Sign inSign up

christianmaier/base-grafana

By christianmaier

•Updated 1 day ago

Interface of the base platform: Grafana without unused plugins, provisioned from Git, amd64/arm64

Image
Monitoring & observability
0

1.4K

christianmaier/base-grafana repository overview

⁠base-grafana

The interface of the base platform: the official Grafana⁠, reduced to the plugins in use, with data source and dashboards provisioned from Git.

Not a general-purpose Grafana image. It shows the metrics of one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use the official Grafana image⁠.

⁠Tags

One tag per release, X.Y.Z, the same version as base-caddy and base-prometheus of that release (first: 2.1.0). There is no latest: deployments reference a version and its digest.

Platforms: linux/amd64, linux/arm64.

⁠What is inside

  • grafana/grafana, pinned by digest, without the bundled data source plugins that are not used. Only prometheus and loki remain. Fewer plugins mean fewer components to keep patched.
  • /etc/grafana/grafana.ini with only the deviations from Grafana's defaults: no usage reporting, no update checks, no plugin downloads, no fetching of the plugin signature key, log to the console
  • A provisioned data source Prometheus (http://prometheus:9090) and the dashboard Caddy, both read-only in the interface: changes come with a release

⁠Running

PathContent
/var/lib/grafanaGrafana's database (users, preferences); keep it in a volume
/tmpneeds to be writable: the data source plugins write there when they start

Port: 3000. Bind it to the loopback address only, or put it behind a VPN or proxy.

services:
  grafana:
    image: christianmaier/base-grafana:2.1.0
    volumes: ["grafana-data:/var/lib/grafana"]
    ports: ["127.0.0.1:3000:3000"]
    networks: [observability, grafana-local]
    read_only: true
    tmpfs: ["/tmp"]
    cap_drop: ["ALL"]
    security_opt: ["no-new-privileges:true"]
networks:
  observability:
    internal: true
  grafana-local: {}    # Docker publishes no port of a container that is only in internal networks
volumes:
  grafana-data: {}

First login: admin / admin. The image contains no password. Grafana offers to change it but lets you skip, so change it right away; it then stays in the volume.

⁠Security

  • Runs as 472, needs no capabilities, read-only root filesystem
  • Nothing calls out to the internet by configuration
  • Before every release and weekly: scanned for vulnerabilities with a fix (Trivy), for Dockerfile misconfigurations and for secrets (gitleaks). A finding without a fixed Grafana release is accepted only with a written reason and an expiry date, after which it blocks again.
  • SBOM (SPDX) and build provenance attached to every release

Tag summary

Content type

Image

Digest

sha256:92a6051ea…

Size

339.1 MB

Last updated

1 day ago

docker pull christianmaier/base-grafana:2.9.4