Repository navigation
Releases: HoneyBearTech/Argus
Releases · HoneyBearTech/Argus
Release list
Argus v0.3.0
Upgrading
- Grafana now runs only the plugins in the image: the Prometheus and Loki datasources and Grafana's
built-in panels. It no longer downloads plugins from grafana.com at start-up, so the Explore
"Drilldown" apps (metrics, logs, traces, profiles) and the Advisor app are gone. Plugins earlier
versions downloaded into thegrafana_datavolume are ignored; to reclaim the space, run
docker compose exec grafana sh -c 'rm -rf /var/lib/grafana/plugins/*'.
Added
- Internet / ISP dashboard: the UniFi gateway's speed tests over time against the plan speeds set in UniFi,
how long ago the last test ran, latency and connectivity drops. It needs nothing beyond unpoller. The
gateway measures from the edge of the network, so the results aren't capped by a server's network card. - Optional auto-deploy for servers that run from a checkout: a systemd timer (deploy/systemd/)
runsscripts/auto_deploy.py, which fast-forwards tomainonce its CI check has passed, rebuilds, restarts
what reads a changed config, and rolls back if Grafana or Prometheus don't come back. Deploys and
rollbacks are posted to Discord. See docs/auto-deploy.md.
Changed
argus-grafanakeeps only the Prometheus and Loki datasource plugins (removing Grafana's other
bundled ones), turns off Grafana's plugin preinstaller and reads plugins from a directory inside the
image (GF_PATHS_PLUGINS), so what runs is what was signed and scanned. Adding a datasource of another
type now means extending the image.- Release images are built without a build cache. The cache was written per release tag, where no later
release could read it, and filled 1.6 GB of the repository's Actions storage per release.
Security
argus-agentapplies Ubuntu's security updates to its base image, fixing CVE-2026-84782 (OpenSSL,
HIGH), which Grafana Alloy v1.20.1's image still contains. The agent runs as root on every host, so
upgrade the agents.argus-grafanadrops seven of Grafana's eight HIGH findings (gRPC and Tempo libraries in bundled plugins
Argus doesn't use) by removing those plugins. Before 0.3.0, Grafana also downloaded 18 plugins from
grafana.com at start-up into its data volume, where they took precedence over the image's own copies,
so the datasource code that ran was neither signed by the release nor covered by the image scan. The remaining one, CVE-2026-84445 in the Prometheus
plugin, is waiting on a Grafana release; see
docs/dependencies.md.
Verify the images and this release: docs/verifying-releases.md
Argus v0.2.0
Upgrading
- unpoller now verifies the UniFi console's TLS certificate. If your console still uses its factory
self-signed certificate, setUNIFI_VERIFY_SSL=falsein.envbefore upgrading, or the Network /
UniFi dashboard goes empty.
Added
- Releases are signed: every image is signed keylessly with cosign (Sigstore) and carries an SBOM and SLSA
provenance, and each GitHub Release has a source archive, the image digests, a signedSHA256SUMSand
SLSA build provenance. Version tags are signed with the maintainer's SSH key. How to check:
docs/verifying-releases.md. - Release notes come from this changelog, with repository links pointing at the release's tag.
- CI now starts the Grafana image and checks that every dashboard, alert rule, datasource and the contact
point loads, so an invalid alert rule fails the pull request instead of the server. - PromQL tests: the shipped alert rule and dashboard queries run against synthetic series with
promtool test rules(tests/promql/), including regression tests for the false alerts
fixed in 0.1.0. - Unit tests for the repo checks, with a coverage floor, and linting for Python (ruff), YAML (yamllint),
workflows (actionlint), Dockerfiles (hadolint) and the agent config (alloy fmt), all in CI. - A weekly vulnerability scan of the five images (Trivy), reported to code scanning.
- Project documentation: governance, support, the
code of conduct, and in docs/ a quick start, architecture,
interfaces, security requirements, assurance case, dependency policy, roadmap and upgrade guide. - Contributions need a Developer Certificate of Origin sign-off, checked on every pull request.
- An MIT license, a security policy for reporting vulnerabilities, and a
contributing guide.
Changed
- Grafana 13.2.2 → 13.2.3 and Prometheus v3.14.0 → v3.15.0 in the
argus-grafanaandargus-prometheus
images. - Every upstream base image is pinned by digest as well as version tag, so a re-pushed upstream tag can't
change what an Argus release builds from. UNIFI_VERIFY_SSL(defaulttrue) controls unpoller's certificate check, which used to be off.check_dashboards.pyalso checks that dashboards keep Grafana's 2-space JSON format (--fixrewrites
them).- The
argus-blackboximage runs as an unprivileged user (65534) instead of root; Argus' HTTP and DNS
probes don't need root. agent/config.alloyis formatted withalloy fmt(whitespace only).
Security
- No vulnerabilities in Argus itself. The new weekly image scan reports upstream Go standard library,
golang.org/x/net,golang.org/x/cryptoand gRPC vulnerabilities in blackbox_exporter v0.28.0, the
latest upstream release; the assessment and plan are in
docs/dependencies.md. The blackbox image now runs unprivileged,
and unpoller now verifies the UniFi console's certificate by default.
Verify the images and this release: docs/verifying-releases.md
Argus v0.1.0
First published release of Argus: Grafana dashboards, alert rules and a per-host agent for monitoring a homelab, shipped as Docker images for amd64 and arm64.
Images
On GHCR (ghcr.io/honeybeartech/argus-*) and Docker Hub (honeybeartech/argus-*), tagged 0.1.0, 0.1 and latest:
| Image | What it is |
|---|---|
argus-grafana |
Grafana 13.2.2 with every dashboard, datasource and alert rule baked in |
argus-prometheus |
Prometheus v3.14.0 with the scrape config; accepts pushes from agents |
argus-blackbox |
blackbox_exporter v0.28.0 with the HTTP and DNS probe modules |
argus-loki |
Loki 3.7.8, single process, 30-day retention |
argus-agent |
Grafana Alloy with embedded node_exporter and cAdvisor; pushes host metrics, container metrics and container logs |
What's included
- 11 dashboards: Homelab Overview, DNS / Pi-hole, Host Health, Docker Containers, Logs, Network / UniFi, Reverse Proxy Traffic, NAS / Storage, Smart Home, Media Stack (including Plex), UPS / Power.
- 19 alert rules with a Discord contact point: availability, capacity, power and hardware, network, containers, logs.
- Push-model agent: one container per host, outbound connections only, no per-host server config.
- Install: clone, copy
.env.example,docker compose up -d— see the README.
Security
No vulnerabilities fixed in this release (first release). Note that Prometheus and Loki accept pushes without authentication; run Argus on a trusted network.