From 7beb791e44a9a8238b0e8cdee8844f5cf54ead8c Mon Sep 17 00:00:00 2001 From: Cedric Date: Mon, 28 Sep 2026 17:29:49 +0200 Subject: [PATCH] Pin image versions - docker-compose: victoria-logs v1.52.0 and docker-socket-proxy v0.5.0, the versions running on sandbox. - Dockerfile: golang 1.27.1-alpine3.24 and alpine 3.24.2 (Go 1.23 and Alpine 3.20 no longer receive security fixes). - README: pinned versions and how to update them. Co-Authored-By: Claude Opus 5.5 --- Dockerfile | 6 ++++-- README.md | 23 +++++++++++++++++++++++ docker-compose.yml | 6 +++--- 3 files changed, 30 insertions(+), 5 deletions(-) diff --git a/Dockerfile b/Dockerfile index c6d3b21..3bcf99e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,7 @@ +# Image versions are pinned: update them on purpose (see "Updating" in the README). + # ---- Build ---- -FROM golang:1.23-alpine AS build +FROM golang:1.27.1-alpine3.24 AS build WORKDIR /src COPY go.mod ./ COPY *.go ./ @@ -7,7 +9,7 @@ COPY web ./web RUN CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o /out/logstream . # ---- Final image (~15 MB) ---- -FROM alpine:3.20 +FROM alpine:3.24.2 RUN adduser -D -H -u 10001 logstream \ && mkdir /data && chown logstream /data COPY --from=build /out/logstream /usr/local/bin/logstream diff --git a/README.md b/README.md index 98d7224..afeecdd 100644 --- a/README.md +++ b/README.md @@ -187,6 +187,29 @@ are only known by your router or a local DNS (Pi-hole, AdGuard, Unbound…), set ``` - Running outside Docker (Go 1.22+): `VLOGS_URL=http://localhost:9428 DATA_DIR=./data SYSLOG_ADDR=:5514 go run .` +## Updating + +Every image version is pinned, so a `docker compose pull` or a rebuild never changes a +component behind your back: + +| Where | Image | Version | +|---|---|---| +| `docker-compose.yml` | `victoriametrics/victoria-logs` | `v1.52.0` | +| `docker-compose.yml` | `tecnativa/docker-socket-proxy` | `v0.5.0` | +| `Dockerfile` (build) | `golang` | `1.27.1-alpine3.24` | +| `Dockerfile` (runtime) | `alpine` | `3.24.2` | + +To update one of them: + +1. Check the release notes: [VictoriaLogs](https://docs.victoriametrics.com/victorialogs/changelog/), + [docker-socket-proxy](https://github.com/Tecnativa/docker-socket-proxy/releases), + [Go](https://go.dev/doc/devel/release), [Alpine](https://alpinelinux.org/releases/). + VictoriaLogs keeps its storage format across minor versions; read the changelog before a + major version change. +2. Change the version in the file above, then run `docker compose up -d --build`. +3. Check the bottom bar (received / stored / dropped) and **Settings > Sources**. To go back, + restore the previous version and run the same command. + ## Code layout | File | Contents | diff --git a/docker-compose.yml b/docker-compose.yml index 4cd4d19..02f4097 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -28,8 +28,8 @@ services: logstream.exclude: "true" # never collect Logstream's own logs victorialogs: - # Pin a specific version in production (see hub.docker.com/r/victoriametrics/victoria-logs/tags) - image: victoriametrics/victoria-logs:latest + # Pinned version: see "Updating" in the README before changing it + image: victoriametrics/victoria-logs:v1.52.0 container_name: logstream-victorialogs restart: unless-stopped command: @@ -47,7 +47,7 @@ services: # Read-only gateway to the Docker API: Logstream can only list containers, # read their logs, receive events and engine info. Anything else (start, # stop, exec, images, volumes…) is refused. - image: tecnativa/docker-socket-proxy:latest + image: tecnativa/docker-socket-proxy:v0.5.0 container_name: logstream-docker-proxy restart: unless-stopped environment: