Add Dozzle container log viewer deployment

Deploy Dozzle (https://dozzle.dev/) for real-time container log viewing in the k8s cluster.

Configuration:
- Namespace: dozzle
- Domain: dozzle.basicstack.de
- Storage: 1Gi PVC with hcloud-volumes-encrypted storage class
- Authentication: Pocket ID OIDC integration
- RBAC: Cluster-wide pod log access via service account
- Strategy: Recreate with ReadWriteOnce PVC for persistent settings

Created Pocket ID OIDC client:
- Client ID: 179c13f2-d251-4e1e-b1a0-c070df350c4e
- Callback URL: https://dozzle.basicstack.de/oauth/callback

ArgoCD application configured with automated sync and self-heal.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
CTO Agent 2026-07-19 13:25:01 +00:00
parent 663c1704ac
commit d78f89fb99
9 changed files with 225 additions and 0 deletions

20
apps/app-dozzle.yaml Normal file
View file

@ -0,0 +1,20 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: dozzle
namespace: argocd
spec:
project: default
source:
repoURL: git@forgejo.forgejo.svc.cluster.local:basicstack/stack.basicstack.de.git
targetRevision: main
path: apps/dozzle
destination:
server: https://kubernetes.default.svc
namespace: dozzle
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true

35
apps/dozzle/README.md Normal file
View file

@ -0,0 +1,35 @@
# Dozzle Deployment
Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.
## Components
- **Namespace**: `dozzle`
- **Domain**: `dozzle.basicstack.de`
- **Storage**: 1Gi PVC using `hcloud-volumes-encrypted` storage class
- **Authentication**: Pocket ID OIDC integration
## Files
- `namespace.yaml`: Dozzle namespace
- `service-account.yaml`: Service account with RBAC for accessing pod logs cluster-wide
- `pvc.yaml`: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)
- `deployment.yaml`: Dozzle deployment with OIDC authentication
- `service.yaml`: Kubernetes service
- `ingress.yaml`: Traefik ingress with TLS
- `dozzle-oidc-sealed.yaml`: Sealed secret with OIDC credentials
## Pocket ID OIDC Client
- **Client ID**: `179c13f2-d251-4e1e-b1a0-c070df350c4e`
- **Client Name**: Dozzle
- **Callback URL**: `https://dozzle.basicstack.de/oauth/callback`
- **Scopes**: `openid profile email`
## Access
After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.
## ArgoCD
The application is managed by ArgoCD via `app-dozzle.yaml` in the parent apps directory.

View file

@ -0,0 +1,56 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: dozzle
namespace: dozzle
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app: dozzle
template:
metadata:
labels:
app: dozzle
spec:
serviceAccountName: dozzle
containers:
- name: dozzle
image: amir20/dozzle:latest
ports:
- containerPort: 8080
name: http
protocol: TCP
env:
- name: DOZZLE_LEVEL
value: "info"
- name: DOZZLE_AUTH_PROVIDER
value: "oidc"
- name: DOZZLE_AUTH_OIDC_PROVIDER_URL
value: "https://auth.basicstack.de"
- name: DOZZLE_AUTH_OIDC_CLIENT_ID
valueFrom:
secretKeyRef:
name: dozzle-oidc
key: client-id
- name: DOZZLE_AUTH_OIDC_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: dozzle-oidc
key: client-secret
volumeMounts:
- name: dozzle-data
mountPath: /data
resources:
limits:
cpu: 500m
memory: 512Mi
requests:
cpu: 100m
memory: 128Mi
volumes:
- name: dozzle-data
persistentVolumeClaim:
claimName: dozzle-data

