Clean scaffold of a Prometheus instance dedicated to fleet liveness, deliberately separate from the home `prom` on PIHA. Scrapes only itself + the VPS-local node_exporter for now. - image pinned to prom/prometheus:v3.5.0 (LTS) — no :latest anti-pattern - TSDB retention 15d / 2GB on the tight VPS; --web.enable-lifecycle for reloads - mem_limit 512m, oom_score_adj +200 (sacrificial OOM victim before control-plane) - tailscale-internal exposure via plain published 9090, mirroring control-plane - node_exporter scraped via host.docker.internal:9100 (it runs network_mode: host) - secret-free prometheus.yml; alerting/rule_files left as commented placeholders - in-container healthcheck via busybox wget (present in the image; curl is not) Smoke: docker compose config OK; promtool check config SUCCESS; up -d -> /-/healthy + /-/ready OK; both targets (prometheus, fleet-node) report up. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
9 lines
426 B
Plaintext
9 lines
426 B
Plaintext
# fleet-prometheus has NO secrets and NO required environment.
|
|
#
|
|
# Configuration lives entirely in prometheus.yml (secret-free by contract) and
|
|
# the compose command flags. There is intentionally nothing to copy to a .env.
|
|
#
|
|
# This template exists only to keep the standard service file layout. If a
|
|
# future step needs env (e.g. an Alertmanager URL), add it here and wire an
|
|
# env_file into docker-compose.yml at that point.
|