From patchwork Thu Jul 30 21:40:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Robin Roevens X-Patchwork-Id: 10082 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hB2nj6tjVz3wqJ for ; Thu, 30 Jul 2026 21:46:01 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hB2nY01M7z6KS for ; Thu, 30 Jul 2026 21:45:52 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hB2n123KBz36VP for ; Thu, 30 Jul 2026 21:45:25 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hB2my5HGTz2xLl for ; Thu, 30 Jul 2026 21:45:22 +0000 (UTC) Received: from layka.disroot.org (layka.disroot.org [178.21.23.139]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bit raw public key) server-digest SHA256) (Client did not present a certificate) by mail01.ipfire.org (Postfix) with ESMTPS id 4hB2mn6pTkz6Y for ; Thu, 30 Jul 2026 21:45:13 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=Bl7lTSTo; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1785447919; b=nh5R7Gd5dYaBAS0eaYHuVgx70wmSxQsUnITvtgSUFGHaFCHZgTqwa5Rg051jegkDnndDdo 6Qv/eLVUKy6OLLmiPhLg84WMzSSu6oCRzg5SwTUcZ6J/9Q6sRBWeWodeF3Sd7akaBEd6ty mtEb9Zhv/kl/PKK3SApiX9Vtg0fKLkVqGntT7ygU0kjmrnUwQPpt5biZP8Yj+yeFfMFDek xCrh85xsrBDOF66NIzC4JYiM9G8boDlU1K9B1x+KVP1Ut/ZR0Lzt3pnrw3Vee08nxG9fo0 oRyaMtu8Z62j1YYsXY6smCnQ6GvHHjIZGnUwdps+93zXjK/cqCMl9gyyTHUfog== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1785447919; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=0qbmHnfpr/2gPpSYam02HJUPrFUdS6yCPNg2Lc7qOmY=; b=Wr68d6QXBlr/xOUyEwC+ixWiw+X22Bv5hNL4DtcCf6Xcfc1r5372W8bpsxvhT/a9YMNPOW YU/n5BoQ1NfXLgL9lPR6HQ/q/UE4ydB61NxrDFqwZdDqjgeCFyvKuzI9McnCul8be2GNPB KR8Kpf8s7RoS6Lyg298DP6bvxK3zwpkUmpBJfTbrPNF90I8eQS2qVyQADZJ+K4I0UHhXA2 PJIAnA49Qw16BdcksxmfF2FV4y0dLK7muRrOTXzzeAszuDV1EwJJZ8xHWLjmaVOmAkpowa aHWP28+/cRUs5mJZEazRk8KVqvkhAhUAp7wUvzrKm8BRdb7auRrtU1Gl9WEtcQ== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=Bl7lTSTo; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org Received: from mail01.layka.lan (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id 3342341BDA for ; Thu, 30 Jul 2026 23:45:13 +0200 (CEST) X-Virus-Scanned: SPAM Filter at disroot.org Received: from layka.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavis, port 10024) with ESMTP id Abizrd0wDSW3 for ; Thu, 30 Jul 2026 23:45:12 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1785447912; bh=J0F5xvogjW2YnTvYTlFekMOeQMc2QeJrFdFtJ5IcGaM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Bl7lTSToyQ9K5hW3jv2qws9uSdTu7IUokRdOT4Y1SSBwXZUfQg3Spxp7S03CkzJFo Vf9aSAwf6bkzfpJqjAguitaMK1t3NMlQoR/MZh96NWwh7ycS1uwbu1OLD3YKViKqiq XrpaJq1Qqhgjpm7VD7PUYyfWrr+CcMKvb/a28kq7OLm/JHu8WW1ircmTAfmjNGcC3j dzOQftXgOVvVbHQiql3+O3dmStgUEd8oleZCGl9a5K/fDKjZNU8rzKA98DElhLNXV9 9maTVI+r4T8dzHgz4049zdK1p+wy/+QESbHXrAf3S4VnTjWtwwDmelhNT75ph9mhQc TJKzEJSK7Zk7Q== Received: from chojin.roevenslambrechts.be (chojin.roevenslambrechts.be [192.168.0.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (no client certificate requested) (Authenticated sender) by hachiman (MailScanner Milter) with SMTP id 971015861E6; Thu, 30 Jul 2026 23:45:07 +0200 (CEST) From: Robin Roevens To: development@lists.ipfire.org Cc: Robin Roevens Subject: [PATCH] zabbix_agentd: Make kresd userparameter not ipfire specific Date: Thu, 30 Jul 2026 23:40:55 +0200 Message-ID: <20260730214502.613317-2-robin.roevens@disroot.org> In-Reply-To: <20260730214502.613317-1-robin.roevens@disroot.org> References: <20260730214502.613317-1-robin.roevens@disroot.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 X-RoevensLambrechts-MailScanner-ID: 971015861E6.AD543 X-RoevensLambrechts-MailScanner: Found to be clean X-RoevensLambrechts-MailScanner-From: robin.roevens@disroot.org X-RoevensLambrechts-MailScanner-Watermark: 1786052710.11156@C5gUpwlnuFdISwtC01S2dQ X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4hB2mn6pTkz6Y X-Rspamd-Action: no action X-Spamd-Result: default: False [-5.63 / 11.00]; BAYES_HAM(-3.00)[100.00%]; R_DKIM_ALLOW(-1.65)[disroot.org:s=mail]; MID_CONTAINS_FROM(1.00)[]; DKIM_REPUTATION(-0.92)[-0.92157174415262]; SPF_REPUTATION_HAM(-0.66)[-0.65701338986531]; DMARC_POLICY_ALLOW(-0.50)[disroot.org,reject]; R_MISSING_CHARSET(0.50)[]; R_SPF_ALLOW(-0.20)[+a]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.10)[disroot.org]; RCPT_COUNT_TWO(0.00)[2]; ASN(0.00)[asn:50673, ipnet:178.21.23.0/24, country:NL]; IP_REPUTATION_HAM(0.00)[asn: 50673(0.00), country: NL(-0.01), ip: 178.21.23.139(0.00)]; ARC_NA(0.00)[]; TO_DN_SOME(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_COUNT_THREE(0.00)[3]; RCVD_TLS_LAST(0.00)[]; TO_MATCH_ENVRCPT_SOME(0.00)[]; MISSING_XM_UA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[disroot.org:+]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; FROM_HAS_DN(0.00)[] By removing the "ipfire."