Skip to content

chore(monitoring): bump Grafana to 11.6.15, victorialogs datasource and alerta - #3011

Merged
Aleksei Sviridkin (lexfrei) merged 1 commit into
mainfrom
chore/bump-monitoring
Jun 23, 2026
Merged

Aleksei Sviridkin (lexfrei) merged 1 commit into
mainfrom
chore/bump-monitoring

Conversation

@lexfrei

@lexfrei Aleksei Sviridkin (lexfrei) commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does

Refreshes the system/monitoring image anchors onto current upstream to clear the published advisories (8 CVEs, 1 critical) carried by the stale pins.

  • grafana image: base grafana/grafana 11.4.0 → 11.6.15 (latest 11.x). The rebuild clears the Go-dependency advisories in the grafana binary (x/crypto, moby/spdystream, jackc/pgx/v5, russellhaering/goxmldsig, buger/jsonparser, golang-jwt/jwt/v4, getkin/kin-openapi). It stays on the 11.x line rather than 12.x to keep the bundled panel plugins compatible (grafana-worldmap-panel is deprecated upstream) and avoid a dashboard-schema migration.
  • victorialogs-datasource plugin: v0.14.1 → v0.28.0 (grafanaDependency >=10.4.0, so it loads on 11.6.15).
  • alerta-web: 9.0.4 → 9.1.0, clearing the python cryptography advisory.
  • images/grafana.tag: re-pinned to the rebuilt multi-arch digest (linux/amd64 + linux/arm64).

The built grafana image was verified in place: grafana 11.6.15, all four plugins present (natel-discrete-panel, grafana-worldmap-panel, marcusolsson-dynamictext-panel, victoriametrics-logs-datasource), vlogs 0.28.0. helm-unittest passes (4/4).

Closes #2892

Release note

chore(monitoring): bump Grafana to 11.6.15, victorialogs-datasource to v0.28.0 and alerta-web to 9.1.0

Summary by CodeRabbit

  • Chores
    • Updated Grafana monitoring dashboard base image to 11.6.15 and VictoriaLogs datasource plugin to v0.28.0
    • Upgraded Alerta monitoring and alerting tool to 9.1.0

…nd alerta

Refreshes the monitoring image anchors onto current upstream to clear the
published advisories carried by the stale pins.

- grafana image: base grafana/grafana 11.4.0 -> 11.6.15 (latest 11.x). The
  rebuild clears the Go-dependency advisories in the grafana binary (x/crypto,
  moby/spdystream, jackc/pgx/v5, russellhaering/goxmldsig, buger/jsonparser,
  golang-jwt/jwt/v4, getkin/kin-openapi). It stays on the 11.x line rather than
  12.x to keep the bundled panel plugins compatible (grafana-worldmap-panel is
  deprecated upstream) and avoid a dashboard-schema migration.
- victorialogs-datasource plugin: v0.14.1 -> v0.28.0 (grafanaDependency
  >=10.4.0, so it loads on 11.6.15).
- alerta-web: 9.0.4 -> 9.1.0, clearing the python cryptography advisory.
- images/grafana.tag: re-pinned to the rebuilt multi-arch digest.

Assisted-By: Claude <[email protected]>
Signed-off-by: Aleksei Sviridkin <[email protected]>
@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: aa977607-432e-4497-b805-ad8b1235e5c5

📥 Commits

Reviewing files that changed from the base of the PR and between 82b8c46 and 37dbc58.

📒 Files selected for processing (3)
  • packages/system/monitoring/images/grafana.tag
  • packages/system/monitoring/images/grafana/Dockerfile
  • packages/system/monitoring/templates/alerta/alerta.yaml

📝 Walkthrough

Walkthrough

Three version bumps in the system/monitoring package: Grafana base image updated from 11.4.0 to 11.6.15, victorialogs-datasource plugin from v0.14.1 to v0.28.0, the pinned Grafana image SHA256 digest refreshed, and the Alerta web image from 9.0.4 to 9.1.0.

Changes

Monitoring Image Version Bumps

Layer / File(s) Summary
Grafana base image and plugin version bump
packages/system/monitoring/images/grafana/Dockerfile, packages/system/monitoring/images/grafana.tag
Base image bumped from grafana/grafana:11.4.0 to grafana/grafana:11.6.15; VLOGS_VERSION build arg bumped from v0.14.1 to v0.28.0, changing the fetched victorialogs-datasource tarball URL; pinned SHA256 digest updated to match the rebuilt image.
Alerta image tag bump
packages/system/monitoring/templates/alerta/alerta.yaml
Container image tag in the alerta Deployment changed from alerta/alerta-web:9.0.4 to alerta/alerta-web:9.1.0.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐇 Hop hop, the versions climb,
Grafana leaps from old to prime,
Alerta too gets a fresh new coat,
The plugins sail on an updated boat,
SHA digests pinned with care so fine —
All bumped and blessed, the stack's in line! 🌟

