Scrutiny Scrutiny

[SSO] Hard Drive S.M.A.R.T Monitoring

Hard Drive S.M.A.R.T Monitoring, Historical Trends & Real World Failure Thresholds

Links:

In addition to the Omnibus image (available under the latest tag) you can deploy in Hub/Spoke mode. Details: scrutiny/docker/example.hubspoke.docker-compose.yml at master ยท AnalogJ/scrutiny

Authentik ForwardAuth

Authentik ForwardAuth protects the Scrutiny web UI for the monitoring group. Keep collector and InfluxDB communication internal; ForwardAuth only protects browser requests.

Setup

scripts/authentik-apps.py --application scrutiny --apply
scripts/labctl.py service recreate monitoring/scrutiny

Keep localaccess-authentik@file on the scrutiny router and do not expose the web UI directly.

Verify

Confirm authorized UI access, non-member denial, proxy-session group revocation, logout, and continued internal health checks and collector operation.

name: scrutiny
services:
  scrutiny-influxdb:
    image: influxdb:2.9
    container_name: scrutiny-influxdb
    restart: unless-stopped
    networks:
      - proxy
    volumes:
      - ${DOCKER_VOLUMES}/scrutiny/influxdb:/var/lib/influxdb2
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:8086/health"]
      interval: 15s
      timeout: 10s
      retries: 20

  scrutiny-web:
    image: ghcr.io/analogj/scrutiny:v0.9.4-web
    container_name: scrutiny-web
    restart: unless-stopped
    networks:
      - proxy
    volumes:
      - ${DOCKER_VOLUMES}/scrutiny/config:/opt/scrutiny/config
    environment:
      SCRUTINY_WEB_INFLUXDB_HOST: "scrutiny-influxdb"
    depends_on:
      scrutiny-influxdb:
        condition: service_healthy
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:8080/api/health"]
      interval: 15s
      timeout: 10s
      retries: 20
      start_period: 10s
    labels:
      traefik.enable: true
      traefik.http.routers.scrutiny.middlewares: localaccess-authentik@file
      traefik.http.routers.scrutiny.rule: Host(`scrutiny.${MYDOMAIN}`)
      traefik.http.services.scrutiny.loadbalancer.server.port: 8080
      homepage.group: Monitoring
      homepage.name: Scrutiny
      homepage.icon: scrutiny.png
      homepage.href: https://scrutiny.${MYDOMAIN}/
      homepage.description: "[SSO] Hard Drive S.M.A.R.T Monitoring"

networks:
  proxy:
    external: true