Sign inSign up

christianmaier/base-node-exporter

By christianmaier

•Updated 1 day ago

Host metrics of the base platform: node_exporter built from source, read-only host view, amd64/arm64

Image
Monitoring & observability
0

549

christianmaier/base-node-exporter repository overview

⁠base-node-exporter

The host metrics of the base platform: the Prometheus node_exporter⁠, built from source, with the collectors the platform's dashboards and alerts read: CPU, load, memory, disk space and disk I/O.

Not a general-purpose node_exporter image. Its flags fit one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use the official image⁠.

⁠Tags

One tag per release, X.Y.Z, the same version as the other base-* images of that release. There is no latest: deployments reference a version and its digest.

Platforms: linux/amd64, linux/arm64.

⁠What is inside

  • node_exporter v1.12.1, built from the release source (checked by SHA-256) with a current Go toolchain. The libraries with known vulnerabilities are raised to the versions the project already uses on its main branch.
  • Alpine Linux as runtime base, wget for the healthcheck
  • Flags: the host's root at /host, the host's /proc at /host/proc, only the collectors listed above. Docker's own mounts, pseudo file systems and virtual disks are left out.

⁠Running

The host's root file system must be mounted read-only at /host. The container joins neither the host's network nor its PID namespace. It does read the host's /proc through that mount: the list of file systems and whether each is read-only come from the host's mount table.

Port: 9100, meant for an internal Docker network only, never published.

services:
  node-exporter:
    image: christianmaier/base-node-exporter:X.Y.Z
    volumes: ["/:/host:ro"]
    networks: [observability]
    read_only: true
    cap_drop: ["ALL"]
    security_opt: ["no-new-privileges:true"]
    healthcheck:
      test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:9100/"]
networks:
  observability:
    internal: true

Without the host's network, the traffic of its network interfaces is not reported.

⁠Security

  • Runs as nobody, needs no capabilities, read-only root filesystem
  • Before every release and weekly: scanned for vulnerabilities with a fix (Trivy), for Dockerfile misconfigurations and for secrets (gitleaks)
  • SBOM (SPDX) and build provenance attached to every release

Tag summary

Content type

Image

Digest

sha256:cd0e8ebc7…

Size

15.4 MB

Last updated

1 day ago

docker pull christianmaier/base-node-exporter:2.9.4