Compare commits

..
1 Commits
Author SHA1 Message Date
smileBeda 168c4558aa Reset history to current sanitized state 2026-08-06 16:20:11 +00:00
3 changed files with 62 additions and 1 deletions
+13
View File
@@ -12,3 +12,16 @@
# Built Visual Studio Code Extensions
*.vsix
# BEGIN reset-history environment exclusions
.env
.env.*
*.env
*.env.*
!.env.example
!.env.*.example
!*.env.example
!*.env.*.example
*.swp
.DS_Store
# END reset-history environment exclusions
+23 -1
View File
@@ -1,2 +1,24 @@
# grafana
# Grafana
Self-hosted visualization and alerting service for dashboards built from configured monitoring data sources.
## Deployment layout
- **Compose:** `/srv/docker/grafana/docker-compose.yml`
- **Static configuration/source:** no additional static configuration or build source
- **Non-secret environment:** embedding, cookie, content-security-policy, and anonymous Viewer settings are declared
inline in Compose; there is no project-local `.env`
- **Secrets:** none
- **NVMe application state:** `/srv/appdata/grafana/data`
- **Bulk HDD data:** none
- **Other mounts:** none
Secrets are never committed to this repository. No standalone secret file is
declared; credentials entered through Grafana are retained in its protected application-managed state.
## Dependencies and recovery
- **Networks/dependencies:** external `npm_proxy` network at `192.168.96.13`; monitoring data sources are configured
within Grafana and were not inspected
- **Back up:** `/srv/appdata/grafana/data`
- **Re-creatable:** the Grafana container; no separate cache or temporary-data mount is declared
+26
View File
@@ -0,0 +1,26 @@
services:
grafana:
mem_limit: 768m
memswap_limit: 1.5g
image: grafana/grafana-enterprise
container_name: grafana
restart: unless-stopped
volumes:
- /srv/appdata/grafana/data:/var/lib/grafana
# ports:
# - '3000:3000'
environment:
- GF_SECURITY_ALLOW_EMBEDDING=true
- GF_SECURITY_COOKIE_SAMESITE=none
- GF_SECURITY_COOKIE_SECURE=true
- GF_SECURITY_CONTENT_SECURITY_POLICY=true
- GF_SECURITY_CONTENT_SECURITY_POLICY_TEMPLATE=frame-ancestors *.lan 'self';
- GF_AUTH_ANONYMOUS_ENABLED=true # optional but makes embedding painless
- GF_AUTH_ANONYMOUS_ORG_ROLE=Viewer
networks:
npm_proxy:
ipv4_address: 192.168.96.13
networks:
npm_proxy:
external: true