summaryrefslogtreecommitdiff
path: root/contrib
diff options
context:
space:
mode:
authorDennis Fink2026-05-06 19:51:45 +0200
committerDennis Fink2026-05-06 19:51:45 +0200
commit5a2d4ca818e6ee45f99e4c92310e137a7b1b4aea (patch)
tree9f1338915f0755c71f5c65573019939dbef0c24a /contrib
parentd9e410a10b2c175fc32437b35c59eccf5172b051 (diff)
downloadprometheus-borgmatic-exporter-78345cb0e3c88c803ac486ed43ab4d5bd9823d1c.tar.gz
prometheus-borgmatic-exporter-78345cb0e3c88c803ac486ed43ab4d5bd9823d1c.zip
feat: implement initial borgmatic Prometheus exporterv1.0.0
Diffstat (limited to 'contrib')
-rw-r--r--contrib/prometheus-borgmatic-exporter.confd1
-rw-r--r--contrib/prometheus-borgmatic-exporter.service61
-rw-r--r--contrib/prometheus-borgmatic-exporter.timer11
3 files changed, 73 insertions, 0 deletions
diff --git a/contrib/prometheus-borgmatic-exporter.confd b/contrib/prometheus-borgmatic-exporter.confd
new file mode 100644
index 0000000..cf82ace
--- /dev/null
+++ b/contrib/prometheus-borgmatic-exporter.confd
@@ -0,0 +1 @@
+PROMETHEUS_BORGMATIC_EXPORTER_ARGS=""
diff --git a/contrib/prometheus-borgmatic-exporter.service b/contrib/prometheus-borgmatic-exporter.service
new file mode 100644
index 0000000..56c3d18
--- /dev/null
+++ b/contrib/prometheus-borgmatic-exporter.service
@@ -0,0 +1,61 @@
+[Unit]
+Description=Borgmatic Prometheus metrics exporter
+After=network.target
+
+[Service]
+Type=oneshot
+EnvironmentFile=/etc/conf.d/prometheus-borgmatic-exporter
+ExecStart=/usr/bin/prometheus-borgmatic-exporter $PROMETHEUS_BORGMATIC_EXPORTER_ARGS
+
+User=root
+Group=root
+
+# Needs write access to emit the .prom file and read/write the borg cache.
+# All other paths read-only by default
+ReadWritePaths=/var/lib/prometheus/node-exporter
+ReadWritePaths=/root/.cache/borg
+# Mount a private /tmp not shared with the rest of the system
+PrivateTmp=true
+# Mount a minimal /dev without the access to raw block or character devices
+PrivateDevices=true
+# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted
+
+# Hide other processes in /proc
+ProtectProc=invisible
+# Limit /proc to PID-related files only
+ProcSubset=pid
+# Set predictable permissions for the written .prom file
+UMask=0022
+
+# Restrict to the address families needed for SSH and local communication
+RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
+
+# Kernel and system hardening
+ProtectKernelTunables=true
+ProtectKernelModules=true
+ProtectKernelLogs=true
+ProtectControlGroups=true
+ProtectHostname=true
+ProtectClock=true
+RestrictNamespaces=true
+RestrictRealtime=true
+RestrictSUIDSGID=true
+LockPersonality=true
+MemoryDenyWriteExecute=true
+RemoveIPC=true
+
+# Capabilites
+# Root always holds capabilites, but we restrict what child processes can inherit
+# CAP_DAC_OVERRIDE: needed by borg for file acess
+# CAP_NET_RAW: needed for SSH connections
+CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_NET_RAW
+AmbientCapabilities=
+# NoNewPrivileges is intentionally omitted as borg needs to exec SSH
+
+# Syscall filtering
+SystemCallArchitectures=native
+SystemCallFilter=@system-service
+SystemCallFilter=~@privileged @resources @mount @swap @reboot
+
+[Install]
+WantedBy=multi-user.target
diff --git a/contrib/prometheus-borgmatic-exporter.timer b/contrib/prometheus-borgmatic-exporter.timer
new file mode 100644
index 0000000..61fa6a8
--- /dev/null
+++ b/contrib/prometheus-borgmatic-exporter.timer
@@ -0,0 +1,11 @@
+[Unit]
+Description=Run Borgmatic Prometheus metrics exporter daily
+After=network.target
+
+[Timer]
+OnCalendar=daily
+AccuracySec=1h
+Persistent=true
+
+[Install]
+WantedBy=timers.target