fail2ban: Add metrics
This commit is contained in:
		
							parent
							
								
									c7d46f1c2b
								
							
						
					
					
						commit
						ec0afc6085
					
				
					 10 changed files with 176 additions and 24 deletions
				
			
		
							
								
								
									
										45
									
								
								configuration/services/metrics/exporters.nix
									
										
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								configuration/services/metrics/exporters.nix
									
										
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,45 @@ | |||
| { | ||||
|   config, | ||||
|   lib, | ||||
|   ... | ||||
| }: { | ||||
|   options.services.prometheus.local-exporters = lib.mkOption { | ||||
|     type = lib.types.anything; | ||||
|   }; | ||||
| 
 | ||||
|   config.systemd.services = lib.mapAttrs (_: exporter: | ||||
|     lib.mkMerge [ | ||||
|       { | ||||
|         wantedBy = ["multi-user.target"]; | ||||
|         after = ["network.target"]; | ||||
| 
 | ||||
|         serviceConfig = { | ||||
|           Restart = "always"; | ||||
|           PrivateTmp = true; | ||||
|           WorkingDirectory = "/tmp"; | ||||
|           DynamicUser = true; | ||||
|           LockPersonality = true; | ||||
|           MemoryDenyWriteExecute = true; | ||||
|           NonNewPrivileges = true; | ||||
|           PrivateDevices = true; | ||||
|           ProtectClock = true; | ||||
|           ProtectControlGroups = true; | ||||
|           ProtectHome = true; | ||||
|           ProtectHostname = true; | ||||
|           ProtectKernelLogs = true; | ||||
|           ProtectKernelModules = true; | ||||
|           ProtectKernelTunables = true; | ||||
|           ProtectSystem = "strict"; | ||||
|           RemoveIPC = true; | ||||
|           RestrictAddressFamilies = lib.mkDefault ["AF_INET" "AF_INET6"]; | ||||
|           RestrictNamespaces = true; | ||||
|           RestrictRealtime = true; | ||||
|           RestrictSUIDSGID = true; | ||||
|           SystemCallArchitectures = "native"; | ||||
|           UMask = "0077"; | ||||
|         }; | ||||
|       } | ||||
|       (removeAttrs exporter ["port" "listenAddress"]) | ||||
|     ]) | ||||
|   config.services.prometheus.local-exporters; | ||||
| } | ||||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue