aboutsummaryrefslogtreecommitdiff
path: root/contrib
diff options
context:
space:
mode:
Diffstat (limited to 'contrib')
-rw-r--r--contrib/prometheus-pacman-exporter.confd1
-rw-r--r--contrib/prometheus-pacman-exporter.service58
-rw-r--r--contrib/prometheus-pacman-exporter.timer11
3 files changed, 70 insertions, 0 deletions
diff --git a/contrib/prometheus-pacman-exporter.confd b/contrib/prometheus-pacman-exporter.confd
new file mode 100644
index 0000000..4f9c056
--- /dev/null
+++ b/contrib/prometheus-pacman-exporter.confd
@@ -0,0 +1 @@
+PROMETHEUS_PACMAN_EXPORTER_ARGS=""
diff --git a/contrib/prometheus-pacman-exporter.service b/contrib/prometheus-pacman-exporter.service
new file mode 100644
index 0000000..770295c
--- /dev/null
+++ b/contrib/prometheus-pacman-exporter.service
@@ -0,0 +1,58 @@
+[Unit]
+Description=Pacman Prometheus metrics exporter
+After=network.target
+
+[Service]
+Type=oneshot
+EnvironmentFile=/etc/conf.d/prometheus-pacman-exporter
+ExecStart=/usr/bin/prometheus-pacman-exporter $PROMETHEUS_PACMAN_EXPORTER_ARGS
+
+User=root
+Group=root
+
+# Needs write access to emit the .prom file and read/write the borg cache.
+# All other paths read-only by default
+ReadWritePaths=/var/lib/prometheus/node-exporter
+# Mount a private /tmp not shared with the rest of the system
+PrivateTmp=true
+# Mount a minimal /dev without the access to raw block or character devices
+PrivateDevices=true
+# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted
+
+# Hide other processes in /proc
+ProtectProc=invisible
+# Limit /proc to PID-related files only
+ProcSubset=pid
+# Set predictable permissions for the written .prom file
+UMask=0022
+
+RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
+
+# Kernel and system hardening
+ProtectKernelTunables=true
+ProtectKernelModules=true
+ProtectKernelLogs=true
+ProtectControlGroups=true
+ProtectHostname=true
+ProtectClock=true
+RestrictNamespaces=true
+RestrictRealtime=true
+RestrictSUIDSGID=true
+LockPersonality=true
+MemoryDenyWriteExecute=true
+RemoveIPC=true
+
+# Capabilites
+# Root always holds capabilites, but we restrict what child processes can inherit
+CapabilityBoundingSet=CAP_DAC_OVERRIDE
+AmbientCapabilities=
+NoNewPrivileges=true
+
+# Syscall filtering
+SystemCallArchitectures=native
+SystemCallFilter=@system-service
+SystemCallFilter=~@privileged @resources @mount @swap @reboot
+SystemCallFilter=setfsuid setfsgid
+
+[Install]
+WantedBy=multi-user.target
diff --git a/contrib/prometheus-pacman-exporter.timer b/contrib/prometheus-pacman-exporter.timer
new file mode 100644
index 0000000..391b957
--- /dev/null
+++ b/contrib/prometheus-pacman-exporter.timer
@@ -0,0 +1,11 @@
+[Unit]
+Description=Run Pacman Prometheus metrics exporter daily
+After=network.target
+
+[Timer]
+OnCalendar=daily
+AccuracySec=1h
+Persistent=true
+
+[Install]
+WantedBy=timers.target