diff options
Diffstat (limited to 'statuspage/checks/pf.sh')
| -rwxr-xr-x | statuspage/checks/pf.sh | 49 |
1 files changed, 49 insertions, 0 deletions
diff --git a/statuspage/checks/pf.sh b/statuspage/checks/pf.sh new file mode 100755 index 0000000..47b2acd --- /dev/null +++ b/statuspage/checks/pf.sh @@ -0,0 +1,49 @@ +#!/bin/sh +# checks/pf.sh +# pf health summary (enabled, state table usage, rule count), plus the +# actual active filter and nat/rdr rules listed as rows below. The rule +# rows use status "info" (a neutral gray square) rather than "ok" - +# they're informational, not a health signal, and a green square there +# would wrongly imply each individual rule was itself being health- +# checked. +set -eu + +DIR=$(dirname "$0") +. "$DIR/../lib/common.sh" + +INFO=$(pfctl -si 2>/dev/null) || INFO="" + +ENABLED=$(printf '%s\n' "$INFO" | awk -F'[ :]+' '/^Status:/{print $2; exit}') +if [ "$ENABLED" = "Enabled" ]; then + json_line "pf" "pf" "" "ok" +else + json_line "pf" "pf" "${ENABLED:-unknown}" "down" +fi + +CURRENT=$(printf '%s\n' "$INFO" | awk '/current entries/{print $NF; exit}') +LIMIT=$(pfctl -sm 2>/dev/null | awk '/^states/{print $NF; exit}') + +if [ -n "$CURRENT" ] && [ -n "$LIMIT" ] && [ "$LIMIT" -gt 0 ] 2>/dev/null; then + PCT=$((CURRENT * 100 / LIMIT)) + if [ "$PCT" -ge 90 ]; then + SSTATUS=down + elif [ "$PCT" -ge 75 ]; then + SSTATUS=warn + else + SSTATUS=ok + fi + json_line "pf" "state table" "${CURRENT}/${LIMIT} (${PCT}%)" "$SSTATUS" +fi + +RULE_COUNT=$(pfctl -sr 2>/dev/null | grep -c .) || RULE_COUNT=0 +json_line "pf" "filter rules loaded" "$RULE_COUNT" "ok" + +pfctl -sr 2>/dev/null | while IFS= read -r rule; do + [ -n "$rule" ] || continue + json_line "pf" " $rule" "" "info" +done + +pfctl -sn 2>/dev/null | while IFS= read -r rule; do + [ -n "$rule" ] || continue + json_line "pf" " nat: $rule" "" "info" +done |
