Skip to content

Self-hosted observability for OpenTelemetry, in one container on your own servers.

Sending telemetry to a vendor means sending service names, queries, addresses and timings out of your network. Running it yourself usually means running five things. One container that accepts OTLP and keeps everything on its own volume is the middle path.

Updated

What runs inside the container

Ritele is one image, ritele/ritele, for Linux on x86-64 and arm64. Inside it is an OpenTelemetry Collector, built from the upstream components, and the application that stores and draws what the Collector passes on. It runs as an unprivileged user, not root.

It publishes three ports: 4317 for OTLP over gRPC, 4318 for OTLP over HTTP, and 8080 for the UI and its API. Everything else listens on loopback inside the container.

  • Traces: kept by tail sampling — every error, every trace you mark for documentation, and 1% of the rest by default, a rate an admin changes
  • Metrics: rate, errors and duration counted from every span before sampling, plus the metrics your services and datastores send
  • Logs: counted by severity as they arrive; the lines themselves are read from your own Loki when you connect one, and never stored

Storage on your own disk

By default everything is kept in embedded stores under the /data volume, with retention you set. Deleting the volume deletes the data. Larger estates can point the same image at their own Postgres and ClickHouse instead.

What leaves the network, and what does not

No trace, span, query or address leaves the install, and licences verify offline. A daily usage ping is on by default and RITELE_USAGE_PING=false stops it; Architecture Review, notification channels and the Loki connection stay off until an admin sets them up. The security page lists every call that can leave, and the usage ping page shows the ping field by field.

What the Collector removes before anything is stored

The bundled Collector deletes enduser.* and user.* attributes, request and response headers, the url.full and url.query attributes, database users and connection strings, and process command lines. It does not remove the older http.url and http.target attributes, so keep tokens out of URLs.

Database statements are stored with their values replaced by ? by default. RITELE_DB_QUERY_TEXT=raw stores them as sent, and off stores none.

People and roles

Sign-in is on by default. Each person has one role: a viewer reads everything but log lines; an editor also reads log lines and works the map, drift, scenarios and Health triage; an admin owns the licence, settings, users and anything that sends data out. The first start prints a one-time admin password in the container log.

OTLP on 4317 and 4318 is not authenticated yet, so keep those two ports to the services you instrument.

Licensing

Ritele is closed source and self-hosted, with a free plan to start and a licence when you outgrow it. The command below starts it.