From 2a24eaf10b16a22c478ee49df16bdfd69c2f00b6 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Sun, 26 Apr 2026 10:15:29 +0700 Subject: [PATCH] fix: drop explicit journal path and bump alloy to v1.16.0 `loki.source.journal "default"` no longer pins `path = "/var/log/journal"`. Upstream omits the field, which lets Alloy default to BOTH `/var/log/journal` (persistent) and `/run/log/journal` (volatile). The explicit path silently dropped journal logs on hosts with volatile-only storage. Matches the canonical Linux Node integration template. Also bumps the image six minor versions to current stable. Doc records the 2026-04-26 re-audit. --- alloy/docker-compose.yml | 3 +-- alloy/docs/upstream-sources-of-truth.md | 5 +++++ 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/alloy/docker-compose.yml b/alloy/docker-compose.yml index f7503f6..76f2c07 100644 --- a/alloy/docker-compose.yml +++ b/alloy/docker-compose.yml @@ -4,7 +4,7 @@ services: alloy: - image: grafana/alloy:v1.10.0 + image: grafana/alloy:v1.16.0 container_name: alloy restart: unless-stopped hostname: ${ALLOY_HOSTNAME:?required} @@ -165,7 +165,6 @@ configs: loki.source.journal "default" { max_age = "12h0m0s" - path = "/var/log/journal" forward_to = [loki.process.default.receiver] relabel_rules = loki.relabel.default.rules } diff --git a/alloy/docs/upstream-sources-of-truth.md b/alloy/docs/upstream-sources-of-truth.md index 906987c..cb4d574 100644 --- a/alloy/docs/upstream-sources-of-truth.md +++ b/alloy/docs/upstream-sources-of-truth.md @@ -65,6 +65,11 @@ Both keep-lists in `docker-compose.yml` are copied verbatim from the **Metrics** - **Linux-Node** — 157 raw metrics (`node_*`, `process_max_fds`, `process_open_fds`, `up`). The list also contains `instance:node_num_cpu:sum`, which is a recording-rule output computed server-side by Grafana Cloud's ruler — it's intentionally **not** in the keep-list because the agent doesn't produce it. - **Docker** — 16 metrics (`container_*`, `machine_memory_bytes`, `machine_scrape_error`, `up`). +Re-verification on 2026-04-26 also confirmed: + +- **Alloy image** bumped `v1.10.0` → `v1.16.0` (latest stable, released 2026-04-23). +- **`loki.source.journal` `path`** was previously pinned to `/var/log/journal`; upstream omits the field, letting Alloy default to **both** `/var/log/journal` (persistent) and `/run/log/journal` (volatile). Local now matches — `path` removed. + The Grafana Cloud integration's full dashboard set (the 7 Linux-Node + 2 Docker dashboards) is not publicly hosted. Tier-4 verification (against the live stack via authenticated API) was **not** performed and is the only known gap. ### Re-running the audit