⁠Tags

One tag per release, X.Y.Z, the same version as the other base-* images of that release. There is no latest: deployments reference a version and its digest.

Platforms: linux/amd64, linux/arm64.

⁠What is inside

  • cAdvisor v0.60.6, built from the release source (checked by SHA-256) with a current Go toolchain and without cgo. The libraries with known vulnerabilities are raised to the versions the project already uses on its main branch.
  • Alpine Linux as runtime base, wget for the healthcheck
  • Flags: Docker containers only, every 15 s, no container labels in the series. Metric groups nobody reads are switched off, the disk ones among them, which would need Docker's whole data directory.

⁠Running

It talks to Docker over TCP at socket-proxy:2375, never to the socket itself: put a proxy there that allows only reading requests. It needs three read-only mounts and no access to Docker's data directory:

Host pathContainer pathWhy
/sys/fs/cgroup/sys/fs/cgroupCPU and memory per container
/proc/rootfs/procnetwork per container
<DockerRootDir>/image/<driver>/layerdb/mountsthe same path below /rootfsto name the containers

<DockerRootDir> and <driver> come from docker info; on most hosts the path is /var/lib/docker/image/overlay2/layerdb/mounts.

Port: 8080, meant for an internal Docker network only, never published.

services:
  cadvisor:
    image: christianmaier/base-cadvisor:X.Y.Z
    volumes:
      - /sys/fs/cgroup:/sys/fs/cgroup:ro
      - /proc:/rootfs/proc:ro
      - /var/lib/docker/image/overlay2/layerdb/mounts:/rootfs/var/lib/docker/image/overlay2/layerdb/mounts:ro
    networks: [observability, docker-api]
    read_only: true
    cap_drop: ["ALL"]
    security_opt: ["no-new-privileges:true"]
    healthcheck:
      test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/healthz"]
networks:
  observability:
    internal: true
  docker-api:
    internal: true

container_health_state is 1 for healthy, 0 for starting or unhealthy and -1 for a container without a healthcheck.

⁠Security

  • Runs as nobody, needs no capabilities, read-only root filesystem
  • Before every release and weekly: scanned for vulnerabilities with a fix (Trivy), for Dockerfile misconfigurations and for secrets (gitleaks)
  • SBOM (SPDX) and build provenance attached to every release

Tag summary

Content type

Image

Digest

sha256:4c31467f6…

Size

22.1 MB

Last updated

1 day ago

docker pull christianmaier/base-cadvisor:2.9.4