chore(monitoring): bump Grafana to 11.6.15, victorialogs datasource and alerta - #3011
Conversation
…nd alerta Refreshes the monitoring image anchors onto current upstream to clear the published advisories carried by the stale pins. - grafana image: base grafana/grafana 11.4.0 -> 11.6.15 (latest 11.x). The rebuild clears the Go-dependency advisories in the grafana binary (x/crypto, moby/spdystream, jackc/pgx/v5, russellhaering/goxmldsig, buger/jsonparser, golang-jwt/jwt/v4, getkin/kin-openapi). It stays on the 11.x line rather than 12.x to keep the bundled panel plugins compatible (grafana-worldmap-panel is deprecated upstream) and avoid a dashboard-schema migration. - victorialogs-datasource plugin: v0.14.1 -> v0.28.0 (grafanaDependency >=10.4.0, so it loads on 11.6.15). - alerta-web: 9.0.4 -> 9.1.0, clearing the python cryptography advisory. - images/grafana.tag: re-pinned to the rebuilt multi-arch digest. Assisted-By: Claude <[email protected]> Signed-off-by: Aleksei Sviridkin <[email protected]>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThree version bumps in the ChangesMonitoring Image Version Bumps
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request performs a security-focused update of the monitoring stack components. By refreshing the base images and plugin versions, it addresses several critical vulnerabilities identified in the previous dependencies while ensuring continued stability and compatibility with existing dashboard configurations. Highlights
New Features🧠 You can now enable Memory (public preview) to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on Gemini (@gemini-code-assist) comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request updates the Grafana base image to version 11.6.15, bumps the VictoriaLogs datasource version to v0.28.0, and updates the Alerta web image to version 9.1.0. The review feedback highlights that the Alerta container is missing a securityContext configuration, which should be added to ensure the container runs securely in accordance with the repository style guide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| containers: | ||
| - name: alerta | ||
| image: "alerta/alerta-web:9.0.4" | ||
| image: "alerta/alerta-web:9.1.0" |
There was a problem hiding this comment.
The alerta container is missing a securityContext. According to the repository style guide, we should ensure containers have a securityContext defined to run securely (e.g., preventing privilege escalation, dropping capabilities, and running as non-root).
image: "alerta/alerta-web:9.1.0"
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
runAsNonRoot: true
seccompProfile:
type: RuntimeDefaultReferences
- Ensure containers have a securityContext defined to run securely and avoid running as root without an explicit reason. (link)
myasnikovdaniil
left a comment
There was a problem hiding this comment.
LGTM — approving. Verified all three bumps against published upstream and ran the artifacts on a dev cluster.
Verified
- grafana
11.6.15: pinned digestsha256:e96e9556…resolves to a real multi-arch (amd64+arm64) image; booting it reportsVersion 11.6.15 (branch: release-11.6.15). - victorialogs-datasource
v0.28.0:plugin.jsondeclaresid=victoriametrics-logs-datasource,type=datasource,grafanaDependency >=10.4.0→ loads cleanly on 11.6.15 ("Starting VL datasource"→"Plugin registered"). The datasourcetypein provisioning and theallow_loading_unsigned_pluginsentry are unchanged, so no provisioning migration is needed. No breaking provisioning/type/id changes between v0.14.1→v0.28.0 (the id move happened at v0.13.0, before the old pin). - alerta-web
9.1.0: image present and functional; the env/config keys this chart sets (ADMIN_*,DATABASE_URL,SIGNUP_ENABLED,AUTH_REQUIRED,PLUGINS,TELEGRAM_*,SLACK_*) are unchanged in 9.1.0. - No stale
11.4.0/v0.14.1/9.0.4references remain anywhere in the repo;helm unittestpasses 4/4.
One correction to the description (non-blocking): the rationale "stays on 11.x for worldmap-panel compatibility" doesn't hold. On a real boot, Grafana 11.6.15 refuses to load both grafana-worldmap-panel and natel-discrete-panel with "angular plugins are not supported" — and the current main 11.4.0 image does exactly the same (Angular has been off by default since Grafana 11.0). So worldmap is already non-functional regardless of this bump; this PR is not a regression, but the "keep worldmap working" justification isn't accurate. Worth a follow-up to migrate those two Angular panels (e.g. worldmap → geomap) before any 12.x bump, where Angular is removed entirely.
Nit: the three grafana-cli plugins install panels are unpinned, so the rebuild pulled marcusolsson-dynamictext-panel 6.2.3 (declares grafanaDependency >=12.3.0). It still registers on 11.6.15, but consider pinning these the way VLOGS_VERSION is pinned, for reproducible rebuilds. Pre-existing, optional.
What this PR does
Refreshes the
system/monitoringimage anchors onto current upstream to clear the published advisories (8 CVEs, 1 critical) carried by the stale pins.grafana/grafana11.4.0→11.6.15(latest 11.x). The rebuild clears the Go-dependency advisories in the grafana binary (x/crypto,moby/spdystream,jackc/pgx/v5,russellhaering/goxmldsig,buger/jsonparser,golang-jwt/jwt/v4,getkin/kin-openapi). It stays on the 11.x line rather than 12.x to keep the bundled panel plugins compatible (grafana-worldmap-panelis deprecated upstream) and avoid a dashboard-schema migration.v0.14.1→v0.28.0(grafanaDependency >=10.4.0, so it loads on 11.6.15).9.0.4→9.1.0, clearing the pythoncryptographyadvisory.images/grafana.tag: re-pinned to the rebuilt multi-arch digest (linux/amd64+linux/arm64).The built grafana image was verified in place: grafana
11.6.15, all four plugins present (natel-discrete-panel,grafana-worldmap-panel,marcusolsson-dynamictext-panel,victoriametrics-logs-datasource), vlogs0.28.0. helm-unittest passes (4/4).Closes #2892
Release note
Summary by CodeRabbit