readystack/loki:v3.7.8-CE-ubuntu24.04-r1
A hardened, cosign-signed, offline-rebuildable build of github.com/grafana/loki v3.7.8 (AGPL-3.0-only), built clean-room from official upstream source by ReadyStack.
cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/loki:v3.7.8-CE-ubuntu24.04-r1.This image follows the ReadyStack release-tag convention:
The current release is v3.7.8-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/loki:v3.7.8-CE-ubuntu24.04-r1
# ✗ unsupported (do not pull)
docker pull readystack/loki:internal-...
Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/loki:v3.7.8-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected].
Single container, single static Go binary running in single-binary monolithic mode (-target=all, all components in one process), foreground process. Log aggregation with the tsdb index + chunk object-store BOTH on the local filesystem under /loki; NO relational/SQL database, NO external object store, NO sidecar. The image IS the complete running instance.
docker run -d --name loki -p 127.0.0.1:3100:3100 -v loki-data:/loki readystack/loki:v3.7.8-CE-ubuntu24.04-r1
Starts a single Loki server (single-binary -target=all) with its data in the loki-data volume. Cold start to /ready (200, body 'ready') measured 14-17 seconds across three boots. Reach it at http://localhost:3100 (published on the host's 127.0.0.1 only, because Loki has no authentication: anyone who reaches port 3100 can push and query; containers on the same Docker network can reach it regardless). Port 9095 (internal gRPC) is not published and does not need to be (tested); it still listens on all container interfaces, so containers on the same Docker network can reach it, unauthenticated like 3100. The archive ships no ReadyStack Compose file for this image (the docker-compose files under the upstream source tree are upstream's examples and run upstream's grafana/loki images).
The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:ad5d005fb…
Size
114.4 MB
Last updated
1 day ago
docker pull readystack/loki:v3.7.8-CE-ubuntu24.04-r1