`sudo -v` always attempts interactive credential validation; it does not consult NOPASSWD entries. On any user configured with `NOPASSWD:ALL` (cloud-init's default ubuntu, most CI runners), `sudo -v` still demands a TTY password prompt and dies with "sudo authentication failed" when there is no TTY. Found by the obmp-portability-test two-VM run: deploy.sh failed at line 433 on a cloud-init-provisioned Ubuntu 24.04 VM despite the ubuntu user having passwordless sudo (`sudo -n whoami` returned root correctly). Fix: try `sudo -n -v` first (succeeds silently on NOPASSWD users, fails non-interactively on others), and only fall through to the interactive `sudo -v` prompt when the non-interactive probe fails. Humans still get the same visible up-front prompt; automation now succeeds without one. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
OpenBMP docker files
Docker files for OpenBMP.
Start here:
- Deploying the stack? Jump to Greenfield deploy below, then see the docs index for deployment types, portability findings, sizing, and backup.
- Configuring routers to feed it? Go straight to docs/router-integration.md and the copy-paste fragments in router-blueprints/.
(Prerequisite) Platform Docker Install
Ignore this step if you already have a current docker install
Note
You should use the latest docker version, documented in this section.
Follow the instructions on https://docs.docker.com/get-docker/
Optionally add a non-root user to run docker as
usermod -aG docker ubuntu
# Logout and log back so the group takes affect.
Optionally configure /etc/default/docker (e.g. for proxy config)
export http_proxy="http://proxy:80/"
export https_proxy="http://proxy:80/"
export no_proxy="127.0.0.1,openbmp.org,/var/run/docker.sock"
Make sure you can run 'docker run hello-world' successfully.
OpenBMP Docker Files
Each docker file contains a readme file, see below:
Greenfield deploy (recommended): deploy.sh
Deploying onto a new host? Use deploy.sh — it reconciles the host-specific
.env values (HOST_IP, router-facing IP/port, auth mode) before running
setup.sh, guards against the known portability traps
(docs/PORTABILITY-FINDINGS.md), and brings the
stack up in stages:
git clone <repo-url> && cd obmp-docker
git checkout <branch> # pin the deploy: note the branch AND commit
git log -1 --oneline # record what you deployed
./deploy.sh # interactive; or --wsl/--prod --scope ... --yes
A greenfield deploy is only reproducible if the checkout is pinned — "clone and run" silently depends on whatever branch was checked out. Record the branch + commit with the deployment.
Deployment types (--scope full-stack|remote|central-store) are described in
docs/DEPLOYMENT-TYPES.md. Router-side BMP config:
docs/router-bmp-config.md; multi-path integration
(BGP-LS, gNMI, NETCONF, RR overlay): docs/router-integration.md,
with copy-paste IOS-XR fragments under router-blueprints/iosxr/.
Using Docker Compose to run everything
Quick start: copy
.env.exampleto.env, fill it in, and run./setup.sh— it creates the data directories, syncs Grafana provisioning, and generates Authelia secrets. Then:docker compose up -d # BMP collector core docker compose --profile test --profile auth up -d # full stackSee docs/DOCS.md section 4 for details and the manual alternative below.
Install Docker Compose
You will need docker-compose. You can install that via Docker Compose instructions. Docker compose will run everything, including handling restarts of containers.
(1) Mount/Make persistent directories
Create expected directories. You can choose to mount these as well or update the compose file to change them.
Note
If you are using OSX/Mac, then you will need to update your docker preferences to allow
/var/openbmp
Make sure to create the OBMP_DATA_ROOT directory first.
export OBMP_DATA_ROOT=/var/openbmp
sudo mkdir -p $OBMP_DATA_ROOT
Create sub directories
mkdir -p ${OBMP_DATA_ROOT}/config
mkdir -p ${OBMP_DATA_ROOT}/kafka-data
mkdir -p ${OBMP_DATA_ROOT}/zk-data
mkdir -p ${OBMP_DATA_ROOT}/zk-log
mkdir -p ${OBMP_DATA_ROOT}/postgres/data
mkdir -p ${OBMP_DATA_ROOT}/postgres/ts
mkdir -p ${OBMP_DATA_ROOT}/grafana
mkdir -p ${OBMP_DATA_ROOT}/grafana/dashboards
sudo chmod -R 7777 $OBMP_DATA_ROOT
WARNING: on a host with an existing Postgres data tree, a recursive chmod makes
psql_server.keygroup/world-accessible and Postgres will refuse to start. Skippostgres/(setup.sh does this for you — see docs/PORTABILITY-FINDINGS.md finding 10).
DB tables are created automatically by psql-app on its first run (it drops a
config/do_not_init_dbmarker afterward so restarts skip the migration). Noinit_dbtrigger file is needed — that was upstream behavior this repo's psql-app replaces.
Change OBMP_DATA_ROOT=<path> to where you created the directories above. The default is /var/openbmp
OBMP_DATA_ROOT=/var/openbmp docker-compose -p obmp up -d