fix: drop explicit journal path and bump alloy to v1.16.0

`loki.source.journal "default"` no longer pins `path = "/var/log/journal"`.
Upstream omits the field, which lets Alloy default to BOTH
`/var/log/journal` (persistent) and `/run/log/journal` (volatile). The
explicit path silently dropped journal logs on hosts with volatile-only
storage. Matches the canonical Linux Node integration template.

Also bumps the image six minor versions to current stable. Doc records
the 2026-04-26 re-audit.
This commit is contained in:
tiennm99 committed 2026-04-26 10:15:29 +07:00
1 parent 9399a8b115
commit 2a24eaf10b
2 files changed
+6 -2

No files matched your search

+1 -2
View File
@@ -4,7 +4,7 @@
services:
alloy:
image: grafana/alloy:v1.10.0
image: grafana/alloy:v1.16.0
container_name: alloy
restart: unless-stopped
hostname: ${ALLOY_HOSTNAME:?required}
@@ -165,7 +165,6 @@ configs:
loki.source.journal "default" {
max_age = "12h0m0s"
path = "/var/log/journal"
forward_to = [loki.process.default.receiver]
relabel_rules = loki.relabel.default.rules
}
+5
View File
@@ -65,6 +65,11 @@ Both keep-lists in `docker-compose.yml` are copied verbatim from the **Metrics**
- **Linux-Node** — 157 raw metrics (`node_*`, `process_max_fds`, `process_open_fds`, `up`). The list also contains `instance:node_num_cpu:sum`, which is a recording-rule output computed server-side by Grafana Cloud's ruler — it's intentionally **not** in the keep-list because the agent doesn't produce it.
- **Docker** — 16 metrics (`container_*`, `machine_memory_bytes`, `machine_scrape_error`, `up`).
Re-verification on 2026-04-26 also confirmed:
- **Alloy image** bumped `v1.10.0` → `v1.16.0` (latest stable, released 2026-04-23).
- **`loki.source.journal` `path`** was previously pinned to `/var/log/journal`; upstream omits the field, letting Alloy default to **both** `/var/log/journal` (persistent) and `/run/log/journal` (volatile). Local now matches — `path` removed.
The Grafana Cloud integration's full dashboard set (the 7 Linux-Node + 2 Docker dashboards) is not publicly hosted. Tier-4 verification (against the live stack via authenticated API) was **not** performed and is the only known gap.
### Re-running the audit