stack.basicstack.de/apps/dozzle
CTO Agent 5797b106a6 Add health probes to Dozzle container to fix startup race condition
Fixes DEV-350. During pod startup, Dozzle takes ~11 seconds to start
accepting connections, but oauth2-proxy can receive and proxy requests
immediately. This causes "connection refused" errors when users access
the UI right after a pod restart.

Solution:
- Add startupProbe with 30s timeout (15 failures × 2s) to give Dozzle
  time to start without failing readiness
- Add readinessProbe to prevent traffic routing until Dozzle is ready
- Add livenessProbe to restart container if Dozzle becomes unhealthy

All probes use the /healthcheck endpoint on port 8080.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-19 14:59:35 +00:00
..
deployment.yaml Add health probes to Dozzle container to fix startup race condition 2026-07-19 14:59:35 +00:00
dozzle-oidc-sealed.yaml Fix Dozzle authentication with oauth2-proxy sidecar 2026-07-19 13:30:41 +00:00
ingress.yaml Fix Dozzle WebSocket/SSE streaming issues 2026-07-19 14:41:00 +00:00
namespace.yaml Add Dozzle container log viewer deployment 2026-07-19 13:25:08 +00:00
pvc.yaml Add Dozzle container log viewer deployment 2026-07-19 13:25:08 +00:00
README.md Fix Dozzle authentication with oauth2-proxy sidecar 2026-07-19 13:30:41 +00:00
service-account.yaml fix(dozzle): add nodes permission to ClusterRole for k8s mode 2026-07-19 13:51:06 +00:00
service.yaml Fix Dozzle authentication with oauth2-proxy sidecar 2026-07-19 13:30:41 +00:00

Dozzle Deployment

Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.

Components

  • Namespace: dozzle
  • Domain: dozzle.basicstack.de
  • Storage: 1Gi PVC using hcloud-volumes-encrypted storage class
  • Authentication: Pocket ID OIDC via oauth2-proxy sidecar

Architecture

Dozzle doesn't support native OIDC authentication, so we use oauth2-proxy as a sidecar container:

  1. oauth2-proxy (port 4180): Handles OIDC authentication with Pocket ID
  2. Dozzle (port 8080): Receives authenticated requests from oauth2-proxy with user headers

The oauth2-proxy authenticates users via Pocket ID OIDC and forwards authenticated requests to Dozzle with X-Forwarded-User, X-Forwarded-Email, and X-Forwarded-Preferred-Username headers. Dozzle is configured with forward-proxy authentication to trust these headers.

Files

  • namespace.yaml: Dozzle namespace
  • service-account.yaml: Service account with RBAC for accessing pod logs cluster-wide
  • pvc.yaml: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)
  • deployment.yaml: Dozzle deployment with oauth2-proxy sidecar
  • service.yaml: Kubernetes service (routes to oauth2-proxy port 4180)
  • ingress.yaml: Traefik ingress with TLS (routes to oauth2-proxy)
  • dozzle-oidc-sealed.yaml: Sealed secret with OIDC client credentials and oauth2-proxy cookie secret

Pocket ID OIDC Client

  • Client ID: 179c13f2-d251-4e1e-b1a0-c070df350c4e
  • Client Name: Dozzle
  • Callback URL: https://dozzle.basicstack.de/oauth2/callback
  • Scopes: openid profile email

Access

After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.

ArgoCD

The application is managed by ArgoCD via app-dozzle.yaml in the parent apps directory.