-prefix from the userparameter, it allows the Kresd monitoring Zabbix template to be more generic and also usable on non-IPFire systems. Signed-off-by: Robin Roevens --- config/rootfiles/packages/zabbix_agentd | 1 + config/zabbix_agentd/userparameter_ipfire.conf | 3 --- config/zabbix_agentd/userparameter_kresd.conf | 2 ++ lfs/zabbix_agentd | 2 ++ 4 files changed, 5 insertions(+), 3 deletions(-) create mode 100644 config/zabbix_agentd/userparameter_kresd.conf diff --git a/config/rootfiles/packages/zabbix_agentd b/config/rootfiles/packages/zabbix_agentd index 7f1f39b64..9d928974f 100644 --- a/config/rootfiles/packages/zabbix_agentd +++ b/config/rootfiles/packages/zabbix_agentd @@ -24,6 +24,7 @@ var/ipfire/zabbix_agentd/userparameters/userparameter_ovpn.conf var/ipfire/zabbix_agentd/userparameters/userparameter_gateway.conf var/ipfire/zabbix_agentd/userparameters/userparameter_wireguard.conf var/ipfire/zabbix_agentd/userparameters/userparameter_locationdb.conf +var/ipfire/zabbix_agentd/userparameters/userparameter_kresd.conf var/ipfire/zabbix_agentd/scripts var/ipfire/zabbix_agentd/scripts/ipfire_certificate_detail.sh var/ipfire/zabbix_agentd/scripts/ipfire_services.pl diff --git a/config/zabbix_agentd/userparameter_ipfire.conf b/config/zabbix_agentd/userparameter_ipfire.conf index a91e305a3..e88c20298 100644 --- a/config/zabbix_agentd/userparameter_ipfire.conf +++ b/config/zabbix_agentd/userparameter_ipfire.conf @@ -10,12 +10,9 @@ UserParameter=ipfire.captive.clients,awk -F ',' 'length($2) == 17 {sum += 1} END UserParameter=ipfire.services.get,sudo /var/ipfire/zabbix_agentd/scripts/ipfire_services.pl # IPS throughput bypassed/scanned/whitelisted in bytes/type (JSON) UserParameter=ipfire.ips.throughput.get,sudo /usr/local/bin/getipstat -xm | awk 'BEGIN{ORS="";print "{"}/Chain IPS/{f=1}/BYPASSED/&&f{printf "\"bypassed\":%s",$2}/SCANNED/&&f{printf ",\"scanned\":%s",$2}/WHITELISTED/&&f{printf ",\"whitelisted\":%s",$2}/^$/{f=0}END{print "}"}' -# Knot DNS resolver statistics -UserParameter=ipfire.kresd.stats.get,sudo /usr/bin/curl -s --unix-socket /var/run/knot-resolver/kres-api.sock http://localhost/metrics/json # Addon: Guardian: Number of currently blocked IP's UserParameter=ipfire.guardian.blocked.count,sudo /usr/local/bin/getipstat | awk 'BEGIN{ORS="";c=0}/Chain GUARDIAN/{f=1}/DROP/&&f{c++}/^$/{f=0}END{print c}' # # Allow item key to be called with (unused) parameters. This allows the #SINGLETON method of discovering this item only when specific service is active Alias=ipfire.ips.throughput.get[]:ipfire.ips.throughput.get -Alias=ipfire.kresd.stats.get[]:ipfire.kresd.stats.get Alias=ipfire.guardian.blocked.count[]:ipfire.guardian.blocked.count \ No newline at end of file diff --git a/config/zabbix_agentd/userparameter_kresd.conf b/config/zabbix_agentd/userparameter_kresd.conf new file mode 100644 index 000000000..f5765919b --- /dev/null +++ b/config/zabbix_agentd/userparameter_kresd.conf @@ -0,0 +1,2 @@ +# Knot DNS resolver statistics +UserParameter=kresd.stats.get,sudo /usr/bin/curl -s --unix-socket /var/run/knot-resolver/kres-api.sock http://localhost/metrics/json \ No newline at end of file diff --git a/lfs/zabbix_agentd b/lfs/zabbix_agentd index cbf4b246c..e41cd6fe1 100644 --- a/lfs/zabbix_agentd +++ b/lfs/zabbix_agentd @@ -118,6 +118,8 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) /var/ipfire/zabbix_agentd/userparameters/userparameter_wireguard.conf install -v -m 644 $(DIR_SRC)/config/zabbix_agentd/userparameter_locationdb.conf \ /var/ipfire/zabbix_agentd/userparameters/userparameter_locationdb.conf + install -v -m 644 $(DIR_SRC)/config/zabbix_agentd/userparameter_kresd.conf \ + /var/ipfire/zabbix_agentd/userparameters/userparameter_kresd.conf # Install IPFire-specific Zabbix Agent scripts -mkdir -pv /var/ipfire/zabbix_agentd/scripts