services:
  alloy:
    image: grafana/alloy:v1.17.1
    container_name: logportal-alloy
    user: "0:0"
    # Optional journal access: use the actual host group IDs if required.
    # Check with: getent group adm; getent group systemd-journal
    # Set these variables in the Compose .env file before enabling group_add.
    # group_add:
    #   - "${ALLOY_ADM_GID:?Set the host adm group ID}"
    #   - "${ALLOY_JOURNAL_GID:?Set the host systemd-journal group ID}"
    command:
      - run
      - /etc/alloy/config.alloy
      - --server.http.listen-addr=0.0.0.0:12345
      - --storage.path=/var/lib/alloy/data
    ports:
      - "127.0.0.1:12345:12345"
    volumes:
      - ./config/alloy-config.alloy:/etc/alloy/config.alloy:ro
      - ./data/alloy:/var/lib/alloy/data
      # SECTION A - Docker logs. Disable with Alloy SECTION A if not needed.
      - /var/run/docker.sock:/var/run/docker.sock:ro

      # SECTION B - systemd journal logs. Enable with Alloy SECTION B.
      # Enable only journal directories that exist on the host.
      # - /run/log/journal:/run/log/journal:ro
      # - /var/log/journal:/var/log/journal:ro
      # - /etc/machine-id:/etc/machine-id:ro

      # SECTION C - PM2 file logs. Enable with Alloy SECTION C.
      # Root-owned PM2 logs.
      # - /root/.pm2/logs:/host/root/.pm2/logs:ro

      # PM2 logs for multiple app users. This exposes all of /home read-only.
      # Prefer a specific user's log directory and adjust the Alloy target.
      # - /home:/host/home:ro

      # Optional app log locations: enable only when these paths are needed.
      # - /opt:/host/opt:ro
      # - /var/www:/host/var/www:ro
    deploy:
      resources:
        limits:
          cpus: '0.50'
          memory: 512M
    restart: unless-stopped
