summaryrefslogtreecommitdiff
path: root/statuspage
diff options
context:
space:
mode:
authorbatsumaru <>2026-07-01 16:36:55 +0900
committerbatsumaru <>2026-07-01 16:36:55 +0900
commit689ca3bdadc00015d5aedd81f76fd0950777f1ef (patch)
treec9673ce29d84289e0d3b799d3f5d8e03bcc4b777 /statuspage
parent358106287b28bffa8505b67fe623f77a3fbceae3 (diff)
Add ntpd/clock-sync check and a pre-commit hook for exec bits
checks/ntpd.sh reports whether ntpd is running and whether the clock's offset is within tolerance (ok <50ms, warn <200ms, down beyond that or if ntpq doesn't respond) - clock drift is a silent failure that otherwise only surfaces later as TLS handshake failures or misleading cross-jail log timestamps. Also add .githooks/pre-commit + core.hooksPath, since this checkout is on Windows where core.fileMode is false (the filesystem doesn't reliably preserve the executable bit) - without it, a plain `git add` on a new check script silently stages it as non-executable, and render.sh skips non-executable files with no visible error. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Diffstat (limited to 'statuspage')
-rwxr-xr-xstatuspage/checks/ntpd.sh33
1 files changed, 33 insertions, 0 deletions
diff --git a/statuspage/checks/ntpd.sh b/statuspage/checks/ntpd.sh
new file mode 100755
index 0000000..1770dc8
--- /dev/null
+++ b/statuspage/checks/ntpd.sh
@@ -0,0 +1,33 @@
+#!/bin/sh
+# checks/ntpd.sh
+# ntpd process, plus whether the clock's actual offset is within
+# tolerance. A stopped or badly-drifted ntpd is a silent failure that
+# only shows up later - in TLS handshake failures, cron firing at the
+# wrong time, or cross-jail log timestamps that don't line up.
+set -eu
+
+DIR=$(dirname "$0")
+. "$DIR/../lib/common.sh"
+
+NTPD_STATUS=$(svc_status ntpd)
+json_line "host services" "ntpd" "" "$NTPD_STATUS"
+
+if [ "$NTPD_STATUS" != "ok" ]; then
+ exit 0
+fi
+
+RAW=$(ntpq -c "rv 0 offset" 2>/dev/null | sed -n 's/.*offset=\([-0-9.]*\).*/\1/p')
+
+if [ -z "$RAW" ]; then
+ json_line "host services" "clock offset" "no response" "warn"
+ exit 0
+fi
+
+STATUS=$(awk -v v="$RAW" 'BEGIN {
+ a = (v < 0) ? -v : v
+ if (a < 50) print "ok"
+ else if (a < 200) print "warn"
+ else print "down"
+}')
+
+json_line "host services" "clock offset" "${RAW} ms" "$STATUS"