Short answer: Authelia’s server.asset_path replaces favicon.ico, logo.png, and locale JSON. It has no stylesheet. The portal’s default Content-Security-Policy is style-src ‘self’ ‘nonce-${NONCE}’, so an off-origin CSS URL is refused, and an injected <style> cannot see the per-request nonce. The theme belongs on the reverse proxy: nginx sub_filter inserts a…
Category: Homelab
How last_over_time stops a scrape gap from firing a Grafana disk alert
Short answer: A mail whose subject starts with DatasourceNoData is not a disk measurement. The Grafana rule asked Prometheus for the latest free-space sample, the scrape had just hit scrape_timeout, and Prometheus had marked that series stale, so the instant query returned no series. Grafana sends the NoData state…
How one page filters Docker logs and Loki
Short answer: The page sends one request, a time window or a line count, and lets the backend that holds the logs apply it. Docker‘s logs API and Loki‘s query_range both answer with a list of lines. Any further filter selects from that list. It does not start another…
How Loki query responses are gzipped on the way to a log viewer
Short answer: Loki gzips query_range when frontend.compress_responses is true and the client sends Accept-Encoding: gzip. On 3.4.2 the help text for -querier.compress-http-responses says that default is true. It is not the value the process runs with. RegisterFlags then registers -frontend.support-parquet-encoding on that same bool, with default false, so gzip…
How Promtail reads the Docker API and pushes logs to Loki
Short answer: Promtail does not open Docker’s log files. It connects to the local Docker socket, lists container ids, and calls the engine logs API with follow. It splits stdout from stderr, removes Docker’s timestamp prefix, and POSTs the lines to Loki at /loki/api/v1/push. This page assumes that push…
How Promtail ships container logs to Loki across an IPsec split tunnel
Short answer: Do not open a remote Docker socket to read container stdout. Promtail on the remote host tails the local socket and pushes to Loki. If that host’s IPsec policy can reach only one virtual address, and Loki is bound to a different virtual address on the same…
How FreeRADIUS makes LDAP authentication work with StrongSwan
Short answer: StrongSwan IKEv2 road-warriors (iOS, macOS, Windows) speak EAP-MSCHAPv2. OpenLDAP can only simple-bind (PAP). Those are not the same protocol, so StrongSwan cannot authenticate an LDAP password by itself. FreeRADIUS sits in the middle: it reads the user’s ntPassword from LDAP and finishes MS-CHAP. That is the supported…
