diff options
| -rw-r--r-- | contrib/prometheus-pacman-exporter.confd | 1 | ||||
| -rw-r--r-- | contrib/prometheus-pacman-exporter.service | 58 | ||||
| -rw-r--r-- | contrib/prometheus-pacman-exporter.timer | 11 |
3 files changed, 70 insertions, 0 deletions
diff --git a/contrib/prometheus-pacman-exporter.confd b/contrib/prometheus-pacman-exporter.confd new file mode 100644 index 0000000..4f9c056 --- /dev/null +++ b/contrib/prometheus-pacman-exporter.confd @@ -0,0 +1 @@ +PROMETHEUS_PACMAN_EXPORTER_ARGS="" diff --git a/contrib/prometheus-pacman-exporter.service b/contrib/prometheus-pacman-exporter.service new file mode 100644 index 0000000..770295c --- /dev/null +++ b/contrib/prometheus-pacman-exporter.service @@ -0,0 +1,58 @@ +[Unit] +Description=Pacman Prometheus metrics exporter +After=network.target + +[Service] +Type=oneshot +EnvironmentFile=/etc/conf.d/prometheus-pacman-exporter +ExecStart=/usr/bin/prometheus-pacman-exporter $PROMETHEUS_PACMAN_EXPORTER_ARGS + +User=root +Group=root + +# Needs write access to emit the .prom file and read/write the borg cache. +# All other paths read-only by default +ReadWritePaths=/var/lib/prometheus/node-exporter +# Mount a private /tmp not shared with the rest of the system +PrivateTmp=true +# Mount a minimal /dev without the access to raw block or character devices +PrivateDevices=true +# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted + +# Hide other processes in /proc +ProtectProc=invisible +# Limit /proc to PID-related files only +ProcSubset=pid +# Set predictable permissions for the written .prom file +UMask=0022 + +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX + +# Kernel and system hardening +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +ProtectControlGroups=true +ProtectHostname=true +ProtectClock=true +RestrictNamespaces=true +RestrictRealtime=true +RestrictSUIDSGID=true +LockPersonality=true +MemoryDenyWriteExecute=true +RemoveIPC=true + +# Capabilites +# Root always holds capabilites, but we restrict what child processes can inherit +CapabilityBoundingSet=CAP_DAC_OVERRIDE +AmbientCapabilities= +NoNewPrivileges=true + +# Syscall filtering +SystemCallArchitectures=native +SystemCallFilter=@system-service +SystemCallFilter=~@privileged @resources @mount @swap @reboot +SystemCallFilter=setfsuid setfsgid + +[Install] +WantedBy=multi-user.target diff --git a/contrib/prometheus-pacman-exporter.timer b/contrib/prometheus-pacman-exporter.timer new file mode 100644 index 0000000..391b957 --- /dev/null +++ b/contrib/prometheus-pacman-exporter.timer @@ -0,0 +1,11 @@ +[Unit] +Description=Run Pacman Prometheus metrics exporter daily +After=network.target + +[Timer] +OnCalendar=daily +AccuracySec=1h +Persistent=true + +[Install] +WantedBy=timers.target |