View file

@ -0,0 +1,19 @@
---
apiVersion: bitnami.com/v1alpha1
kind: SealedSecret
metadata:
creationTimestamp: null
name: dozzle-oidc
namespace: dozzle
spec:
encryptedData:
client-id: AgAijJ3Jxjath5x5mqYJ8YJYoDm0qEXRPvkShD53wRepXPkIInF/X+DaBfI8SEaqasfLI2j0SGLOB0xFR6j9CbiqSJ5Oy+AgI9pVB9eKLZEgrd0WywhYPW24SOflLxgsBOiQkhx6xy+S3dg7qj9q/CqPajnNQYS/FnJsV4YOzlZekcLnizhqnK2gPykAHMoKQZLecKSScUvMzDwwS21gEuhJK+8onR63i7q+EQWbZMSH/60yAvOAJDECM9ZxAwWziCkGZAhv+Ir+W+D6Hmls6uy53uARtUktVfZM9JDBcqM9M8WltXcQKOh9lV00V3Tu6HBF+3IP1gRMzQyDnli3zG6Zdnq41+wVv4k9nh6obZBeMbx/4aib2w0uwnCBFUXI6QaK3Uy309ZUF/tu6TshQExXTAHLRafOWTKmFlrutDF3gcLZqGhVrFzsant/IRmx3xiIOYphtJyAQA8KrvNJGLXSHOpDmkE96IJPYdAPypBAb9qKEFnDe05btem1ZqyPwjm27HDxmQHsz27Bnhd3o3a7I+cO7mM6J4yJex4zRiN/DEZfmxqfnGI2AwByn+xdxlCdxqjfAVn5NGo24KPLmayxNxSDeF/2tLl8uXaCPn0Q2qALgsMvbTmujLdU9PXsHqM6D5W9OOu1aG2MocIg/uMRXld9PjHG1mpw/81G1B/qVsY5BIlessEksoIARRb7DmVEmf18KjONnQc47VuQWmtjPgPtYdAeekUxxPwnMbtZVA/xYEM=
client-secret: AgBjUlnxkPi0KVwb/lM/C+F72+aU6TTGWk/t3hpYkCApG7lFuFukshwIi2WWf09UMa5HwHLDuF+a4pf88+JYgecE0tU3oAcDHHiL2xN97bjebustcLAM0JqORPW10yMJ0xqLg70SFyp/rR7AdJAIVETvTB/dxheaP7gtbR1m669FrP3MiAIcV2U2b3HUc1iw0tkpNv+lQD33b5pStSlZDdc8eg2xmfiLgsCTzVla3lysAtGwXORsaP9L1HOhCy4GDc3YfeAdbIsNbFy2q/ug6vlytM6rHZgwt9Pmln7CTQGuLkDPPN3qG79TUIUgQ4nK+CxVXZYq044b+2G+mihdEfNe6GwmQus/SsFqhv5+nQcxWJKZwl3VSf3zhWBLRSbnYSvTRnGyqOGnc5isffxNnXWuJ0UUBiV8wcy9l9j2La4isB+GTEIlUZTPxyCwCx3v43ugb0BzhEPpQ5kB/FR0kdQgBcYitxE+sonwe7CUcv+wDtm1JtDwPyTJLKY2JSFGafsJtoTf8VFIyXdXe4I54gRA5c51TW+86spKqCy01UGhOR9wbo/pzf/esG9SHaOZNDPWeXTZneLdeYRf+RVj+eGRusRaGgByKgIDR9UHiJQTPvJC35YB/J7glJN0+kkO2UVrlYeD+o6ukWttfE2oW2aPxHXrMs68iUsgyLg/Lpc0MwzjJqGnBXYHhbbEcg9Oa6p/OxvQhOpzXq0GtIhd70iXsmlrRMCp8YlW+Lq/kExWQA==
template:
metadata:
creationTimestamp: null
name: dozzle-oidc
namespace: dozzle
annotations:
argocd.argoproj.io/compare-options: IgnoreExtraneous
type: Opaque

26
apps/dozzle/ingress.yaml Normal file
View file

@ -0,0 +1,26 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: dozzle
namespace: dozzle
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
traefik.ingress.kubernetes.io/router.entrypoints: web,websecure
traefik.ingress.kubernetes.io/preserve-host: "true"
spec:
ingressClassName: traefik
rules:
- host: dozzle.basicstack.de
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: dozzle
port:
number: 8080
tls:
- hosts:
- dozzle.basicstack.de
secretName: dozzle-tls

View file

@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: dozzle

12
apps/dozzle/pvc.yaml Normal file
View file

@ -0,0 +1,12 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: dozzle-data
namespace: dozzle
spec:
accessModes:
- ReadWriteOnce
storageClassName: hcloud-volumes-encrypted
resources:
requests:
storage: 1Gi

View file

@ -0,0 +1,40 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: dozzle
namespace: dozzle
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: dozzle
rules:
- apiGroups:
- ""
resources:
- pods
- pods/log
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: dozzle
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: dozzle
subjects:
- kind: ServiceAccount
name: dozzle
namespace: dozzle

13
apps/dozzle/service.yaml Normal file
View file

@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: dozzle
namespace: dozzle
spec:
selector:
app: dozzle
ports:
- name: http
port: 8080
targetPort: 8080
protocol: TCP