dozzle logs¶
secrets
i make my secrets from my own secret store, which
only fits my setup. the docker secret create commands here are plain
swarm: use them, or however you normally make secrets.
one dozzle UI shows the logs of every container on every docker host, fed by an agent on each host. the hub (the UI) has no docker socket, so every host reaches it through an agent, docker01 included.
| piece | where | port |
|---|---|---|
| hub, the UI | swarm, one replica pinned to docker01 | 8888, host mode, at 192.168.1.41:8888 |
| agent | swarm, mode: global, one per node |
7007, host mode |
| agent | truenas1, syn02, pi-zwave01, each its own stack | 7007 |
compose.yml: the swarm, the hub and one agent per node, 65 lines, 4 notes
each in the code opens a note on that line. download compose.yml
- the dozzle image has no time zone data, so
TZalone changes nothing. the hub and every agent mount the host's/usr/share/zoneinforead-only. - in host mode, 8888 answers only on docker01, the node the hub is pinned to. through the ingress mesh, every node would answer on it.
- the tile on the homepage dashboard, under
deploy.labelsbecause homepage reads labels from the swarm's service specs. the agents have no UI, so they carry no labels. - in host mode, 7007 on a node's own address is that node's agent, so
DOZZLE_REMOTE_AGENTcan name each one. through the ingress mesh, a connection could reach any node's agent.
before you deploy¶
-
make your own certificate pair. the hub and the agents authenticate each other with it:
docker run --name dozzle-certgen amir20/dozzle:v11.1.0 \ generate-certs --cert-out /dozzle_cert.pem --key-out /dozzle_key.pem docker cp dozzle-certgen:/dozzle_cert.pem . docker cp dozzle-certgen:/dozzle_key.pem . docker rm dozzle-certgen- the image has a pair built in, and every copy has the same one. anyone who can reach port
7007with a stock image can read every log on that host - the pair is valid for five years. replace it on the hub and every agent at the same time
- the image has a pair built in, and every copy has the same one. anyone who can reach port
-
on a swarm manager, make the pair two docker secrets:
docker secret create dozzle_agent_cert_v1 dozzle_cert.pem docker secret create dozzle_agent_key_v1 dozzle_key.pem- the hub and the swarm's agents read them through
DOZZLE_CERTandDOZZLE_KEY
- the hub and the swarm's agents read them through
-
copy the pair to each standalone host, into the directory its agent binds from:
host directory truenas1 /mnt/fast/configs/dozzlesyn02 /volume1/docker/dozzlepi-zwave01 /docker-data/dozzle- docker creates a directory at a missing bind source, and the agent then fails its handshake
- a host that loses its copy gets the same pair back. a new pair has to reach the hub and every agent at once
-
deploy the agents on truenas1, syn02 and pi-zwave01 first, then the swarm's stack, which brings up its agents and the hub together
- a hub with no agents answering is an empty UI
state considerations¶
- the hub keeps
/dataindata, a plain named volume with nodriver_opts, so docker keeps it on docker01, where the hub is pinned - the certificate pair is two docker secrets,
dozzle_agent_cert_v1anddozzle_agent_key_v1, which the hub and the swarm's agents mount. the standalone hosts bind the same pair from a directory on the host, as in before you deploy - the agents keep nothing
network considerations¶
- the hub publishes the UI's
8080as8888in host mode, so it answers on docker01 only, at192.168.1.41:8888. its dashboard tile links to it by name,https://dozzle.mydomain.com, which is behind oauth on the lan - each agent publishes
7007in host mode, so a node's own address reaches that node's agent. the hub names every agent by that address in the agent list. see stack conventions - the stack joins no shared overlay network
placement considerations¶
- the hub is one replica pinned to docker01 (
node.hostname == Docker01), so its address stays put instead of following the task between nodes - the swarm's agents run
mode: global, one per node, and a node added to the swarm gets one
the agent list¶
the hub lists every agent by the host's own address, with a name and a sidebar group:
- DOZZLE_REMOTE_AGENT=192.168.1.41:7007|Docker01|Swarm,192.168.1.42:7007|Docker02|Swarm,192.168.1.43:7007|docker03|Swarm,192.168.1.86:7007|truenas1|TrueNAS,192.168.1.31:7007|syn02|Other,192.168.1.96:7007|pi-zwave01|Other
don't use the keepalived VIP. it moves, and the hub would show one node's logs under another's name.
the agents on the standalone hosts¶
truenas1, syn02 and pi-zwave01 are not in the swarm, so none of them can mount a swarm secret. each runs the agent as a stack of its own. it binds the pair read-only from the directory in before you deploy to /dozzle_cert.pem and /dozzle_key.pem, where dozzle looks by default.
compose.yml: the agent on truenas1, 19 lines
compose.yml: the agent on syn02, 20 lines
compose.yml: the agent on pi-zwave01, 20 lines
adding a host¶
- copy the pair to the new host
- add its agent stack, as for syn02 or the pi
- add the host to the hub's
DOZZLE_REMOTE_AGENTlist, which redeploys the hub
checking it¶
the hub's page lists the hosts, and whether it can reach each agent:
false is an agent the hub can't reach or that refuses its certificate. gatus checks each agent's port on each host's own address.