summaryrefslogtreecommitdiff
path: root/statuspage/checks/pf.sh
diff options
context:
space:
mode:
Diffstat (limited to 'statuspage/checks/pf.sh')
-rwxr-xr-xstatuspage/checks/pf.sh49
1 files changed, 49 insertions, 0 deletions
diff --git a/statuspage/checks/pf.sh b/statuspage/checks/pf.sh
new file mode 100755
index 0000000..47b2acd
--- /dev/null
+++ b/statuspage/checks/pf.sh
@@ -0,0 +1,49 @@
+#!/bin/sh
+# checks/pf.sh
+# pf health summary (enabled, state table usage, rule count), plus the
+# actual active filter and nat/rdr rules listed as rows below. The rule
+# rows use status "info" (a neutral gray square) rather than "ok" -
+# they're informational, not a health signal, and a green square there
+# would wrongly imply each individual rule was itself being health-
+# checked.
+set -eu
+
+DIR=$(dirname "$0")
+. "$DIR/../lib/common.sh"
+
+INFO=$(pfctl -si 2>/dev/null) || INFO=""
+
+ENABLED=$(printf '%s\n' "$INFO" | awk -F'[ :]+' '/^Status:/{print $2; exit}')
+if [ "$ENABLED" = "Enabled" ]; then
+ json_line "pf" "pf" "" "ok"
+else
+ json_line "pf" "pf" "${ENABLED:-unknown}" "down"
+fi
+
+CURRENT=$(printf '%s\n' "$INFO" | awk '/current entries/{print $NF; exit}')
+LIMIT=$(pfctl -sm 2>/dev/null | awk '/^states/{print $NF; exit}')
+
+if [ -n "$CURRENT" ] && [ -n "$LIMIT" ] && [ "$LIMIT" -gt 0 ] 2>/dev/null; then
+ PCT=$((CURRENT * 100 / LIMIT))
+ if [ "$PCT" -ge 90 ]; then
+ SSTATUS=down
+ elif [ "$PCT" -ge 75 ]; then
+ SSTATUS=warn
+ else
+ SSTATUS=ok
+ fi
+ json_line "pf" "state table" "${CURRENT}/${LIMIT} (${PCT}%)" "$SSTATUS"
+fi
+
+RULE_COUNT=$(pfctl -sr 2>/dev/null | grep -c .) || RULE_COUNT=0
+json_line "pf" "filter rules loaded" "$RULE_COUNT" "ok"
+
+pfctl -sr 2>/dev/null | while IFS= read -r rule; do
+ [ -n "$rule" ] || continue
+ json_line "pf" " $rule" "" "info"
+done
+
+pfctl -sn 2>/dev/null | while IFS= read -r rule; do
+ [ -n "$rule" ] || continue
+ json_line "pf" " nat: $rule" "" "info"
+done