Repository navigation
Argus v0.2.0
Upgrading
- unpoller now verifies the UniFi console's TLS certificate. If your console still uses its factory
self-signed certificate, setUNIFI_VERIFY_SSL=falsein.envbefore upgrading, or the Network /
UniFi dashboard goes empty.
Added
- Releases are signed: every image is signed keylessly with cosign (Sigstore) and carries an SBOM and SLSA
provenance, and each GitHub Release has a source archive, the image digests, a signedSHA256SUMSand
SLSA build provenance. Version tags are signed with the maintainer's SSH key. How to check:
docs/verifying-releases.md. - Release notes come from this changelog, with repository links pointing at the release's tag.
- CI now starts the Grafana image and checks that every dashboard, alert rule, datasource and the contact
point loads, so an invalid alert rule fails the pull request instead of the server. - PromQL tests: the shipped alert rule and dashboard queries run against synthetic series with
promtool test rules(tests/promql/), including regression tests for the false alerts
fixed in 0.1.0. - Unit tests for the repo checks, with a coverage floor, and linting for Python (ruff), YAML (yamllint),
workflows (actionlint), Dockerfiles (hadolint) and the agent config (alloy fmt), all in CI. - A weekly vulnerability scan of the five images (Trivy), reported to code scanning.
- Project documentation: governance, support, the
code of conduct, and in docs/ a quick start, architecture,
interfaces, security requirements, assurance case, dependency policy, roadmap and upgrade guide. - Contributions need a Developer Certificate of Origin sign-off, checked on every pull request.
- An MIT license, a security policy for reporting vulnerabilities, and a
contributing guide.
Changed
- Grafana 13.2.2 → 13.2.3 and Prometheus v3.14.0 → v3.15.0 in the
argus-grafanaandargus-prometheus
images. - Every upstream base image is pinned by digest as well as version tag, so a re-pushed upstream tag can't
change what an Argus release builds from. UNIFI_VERIFY_SSL(defaulttrue) controls unpoller's certificate check, which used to be off.check_dashboards.pyalso checks that dashboards keep Grafana's 2-space JSON format (--fixrewrites
them).- The
argus-blackboximage runs as an unprivileged user (65534) instead of root; Argus' HTTP and DNS
probes don't need root. agent/config.alloyis formatted withalloy fmt(whitespace only).
Security
- No vulnerabilities in Argus itself. The new weekly image scan reports upstream Go standard library,
golang.org/x/net,golang.org/x/cryptoand gRPC vulnerabilities in blackbox_exporter v0.28.0, the
latest upstream release; the assessment and plan are in
docs/dependencies.md. The blackbox image now runs unprivileged,
and unpoller now verifies the UniFi console's certificate by default.
Verify the images and this release: docs/verifying-releases.md