Skip to content

Releases: HoneyBearTech/Argus

Argus v0.3.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 01:15
v0.3.0
d306861

Upgrading

  • Grafana now runs only the plugins in the image: the Prometheus and Loki datasources and Grafana's
    built-in panels. It no longer downloads plugins from grafana.com at start-up, so the Explore
    "Drilldown" apps (metrics, logs, traces, profiles) and the Advisor app are gone. Plugins earlier
    versions downloaded into the grafana_data volume are ignored; to reclaim the space, run
    docker compose exec grafana sh -c 'rm -rf /var/lib/grafana/plugins/*'.

Added

  • Internet / ISP dashboard: the UniFi gateway's speed tests over time against the plan speeds set in UniFi,
    how long ago the last test ran, latency and connectivity drops. It needs nothing beyond unpoller. The
    gateway measures from the edge of the network, so the results aren't capped by a server's network card.
  • Optional auto-deploy for servers that run from a checkout: a systemd timer (deploy/systemd/)
    runs scripts/auto_deploy.py, which fast-forwards to main once its CI check has passed, rebuilds, restarts
    what reads a changed config, and rolls back if Grafana or Prometheus don't come back. Deploys and
    rollbacks are posted to Discord. See docs/auto-deploy.md.

Changed

  • argus-grafana keeps only the Prometheus and Loki datasource plugins (removing Grafana's other
    bundled ones), turns off Grafana's plugin preinstaller and reads plugins from a directory inside the
    image (GF_PATHS_PLUGINS), so what runs is what was signed and scanned. Adding a datasource of another
    type now means extending the image.
  • Release images are built without a build cache. The cache was written per release tag, where no later
    release could read it, and filled 1.6 GB of the repository's Actions storage per release.

Security

  • argus-agent applies Ubuntu's security updates to its base image, fixing CVE-2026-84782 (OpenSSL,
    HIGH), which Grafana Alloy v1.20.1's image still contains. The agent runs as root on every host, so
    upgrade the agents.
  • argus-grafana drops seven of Grafana's eight HIGH findings (gRPC and Tempo libraries in bundled plugins
    Argus doesn't use) by removing those plugins. Before 0.3.0, Grafana also downloaded 18 plugins from
    grafana.com at start-up into its data volume, where they took precedence over the image's own copies,
    so the datasource code that ran was neither signed by the release nor covered by the image scan. The remaining one, CVE-2026-84445 in the Prometheus
    plugin, is waiting on a Grafana release; see
    docs/dependencies.md.

Verify the images and this release: docs/verifying-releases.md

Argus v0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 00:07
v0.2.0
a0bf61d

Upgrading

  • unpoller now verifies the UniFi console's TLS certificate. If your console still uses its factory
    self-signed certificate, set UNIFI_VERIFY_SSL=false in .env before upgrading, or the Network /
    UniFi dashboard goes empty.

Added

  • Releases are signed: every image is signed keylessly with cosign (Sigstore) and carries an SBOM and SLSA
    provenance, and each GitHub Release has a source archive, the image digests, a signed SHA256SUMS and
    SLSA build provenance. Version tags are signed with the maintainer's SSH key. How to check:
    docs/verifying-releases.md.
  • Release notes come from this changelog, with repository links pointing at the release's tag.
  • CI now starts the Grafana image and checks that every dashboard, alert rule, datasource and the contact
    point loads, so an invalid alert rule fails the pull request instead of the server.
  • PromQL tests: the shipped alert rule and dashboard queries run against synthetic series with
    promtool test rules (tests/promql/), including regression tests for the false alerts
    fixed in 0.1.0.
  • Unit tests for the repo checks, with a coverage floor, and linting for Python (ruff), YAML (yamllint),
    workflows (actionlint), Dockerfiles (hadolint) and the agent config (alloy fmt), all in CI.
  • A weekly vulnerability scan of the five images (Trivy), reported to code scanning.
  • Project documentation: governance, support, the
    code of conduct, and in docs/ a quick start, architecture,
    interfaces, security requirements, assurance case, dependency policy, roadmap and upgrade guide.
  • Contributions need a Developer Certificate of Origin sign-off, checked on every pull request.
  • An MIT license, a security policy for reporting vulnerabilities, and a
    contributing guide.

Changed

  • Grafana 13.2.2 → 13.2.3 and Prometheus v3.14.0 → v3.15.0 in the argus-grafana and argus-prometheus
    images.
  • Every upstream base image is pinned by digest as well as version tag, so a re-pushed upstream tag can't
    change what an Argus release builds from.
  • UNIFI_VERIFY_SSL (default true) controls unpoller's certificate check, which used to be off.
  • check_dashboards.py also checks that dashboards keep Grafana's 2-space JSON format (--fix rewrites
    them).
  • The argus-blackbox image runs as an unprivileged user (65534) instead of root; Argus' HTTP and DNS
    probes don't need root.
  • agent/config.alloy is formatted with alloy fmt (whitespace only).

Security

  • No vulnerabilities in Argus itself. The new weekly image scan reports upstream Go standard library,
    golang.org/x/net, golang.org/x/crypto and gRPC vulnerabilities in blackbox_exporter v0.28.0, the
    latest upstream release; the assessment and plan are in
    docs/dependencies.md. The blackbox image now runs unprivileged,
    and unpoller now verifies the UniFi console's certificate by default.

Verify the images and this release: docs/verifying-releases.md

Argus v0.1.0

Choose a tag to compare

@HoneyBearTech HoneyBearTech released this 04 Oct 23:01
10361cb

First published release of Argus: Grafana dashboards, alert rules and a per-host agent for monitoring a homelab, shipped as Docker images for amd64 and arm64.

Images

On GHCR (ghcr.io/honeybeartech/argus-*) and Docker Hub (honeybeartech/argus-*), tagged 0.1.0, 0.1 and latest:

Image What it is
argus-grafana Grafana 13.2.2 with every dashboard, datasource and alert rule baked in
argus-prometheus Prometheus v3.14.0 with the scrape config; accepts pushes from agents
argus-blackbox blackbox_exporter v0.28.0 with the HTTP and DNS probe modules
argus-loki Loki 3.7.8, single process, 30-day retention
argus-agent Grafana Alloy with embedded node_exporter and cAdvisor; pushes host metrics, container metrics and container logs

What's included

  • 11 dashboards: Homelab Overview, DNS / Pi-hole, Host Health, Docker Containers, Logs, Network / UniFi, Reverse Proxy Traffic, NAS / Storage, Smart Home, Media Stack (including Plex), UPS / Power.
  • 19 alert rules with a Discord contact point: availability, capacity, power and hardware, network, containers, logs.
  • Push-model agent: one container per host, outbound connections only, no per-host server config.
  • Install: clone, copy .env.example, docker compose up -d — see the README.

Security

No vulnerabilities fixed in this release (first release). Note that Prometheus and Loki accept pushes without authentication; run Argus on a trusted network.