monitoring: harden the Quadlet units and cap their memory #464

Öppen
öppnade 2026-09-08 23:04:26 +00:00 av supernaut · 0 kommentarer
Ägare

All ten ansible/roles/monitoring/templates/*.container.j2 units and the three monitoring-agent units (alloy, vmagent, node-exporter) have no NoNewPrivileges, no DropCapability, and no MemoryHigh/MemoryMax. Every services-host unit sets all three.

An uncapped Loki or VictoriaMetrics can take down the host whose job is to say the estate is down. CI's smoke:containers only tests the already-hardened units.

Add the three directives per unit, restoring only the capabilities a collector proves it needs (node-exporter needs host namespaces; check each). Extend the container smoke test to cover these units.

All ten `ansible/roles/monitoring/templates/*.container.j2` units and the three `monitoring-agent` units (alloy, vmagent, node-exporter) have no `NoNewPrivileges`, no `DropCapability`, and no `MemoryHigh`/`MemoryMax`. Every services-host unit sets all three. An uncapped Loki or VictoriaMetrics can take down the host whose job is to say the estate is down. CI's `smoke:containers` only tests the already-hardened units. Add the three directives per unit, restoring only the capabilities a collector proves it needs (node-exporter needs host namespaces; check each). Extend the container smoke test to cover these units.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#464
Ingen beskrivning angiven.