packaged by Chainguard
Contact our team to test out this image for free. Please also indicate any other images you would like to evaluate.
Percona Monitoring and Management is an open source database observability, monitoring and management tool for MySQL, PostgreSQL and MongoDB.
Chainguard Containers are regularly-updated, secure-by-default container images.
For those with access, this container image is available on cgr.dev:
Be sure to replace the ORGANIZATION placeholder with the name used for your organization's private repository within the Chainguard Registry.
Chainguard's pmm-server image is comparable to the upstream percona/pmm-server image and is designed to be a drop-in replacement for it for new deployments. It matches the upstream image's launch command, working directory, /srv volume, and HTTP port, so docker run invocations and Kubernetes manifests written for the upstream image work unchanged here, though an existing upstream /srv volume cannot be reused (see below).
The following differences are worth noting:
dnf and yum are not present and the RPM database is absent. Software is added through Custom Assembly instead.HEALTHCHECK. The upstream image polls http://127.0.0.1:8080/v1/server/readyz from one; that endpoint behaves identically here, but the probe has to be supplied by the caller — --health-cmd on docker run, or a readinessProbe in Kubernetes.linux/amd64 and linux/arm64. The upstream image publishes linux/amd64 only.rsync is not included, although the upstream image ships it. Nothing in PMM invokes it: upstream installs it from a build-time ansible role that does not run at container start. Add it with Custom Assembly if you rely on it.LANG is set to C.UTF-8 rather than upstream's en_US.utf8, which this image has no locale data for. Both yield a UTF8 PostgreSQL cluster, but collation is C rather than en_US, so ORDER BY on text columns in the PMM database sorts by byte value./srv volume from percona/pmm-server cannot be reused: its PostgreSQL cluster was initialized with en_US.utf8, and PostgreSQL refuses to start against a cluster whose locale is missing. Start from an empty volume and carry over metrics and Query Analytics data with PMM Dump; dashboards, users, alert rules and inventory do not carry over, so clients must re-register. Alternatively, add the locale with Custom Assembly.PGHOST is set to /run/postgresql image-wide. Percona's RPM builds libpq with that socket directory compiled in; the Chainguard PostgreSQL packages use the upstream default, so the variable supplies what the compiled-in path would otherwise provide./srv/nginx at first start, so HTTPS on port 8443 uses an untrusted certificate. To use your own, place certificate.crt and certificate.key in /srv/nginx before first start, or terminate TLS in front of the container. /srv/nginx must stay writable: the entrypoint creates nginx's temp directories there before it looks at any certificate, so a read-only mount — a Kubernetes Secret, for example — makes the container exit at start.runAsUser) does not work, because PMM's initialization playbook performs an ownership operation on a file the overriding UID does not own. Group-writable directory modes do not make this work.This follows Percona's PMM quickstart: start the server, open its web interface, then register a database with it.
PMM Server keeps all of its state in /srv, so start it with a volume mounted there and set the administrator password up front:
The first start initializes the PostgreSQL and ClickHouse databases and provisions the bundled dashboards, so it takes a minute or two longer than subsequent restarts. Wait for the server to report itself ready:
Browse to http://localhost:8080. The server redirects to the Grafana interface at /graph/ and presents a login form. Sign in as admin with the password you set above.
The landing page is the Home Dashboard, which summarizes every monitored node, and Query Analytics is reachable from the main menu — that is where per-query metrics appear once a database is registered.
PMM monitors itself, so even with no databases registered yet the server's own node is already in its inventory. The quickest way to confirm the client stack came up is to ask the API directly:
It returns a generic node named pmm-server with "is_pmm_server_node": true.
Monitoring happens through PMM Client, which runs alongside the database rather than in this container. Chainguard does not currently publish a pmm-client image, so use Percona's.
Both containers need to be on the same user-defined network for pmm-server to resolve, and the server's HTTPS port inside the container is 8443. Attach the already-running server rather than restarting it, and put the monitored database on the same network with a pmm user that can read performance_schema:
--query-source=perfschema matters: the default is slowlog, which reads MySQL's slow log as a local file that a separate client container does not have, so Query Analytics would stay empty.
Metrics appear on the MySQL dashboards within a minute, and query data in Query Analytics once the database has served some traffic. See Set up PMM Client for the other supported database types and connection options.
/srv holds the PostgreSQL and ClickHouse data directories, the VictoriaMetrics time series database, and the Grafana plugin tree. Mounting a persistent volume there is the single most important configuration choice, because a container started without one loses every metric and dashboard when it is replaced.
GF_SECURITY_ADMIN_PASSWORD applies when the server initializes its database on first start. Because that initialization happens only once per volume, changing the variable later has no effect; rotate it afterwards with the change-admin-password script the image ships, or through the Grafana user interface:
Chainguard's free tier of Starter container images are built with Wolfi, our minimal Linux undistro.
All other Chainguard Containers are built with Chainguard OS, Chainguard's minimal Linux operating system designed to produce container images that meet the requirements of a more secure software supply chain.
The main features of Chainguard Containers include:
For cases where you need container images with shells and package managers to build or debug, most Chainguard Containers come paired with a development, or -dev, variant.
In all other cases, including Chainguard Containers tagged as :latest or with a specific version number, the container images include only an open-source application and its runtime dependencies. These minimal container images typically do not contain a shell or package manager.
Although the -dev container image variants have similar security features as their more minimal versions, they include additional software that is typically not necessary in production environments. We recommend using multi-stage builds to copy artifacts from the -dev variant into a more minimal production image.
To improve security, Chainguard Containers include only essential dependencies. Need more packages? Chainguard customers can use Custom Assembly to add packages, either through the Console, chainctl, or API.
To use Custom Assembly in the Chainguard Console: navigate to the image you'd like to customize in your Organization's list of images, and click on the Customize image button at the top of the page.
Refer to our Chainguard Containers documentation on Chainguard Academy. Chainguard also offers VMs and Libraries — contact us for access.
This software listing is packaged by Chainguard. The trademarks set forth in this offering are owned by their respective companies, and use of them does not imply any affiliation, sponsorship, or endorsement by such companies.
Chainguard's container images contain software packages that are direct or transitive dependencies. The following licenses were found in the "latest" tag of this image:
( GPL-2.0-or-later
AGPL-3.0-only
Apache-2.0
Artistic-1.0-Perl
BSD-1-Clause
BSD-2-Clause
BSD-3-Clause
For a complete list of licenses, please refer to this Image's SBOM.
Software license agreementChainguard Containers are SLSA Level 3 compliant with detailed metadata and documentation about how it was built. We generate build provenance and a Software Bill of Materials (SBOM) for each release, with complete visibility into the software supply chain.
SLSA compliance at ChainguardThis image helps reduce time and effort in establishing PCI DSS 4.0 compliance with low-to-no CVEs.
PCI DSS at Chainguard