stack.basicstack.de/apps/dozzle
CTO Agent 8c66f6c955 Add metrics.k8s.io permissions to Dozzle ClusterRole
Dozzle pod was crashing with:
  pods.metrics.k8s.io is forbidden: User "system:serviceaccount:dozzle:dozzle"
  cannot list resource "pods" in API group "metrics.k8s.io" at the cluster scope

Added permission for the metrics.k8s.io API group to allow Dozzle to collect
pod metrics for its monitoring dashboard.

Fixes: DEV-372

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-25 11:34:26 +00:00
..
deployment.yaml Fix Dozzle websocket timeouts by increasing oauth2-proxy upstream timeout 2026-07-25 11:14:50 +00:00
dozzle-oidc-sealed.yaml Fix Dozzle authentication with oauth2-proxy sidecar 2026-07-19 13:30:41 +00:00
ingress.yaml apps/dozzle/ingress.yaml aktualisiert 2026-07-25 11:06:17 +00:00
namespace.yaml Add Dozzle container log viewer deployment 2026-07-19 13:25:08 +00:00
pvc.yaml Add Dozzle container log viewer deployment 2026-07-19 13:25:08 +00:00
README.md Fix Dozzle authentication with oauth2-proxy sidecar 2026-07-19 13:30:41 +00:00
service-account.yaml Add metrics.k8s.io permissions to Dozzle ClusterRole 2026-07-25 11:34:26 +00:00
service.yaml Fix Dozzle authentication with oauth2-proxy sidecar 2026-07-19 13:30:41 +00:00

Dozzle Deployment

Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.

Components

  • Namespace: dozzle
  • Domain: dozzle.basicstack.de
  • Storage: 1Gi PVC using hcloud-volumes-encrypted storage class
  • Authentication: Pocket ID OIDC via oauth2-proxy sidecar

Architecture

Dozzle doesn't support native OIDC authentication, so we use oauth2-proxy as a sidecar container:

  1. oauth2-proxy (port 4180): Handles OIDC authentication with Pocket ID
  2. Dozzle (port 8080): Receives authenticated requests from oauth2-proxy with user headers

The oauth2-proxy authenticates users via Pocket ID OIDC and forwards authenticated requests to Dozzle with X-Forwarded-User, X-Forwarded-Email, and X-Forwarded-Preferred-Username headers. Dozzle is configured with forward-proxy authentication to trust these headers.

Files

  • namespace.yaml: Dozzle namespace
  • service-account.yaml: Service account with RBAC for accessing pod logs cluster-wide
  • pvc.yaml: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)
  • deployment.yaml: Dozzle deployment with oauth2-proxy sidecar
  • service.yaml: Kubernetes service (routes to oauth2-proxy port 4180)
  • ingress.yaml: Traefik ingress with TLS (routes to oauth2-proxy)
  • dozzle-oidc-sealed.yaml: Sealed secret with OIDC client credentials and oauth2-proxy cookie secret

Pocket ID OIDC Client

  • Client ID: 179c13f2-d251-4e1e-b1a0-c070df350c4e
  • Client Name: Dozzle
  • Callback URL: https://dozzle.basicstack.de/oauth2/callback
  • Scopes: openid profile email

Access

After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.

ArgoCD

The application is managed by ArgoCD via app-dozzle.yaml in the parent apps directory.