Skip to content

Monitoring: Alloy role (host metrics, container logs, Ponder metrics) - #1

Open
y3v63n wants to merge 4 commits into
AztecProtocol:mainfrom
y3v63n:monitoring/alloy
Open

y3v63n wants to merge 4 commits into
AztecProtocol:mainfrom
y3v63n:monitoring/alloy

Conversation

@y3v63n

@y3v63n y3v63n commented Sep 29, 2026 •

Copy link
Copy Markdown

Adds an alloy Ansible role: Grafana Alloy + node_exporter as a separate compose project, pushing to the Foundation observability VM over the tailnet with cluster=dashtec labels. It collects:

  • Host metrics (node_exporter).
  • Ponder metrics from both indexers' /metrics endpoints (mainnet :42069, testnet :42070). The addresses live in group_vars next to a note tying them to the compose PONDER_PORT / PONDER_TESTNET_PORT defaults.
  • Container health via Alloy's built-in container exporter: running set, restarts, CPU and memory per container. Deploy-time one-off containers (compose run, e.g. the Prisma migrations) and plain docker run containers are filtered out, so they do not distort the "expected containers" baseline on the dashboard and its alert.
  • Container logs for every Compose service.

The role flushes its handlers at the end, so a config change restarts Alloy before the long-running roles that follow.

Security note: the docker and containerd sockets are mounted read-only, but socket access is root-level access to the host either way; :ro does not limit the API. This is the accepted cost of container metrics and logs.

Prerequisite: AztecProtocol/foundation-iac#28 merged and applied (the observability VM, and the tailnet ACL that lets dashtec push to it on 9090/3100).

Deploy: the normal ansible-playbook site.yml run; the role is idempotent.

Tested end to end on a throwaway VM with a real Ponder 0.15.11 (the version this repo pins): the Ponder metrics the dashboard uses (ponder_sync_block, ponder_sync_block_timestamp, ponder_sync_is_realtime, ponder_rpc_request_error_total) exist and arrive with the expected labels; container metrics resolve names on current Docker (which needs the containerd socket); one-off containers produce no series.

🤖 Generated with Claude Code

y3v63n and others added 4 commits September 29, 2026 13:44
New ansible role runs Alloy + node_exporter as a separate compose
project. Collects host metrics, all container logs, and the two
Ponder /metrics endpoints (mainnet 42069, testnet 42070), pushing to
the Foundation observability VM over the tailnet with
cluster=dashtec labels. Requires the tailnet ACL change in
foundation-iac (dashtec -> observability 9090/3100) to be applied
first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Three fixes from an external audit of this PR:
- flush_handlers at the end of the alloy role: handlers otherwise run at
  end of play (hours later behind aztec_node's ready-wait, or never if a
  later role fails), leaving a re-rendered Alloy config silently
  unapplied with no re-notify on the next run.
- Ponder scrape addresses move to group_vars with a comment tying them
  to the compose PONDER_PORT/PONDER_TESTNET_PORT defaults, so a port
  override has one place to update instead of silently killing the
  scrape.
- Comment on the docker.sock mount stating plainly that :ro does not
  reduce API privilege — socket access is root-equivalent; accepted for
  log collection.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Running set, restarts (CPU-counter resets), CPU and memory per container,
trimmed to the four metrics the Foundation Systems dashboard uses. Alloy
gets read-only cgroup/Docker mounts and the containerd socket, which
current Docker needs to resolve container names.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Drop deploy-time one-offs (`compose run`, e.g. Prisma migrations) and
plain `docker run` containers (no Compose project) from the container
metrics, and the unused container_label_* labels. Otherwise they inflate
the "expected containers" baseline on the Foundation Systems dashboard
and its container-missing alert for hours after each deploy. Notes that
the containerd socket mount is root-level access, like docker.sock.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant