Skip to content

Argus v0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 00:07
· 5 commits to main since this release
v0.2.0
a0bf61d

Upgrading

  • unpoller now verifies the UniFi console's TLS certificate. If your console still uses its factory
    self-signed certificate, set UNIFI_VERIFY_SSL=false in .env before upgrading, or the Network /
    UniFi dashboard goes empty.

Added

  • Releases are signed: every image is signed keylessly with cosign (Sigstore) and carries an SBOM and SLSA
    provenance, and each GitHub Release has a source archive, the image digests, a signed SHA256SUMS and
    SLSA build provenance. Version tags are signed with the maintainer's SSH key. How to check:
    docs/verifying-releases.md.
  • Release notes come from this changelog, with repository links pointing at the release's tag.
  • CI now starts the Grafana image and checks that every dashboard, alert rule, datasource and the contact
    point loads, so an invalid alert rule fails the pull request instead of the server.
  • PromQL tests: the shipped alert rule and dashboard queries run against synthetic series with
    promtool test rules (tests/promql/), including regression tests for the false alerts
    fixed in 0.1.0.
  • Unit tests for the repo checks, with a coverage floor, and linting for Python (ruff), YAML (yamllint),
    workflows (actionlint), Dockerfiles (hadolint) and the agent config (alloy fmt), all in CI.
  • A weekly vulnerability scan of the five images (Trivy), reported to code scanning.
  • Project documentation: governance, support, the
    code of conduct, and in docs/ a quick start, architecture,
    interfaces, security requirements, assurance case, dependency policy, roadmap and upgrade guide.
  • Contributions need a Developer Certificate of Origin sign-off, checked on every pull request.
  • An MIT license, a security policy for reporting vulnerabilities, and a
    contributing guide.

Changed

  • Grafana 13.2.2 → 13.2.3 and Prometheus v3.14.0 → v3.15.0 in the argus-grafana and argus-prometheus
    images.
  • Every upstream base image is pinned by digest as well as version tag, so a re-pushed upstream tag can't
    change what an Argus release builds from.
  • UNIFI_VERIFY_SSL (default true) controls unpoller's certificate check, which used to be off.
  • check_dashboards.py also checks that dashboards keep Grafana's 2-space JSON format (--fix rewrites
    them).
  • The argus-blackbox image runs as an unprivileged user (65534) instead of root; Argus' HTTP and DNS
    probes don't need root.
  • agent/config.alloy is formatted with alloy fmt (whitespace only).

Security

  • No vulnerabilities in Argus itself. The new weekly image scan reports upstream Go standard library,
    golang.org/x/net, golang.org/x/crypto and gRPC vulnerabilities in blackbox_exporter v0.28.0, the
    latest upstream release; the assessment and plan are in
    docs/dependencies.md. The blackbox image now runs unprivileged,
    and unpoller now verifies the UniFi console's certificate by default.

Verify the images and this release: docs/verifying-releases.md