diff --git a/OpenTelemetryPlan/05-configuration-reference.md b/OpenTelemetryPlan/05-configuration-reference.md index 41796b3590..baceb4680f 100644 --- a/OpenTelemetryPlan/05-configuration-reference.md +++ b/OpenTelemetryPlan/05-configuration-reference.md @@ -353,7 +353,7 @@ The authoritative development stack lives in the repo at `docker/telemetry/docke | `loki` | `grafana/loki:3.7.6` | `3100` | Log storage for log↔trace correlation | | `prometheus` | `prom/prometheus:v3.13.2` | `9090` | Scrapes the collector's `:8889` | | `grafana` | `grafana/grafana:13.1.2` | `3000` | Dashboards + provisioned datasources/alerts, anonymous admin | -| `renderer` | `grafana/grafana-image-renderer:v5.12.0` | `8081` | Panel→PNG rendering for image export and alert screenshots | +| `renderer` | `grafana/grafana-image-renderer:v5.12.0` | none | Panel→PNG rendering for image export and alert screenshots | Two corrections to earlier drafts: diff --git a/docker/telemetry/docker-compose.yml b/docker/telemetry/docker-compose.yml index 1cd02c9647..1cb821734d 100644 --- a/docker/telemetry/docker-compose.yml +++ b/docker/telemetry/docker-compose.yml @@ -214,8 +214,10 @@ services: # Shared secret for the JWT-authenticated render requests Grafana 13 # sends. Must match GF_RENDERING_RENDERER_TOKEN on the grafana service. - AUTH_TOKEN=${GF_RENDERING_RENDERER_TOKEN:-xrpld-local-render} - ports: - - "8081:8081" # Renderer HTTP endpoint (called by grafana) + # No `ports:` on purpose. Grafana reaches this over the compose network at + # http://renderer:8081, so publishing 8081 on the host adds nothing the + # stack needs. AUTH_TOKEN above is the only guard on the endpoint, and its + # default is a fixed string in this file, so keep the service off the host. networks: - xrpld-telemetry # Named volume for Tempo trace storage (WAL and compacted blocks).