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main changes: bumping Grafana to 11.6.15, victorialogs datasource, and alerta versions.
Linked Issues check ✅ Passed The PR meets issue #2892 requirements by updating monitoring stack images to clear security advisories in outdated packages.
Out of Scope Changes check ✅ Passed All changes are directly aligned with updating the monitoring stack components to address security advisories per issue #2892.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/bump-monitoring

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added size/XS This PR changes 0-9 lines, ignoring generated files area/monitoring Issues or PRs related to the monitoring stack (vlogs, vmstack, grafana, workloadmonitor) kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt labels Jun 22, 2026
@lexfrei
Aleksei Sviridkin (lexfrei) marked this pull request as ready for review June 22, 2026 23:48
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request performs a security-focused update of the monitoring stack components. By refreshing the base images and plugin versions, it addresses several critical vulnerabilities identified in the previous dependencies while ensuring continued stability and compatibility with existing dashboard configurations.

Highlights

  • Security Patching: Updated Grafana, VictoriaLogs datasource, and Alerta-web to resolve multiple CVEs and dependency vulnerabilities.
  • Grafana Upgrade: Bumped Grafana base image from 11.4.0 to 11.6.15, maintaining the 11.x line to ensure plugin compatibility.
  • Plugin and Component Updates: Upgraded VictoriaLogs datasource to v0.28.0 and Alerta-web to 9.1.0.
New Features

🧠 You can now enable Memory (public preview) to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment Gemini (@gemini-code-assist) Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on Gemini (@gemini-code-assist) comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Grafana base image to version 11.6.15, bumps the VictoriaLogs datasource version to v0.28.0, and updates the Alerta web image to version 9.1.0. The review feedback highlights that the Alerta container is missing a securityContext configuration, which should be added to ensure the container runs securely in accordance with the repository style guide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

containers:
- name: alerta
image: "alerta/alerta-web:9.0.4"
image: "alerta/alerta-web:9.1.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

The alerta container is missing a securityContext. According to the repository style guide, we should ensure containers have a securityContext defined to run securely (e.g., preventing privilege escalation, dropping capabilities, and running as non-root).

          image: "alerta/alerta-web:9.1.0"
          securityContext:
            allowPrivilegeEscalation: false
            capabilities:
              drop:
              - ALL
            runAsNonRoot: true
            seccompProfile:
              type: RuntimeDefault
References
  1. Ensure containers have a securityContext defined to run securely and avoid running as root without an explicit reason. (link)

@myasnikovdaniil myasnikovdaniil left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — approving. Verified all three bumps against published upstream and ran the artifacts on a dev cluster.

Verified

  • grafana 11.6.15: pinned digest sha256:e96e9556… resolves to a real multi-arch (amd64+arm64) image; booting it reports Version 11.6.15 (branch: release-11.6.15).
  • victorialogs-datasource v0.28.0: plugin.json declares id=victoriametrics-logs-datasource, type=datasource, grafanaDependency >=10.4.0 → loads cleanly on 11.6.15 ("Starting VL datasource" → "Plugin registered"). The datasource type in provisioning and the allow_loading_unsigned_plugins entry are unchanged, so no provisioning migration is needed. No breaking provisioning/type/id changes between v0.14.1→v0.28.0 (the id move happened at v0.13.0, before the old pin).
  • alerta-web 9.1.0: image present and functional; the env/config keys this chart sets (ADMIN_*, DATABASE_URL, SIGNUP_ENABLED, AUTH_REQUIRED, PLUGINS, TELEGRAM_*, SLACK_*) are unchanged in 9.1.0.
  • No stale 11.4.0 / v0.14.1 / 9.0.4 references remain anywhere in the repo; helm unittest passes 4/4.

One correction to the description (non-blocking): the rationale "stays on 11.x for worldmap-panel compatibility" doesn't hold. On a real boot, Grafana 11.6.15 refuses to load both grafana-worldmap-panel and natel-discrete-panel with "angular plugins are not supported" — and the current main 11.4.0 image does exactly the same (Angular has been off by default since Grafana 11.0). So worldmap is already non-functional regardless of this bump; this PR is not a regression, but the "keep worldmap working" justification isn't accurate. Worth a follow-up to migrate those two Angular panels (e.g. worldmap → geomap) before any 12.x bump, where Angular is removed entirely.

Nit: the three grafana-cli plugins install panels are unpinned, so the rebuild pulled marcusolsson-dynamictext-panel 6.2.3 (declares grafanaDependency >=12.3.0). It still registers on 11.6.15, but consider pinning these the way VLOGS_VERSION is pinned, for reproducible rebuilds. Pre-existing, optional.

@lexfrei
Aleksei Sviridkin (lexfrei) merged commit 2a5ccf1 into main Jun 23, 2026
12 checks passed
@lexfrei
Aleksei Sviridkin (lexfrei) deleted the chore/bump-monitoring branch June 23, 2026 10:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/monitoring Issues or PRs related to the monitoring stack (vlogs, vmstack, grafana, workloadmonitor) kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt size/XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(monitoring): bump system/monitoring images to current upstream release

2 participants