Dozzle running in k8s mode requires permission to list nodes at cluster scope. Without this permission, the pod fails with error: "nodes is forbidden: User \"system:serviceaccount:dozzle:dozzle\" cannot list resource \"nodes\" in API group \"\" at the cluster scope" This change adds the nodes resource with get, list, and watch verbs to the ClusterRole, allowing Dozzle to discover all nodes in the cluster when running in k8s/swarm mode. Resolves: DEV-349 Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| deployment.yaml | ||
| dozzle-oidc-sealed.yaml | ||
| ingress.yaml | ||
| namespace.yaml | ||
| pvc.yaml | ||
| README.md | ||
| service-account.yaml | ||
| service.yaml | ||
Dozzle Deployment
Dozzle is a real-time log viewer for Docker containers running in the Kubernetes cluster.
Components
- Namespace:
dozzle - Domain:
dozzle.basicstack.de - Storage: 1Gi PVC using
hcloud-volumes-encryptedstorage class - Authentication: Pocket ID OIDC via oauth2-proxy sidecar
Architecture
Dozzle doesn't support native OIDC authentication, so we use oauth2-proxy as a sidecar container:
- oauth2-proxy (port 4180): Handles OIDC authentication with Pocket ID
- Dozzle (port 8080): Receives authenticated requests from oauth2-proxy with user headers
The oauth2-proxy authenticates users via Pocket ID OIDC and forwards authenticated requests to Dozzle with X-Forwarded-User, X-Forwarded-Email, and X-Forwarded-Preferred-Username headers. Dozzle is configured with forward-proxy authentication to trust these headers.
Files
namespace.yaml: Dozzle namespaceservice-account.yaml: Service account with RBAC for accessing pod logs cluster-widepvc.yaml: Persistent volume claim for Dozzle settings (1Gi, ReadWriteOnce with Recreate strategy)deployment.yaml: Dozzle deployment with oauth2-proxy sidecarservice.yaml: Kubernetes service (routes to oauth2-proxy port 4180)ingress.yaml: Traefik ingress with TLS (routes to oauth2-proxy)dozzle-oidc-sealed.yaml: Sealed secret with OIDC client credentials and oauth2-proxy cookie secret
Pocket ID OIDC Client
- Client ID:
179c13f2-d251-4e1e-b1a0-c070df350c4e - Client Name: Dozzle
- Callback URL:
https://dozzle.basicstack.de/oauth2/callback - Scopes:
openid profile email
Access
After deployment, access Dozzle at https://dozzle.basicstack.de and authenticate with Pocket ID credentials.
ArgoCD
The application is managed by ArgoCD via app-dozzle.yaml in the parent apps directory.