diff options
Diffstat (limited to 'contrib')
| -rw-r--r-- | contrib/prometheus-borgmatic-exporter.confd | 1 | ||||
| -rw-r--r-- | contrib/prometheus-borgmatic-exporter.service | 61 | ||||
| -rw-r--r-- | contrib/prometheus-borgmatic-exporter.timer | 11 |
3 files changed, 73 insertions, 0 deletions
diff --git a/contrib/prometheus-borgmatic-exporter.confd b/contrib/prometheus-borgmatic-exporter.confd new file mode 100644 index 0000000..cf82ace --- /dev/null +++ b/contrib/prometheus-borgmatic-exporter.confd @@ -0,0 +1 @@ +PROMETHEUS_BORGMATIC_EXPORTER_ARGS="" diff --git a/contrib/prometheus-borgmatic-exporter.service b/contrib/prometheus-borgmatic-exporter.service new file mode 100644 index 0000000..56c3d18 --- /dev/null +++ b/contrib/prometheus-borgmatic-exporter.service @@ -0,0 +1,61 @@ +[Unit] +Description=Borgmatic Prometheus metrics exporter +After=network.target + +[Service] +Type=oneshot +EnvironmentFile=/etc/conf.d/prometheus-borgmatic-exporter +ExecStart=/usr/bin/prometheus-borgmatic-exporter $PROMETHEUS_BORGMATIC_EXPORTER_ARGS + +User=root +Group=root + +# Needs write access to emit the .prom file and read/write the borg cache. +# All other paths read-only by default +ReadWritePaths=/var/lib/prometheus/node-exporter +ReadWritePaths=/root/.cache/borg +# Mount a private /tmp not shared with the rest of the system +PrivateTmp=true +# Mount a minimal /dev without the access to raw block or character devices +PrivateDevices=true +# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted + +# Hide other processes in /proc +ProtectProc=invisible +# Limit /proc to PID-related files only +ProcSubset=pid +# Set predictable permissions for the written .prom file +UMask=0022 + +# Restrict to the address families needed for SSH and local communication +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX + +# Kernel and system hardening +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +ProtectControlGroups=true +ProtectHostname=true +ProtectClock=true +RestrictNamespaces=true +RestrictRealtime=true +RestrictSUIDSGID=true +LockPersonality=true +MemoryDenyWriteExecute=true +RemoveIPC=true + +# Capabilites +# Root always holds capabilites, but we restrict what child processes can inherit +# CAP_DAC_OVERRIDE: needed by borg for file acess +# CAP_NET_RAW: needed for SSH connections +CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_NET_RAW +AmbientCapabilities= +# NoNewPrivileges is intentionally omitted as borg needs to exec SSH + +# Syscall filtering +SystemCallArchitectures=native +SystemCallFilter=@system-service +SystemCallFilter=~@privileged @resources @mount @swap @reboot + +[Install] +WantedBy=multi-user.target diff --git a/contrib/prometheus-borgmatic-exporter.timer b/contrib/prometheus-borgmatic-exporter.timer new file mode 100644 index 0000000..61fa6a8 --- /dev/null +++ b/contrib/prometheus-borgmatic-exporter.timer @@ -0,0 +1,11 @@ +[Unit] +Description=Run Borgmatic Prometheus metrics exporter daily +After=network.target + +[Timer] +OnCalendar=daily +AccuracySec=1h +Persistent=true + +[Install] +WantedBy=timers.target |
