Files
archy/apps/grafana/manifest.yml
T
archipelagoandClaude Fable 5 dbe37f7ffe fix(grafana): manifest and curation move onto the fleet trust floor
The signed catalog has homed grafana at lfg2025/grafana:10.2.0 in the fleet
registry all along; the manifest still pulled Docker Hub's grafana/grafana,
so the repo-mismatch guard (correctly) discarded the catalog image on every
tick and warned every ~75s on every node. Registry verified to carry the
image; aligning the repo path makes the already-signed catalog entry
effective — no re-signing needed, no behavioural change beyond pull source.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-10 13:45:10 -04:00

60 lines
1.2 KiB
YAML

app:
id: grafana
name: Grafana
version: 10.2.0
description: Analytics and monitoring platform. Visualize metrics and create dashboards.
container:
image: source.archipelago-foundation.org/lfg2025/grafana:10.2.0
image_signature: cosign://...
pull_policy: if-not-present
data_uid: "472:472"
dependencies:
- storage: 5Gi
resources:
cpu_limit: 2
memory_limit: 1Gi
disk_limit: 5Gi
security:
capabilities: []
readonly_root: true
no_new_privileges: true
user: 1000
seccomp_profile: default
network_policy: isolated
apparmor_profile: grafana
ports:
- host: 3000
container: 3000
protocol: tcp # Web UI
bind: 127.0.0.1
auth: gated
volumes:
- type: bind
source: /var/lib/archipelago/grafana
target: /var/lib/grafana
options: [rw]
environment:
- GF_SECURITY_ADMIN_USER=admin
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_ADMIN_PASSWORD}
- GF_SERVER_ROOT_URL=http://localhost:3000
- GF_INSTALL_PLUGINS=
health_check:
type: http
endpoint: http://localhost:3000
path: /api/health
interval: 30s
timeout: 30s
retries: 5
metadata:
launch:
open_in_new_tab: true