Skip to content

Argus v0.3.0

Latest

Choose a tag to compare

@github-actions github-actions released this 06 Oct 01:15
· 1 commit to main since this release
v0.3.0
d306861

Upgrading

  • Grafana now runs only the plugins in the image: the Prometheus and Loki datasources and Grafana's
    built-in panels. It no longer downloads plugins from grafana.com at start-up, so the Explore
    "Drilldown" apps (metrics, logs, traces, profiles) and the Advisor app are gone. Plugins earlier
    versions downloaded into the grafana_data volume are ignored; to reclaim the space, run
    docker compose exec grafana sh -c 'rm -rf /var/lib/grafana/plugins/*'.

Added

  • Internet / ISP dashboard: the UniFi gateway's speed tests over time against the plan speeds set in UniFi,
    how long ago the last test ran, latency and connectivity drops. It needs nothing beyond unpoller. The
    gateway measures from the edge of the network, so the results aren't capped by a server's network card.
  • Optional auto-deploy for servers that run from a checkout: a systemd timer (deploy/systemd/)
    runs scripts/auto_deploy.py, which fast-forwards to main once its CI check has passed, rebuilds, restarts
    what reads a changed config, and rolls back if Grafana or Prometheus don't come back. Deploys and
    rollbacks are posted to Discord. See docs/auto-deploy.md.

Changed

  • argus-grafana keeps only the Prometheus and Loki datasource plugins (removing Grafana's other
    bundled ones), turns off Grafana's plugin preinstaller and reads plugins from a directory inside the
    image (GF_PATHS_PLUGINS), so what runs is what was signed and scanned. Adding a datasource of another
    type now means extending the image.
  • Release images are built without a build cache. The cache was written per release tag, where no later
    release could read it, and filled 1.6 GB of the repository's Actions storage per release.

Security

  • argus-agent applies Ubuntu's security updates to its base image, fixing CVE-2026-84782 (OpenSSL,
    HIGH), which Grafana Alloy v1.20.1's image still contains. The agent runs as root on every host, so
    upgrade the agents.
  • argus-grafana drops seven of Grafana's eight HIGH findings (gRPC and Tempo libraries in bundled plugins
    Argus doesn't use) by removing those plugins. Before 0.3.0, Grafana also downloaded 18 plugins from
    grafana.com at start-up into its data volume, where they took precedence over the image's own copies,
    so the datasource code that ran was neither signed by the release nor covered by the image scan. The remaining one, CVE-2026-84445 in the Prometheus
    plugin, is waiting on a Grafana release; see
    docs/dependencies.md.

Verify the images and this release: docs/verifying-releases.md