Conversation
… reference - docs/02-platforms.md: Podman, Synology, Unraid, TrueNAS SCALE, macOS and Windows, Docker Swarm and Kubernetes, each saying how well it is known to work. - docs/02-security.md: what :ro on the Docker socket does not do, a read-only docker-socket-proxy with the API sections DockTail uses, and dropping capabilities. - docker-compose.yaml is now a deployment example; the development stack moves to docker-compose.dev.yaml (make up/down/logs follow). New docker-compose.cloud.yaml enables DockTail Cloud reporting. - docs/06-cloud.md: Cloud is a paid service, the unmonitored preview host, prerequisites with Tailscale API credentials first, the enrollment window choices. - docs/07-reference.md and .env.example: every variable DockTail reads, including the Docker client variables, NO_COLOR and DOCKTAIL_HOST_ROOT; DOCKTAIL_LOG_LEVEL and TAILSCALE_SOCKET now say what they actually do.
Keep DockTail on a normal network next to the socket proxy, hedge the Unraid, SELinux and Swarm notes to what users reported, drop the untested non-root paragraph, and make .env.example say which variables reach DockTail.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documentation for running DockTail beyond a plain Linux Docker host, a clean set of Compose examples, and an environment reference that matches the code.
What changes
Platform guides (
docs/02-platforms.md, new): Podman, Synology, Unraid, TrueNAS SCALE, macOS and Windows, Docker Swarm, Kubernetes. Each one says how well it is known to work. It is either reported by users (I may just be dumb, but does this not work in Unraid? #12, Docker Swarm Version #43, Support multiple docker sockets (for podman) #49, Macos Support #68), not tested by the maintainers, or not supported (Kubernetes: no Docker Engine API and no Helm chart). The Swarm layout is based on the one reported working in Docker Swarm Version #43: a global DockTail plustailscaledper node, top-level containerlabels:instead ofdeploy.labels, at most one replica per node, and nostart-firstfor the sidecar.Hardening (
docs/02-security.md, new)::roondocker.sockprotects nothing;tecnativa/docker-socket-proxysetup with the exact sections (CONTAINERS,INFOfor Cloud, plus the defaultEVENTS/PING/VERSION,POST=0);cap_drop: [ALL]+no-new-privileges, and the caveat that*_FILEsecrets must then be readable by root through normal permission bits.Compose files:
version:,build: ., test containers, unused volume) moves todocker-compose.dev.yaml.make up/down/logsfollow it, andlogsnow names the right container.docker-compose.yamlis now a deployment example.docker-compose.cloud.yamlenables Cloud reporting.docs/06-cloud.md:docs/07-reference.mdand.env.example: every variable DockTail reads, now including the Docker client'sDOCKER_API_VERSION/DOCKER_CERT_PATH/DOCKER_TLS_VERIFY, plusNO_COLOR,DOCKTAIL_HOST_ROOTand the dev-only cloud overrides. Two descriptions were wrong:DOCKTAIL_LOG_LEVELis read but has no effect;LOG_LEVELsets the cloud module's level.TAILSCALE_SOCKETonly feeds the socket checks. The bundledtailscaleCLI is never passed--socketand always uses/var/run/tailscale/tailscaled.sock..env.examplenow also says that only variables listed under a service'senvironment:reach DockTail.Section edits to
06-cloud.md,07-reference.md,02-installation.mdandREADME.mdare kept small so they sit alongside the open doc PRs.git merge-treeagainst #90, #92, #93 and #94 is clean.Notes for merging
UPDATE_CHECKandHEALTH_FILEto the environment table. Whichever PR merges last should check that.env.examplelists them too.02-installation.md. It sits next to the new "Platform Guides" page, so a cross-link is worth adding once both have landed.02-prefix (02-platforms.md,02-security.md) so they sort after Installation without renumbering the existing files.Follow-ups found while writing this (not changed here)
TAILSCALE_SOCKETis not passed to thetailscaleCLI (tailscale/utils.gotailscaleCmd).DOCKTAIL_LOG_LEVELis parsed butConfig.ZerologLevelis never used.RECONCILE_INTERVAL=0s(or negative) parses and then panics intime.NewTicker.Refs marvinvr/docktail-cloud#82