@cryptotaxi247 / netdata-1 / commits / 2a5074ad4

Anonymous statistics (#5113)

* Added shell and dashboard anonymous statistics * Check for environment var NETDATA_REGISTRY_UNIQUE_ID * Fix indentation * Removed health-cmdapi-test * docs/anonymous-statistics.md

Chris Akritidis committed Jan 27, 2019 at 12:35 UTC 2a5074ad432f41b942bdee845975b4d8ec527361
23 files changed +414 -32
.gitignore
+2
@@ -94,6 +94,8 @@ system/netdata.plist
94 system/netdata-freebsd
95 system/edit-config
96
97 +daemon/anonymous-statistics.sh
98 +
99 health/notifications/alarm-notify.sh
100 collectors/cgroups.plugin/cgroup-name.sh
101 collectors/tc.plugin/tc-qos-helper.sh
collectors/apps.plugin/apps_plugin.c
+3
@@ -15,6 +15,9 @@ void netdata_cleanup_and_exit(int ret) {
15 exit(ret);
16 }
17
18 +void send_statistics( const char *action, const char *action_result, const char *action_data) {
19 + return;
20 +}
21 // callbacks required by popen()
22 void signals_block(void) {};
23 void signals_unblock(void) {};
collectors/cgroups.plugin/cgroup-network.c
+4
@@ -24,6 +24,10 @@ void netdata_cleanup_and_exit(int ret) {
24 exit(ret);
25 }
26
27 +void send_statistics( const char *action, const char *action_result, const char *action_data) {
28 + return;
29 +}
30 +
31 // callbacks required by popen()
32 void signals_block(void) {};
33 void signals_unblock(void) {};
collectors/freeipmi.plugin/freeipmi_plugin.c
+4
@@ -35,6 +35,10 @@ void netdata_cleanup_and_exit(int ret) {
35 exit(ret);
36 }
37
38 +void send_statistics( const char *action, const char *action_result, const char *action_data) {
39 + return;
40 +}
41 +
42 // callbacks required by popen()
43 void signals_block(void) {};
44 void signals_unblock(void) {};
daemon/Makefile.am
+11
@@ -2,8 +2,19 @@
2
3 AUTOMAKE_OPTIONS = subdir-objects
4 MAINTAINERCLEANFILES= $(srcdir)/Makefile.in
5 +CLEANFILES = \
6 + anonymous-statistics.sh \
7 + $(NULL)
8 +
9 +include $(top_srcdir)/build/subst.inc
10 +SUFFIXES = .in
11
12 dist_noinst_DATA = \
13 README.md \
14 config/README.md \
15 + anonymous-statistics.sh.in \
16 + $(NULL)
17 +
18 +dist_plugins_SCRIPTS = \
19 + anonymous-statistics.sh \
20 $(NULL)
daemon/anonymous-statistics.sh.in new
+194
@@ -0,0 +1,194 @@
1 +#!/usr/bin/env sh
2 +
3 +# Valid actions:
4 +
5 +# - FATAL - netdata exited due to a fatal condition
6 +# ACTION_RESULT -- program name and thread tag
7 +# ACTION_DATA -- fmt, args passed to fatal
8 +# - START - netdata started
9 +# ACTION_DATA -- nan
10 +# - EXIT - installation action
11 +# ACTION_DATA -- ret value of
12 +
13 +ACTION="${1}"
14 +ACTION_RESULT="${2}"
15 +ACTION_DATA="${3}"
16 +ACTION_DATA=$(echo "${ACTION_DATA}" | tr '"' "'")
17 +
18 +# -------------------------------------------------------------------------------------------------
19 +# check opt-out
20 +
21 +if [ -f "@configdir_POST@/.opt-out-from-anonymous-statistics" ]; then
22 + exit 0
23 +fi
24 +
25 +# -------------------------------------------------------------------------------------------------
26 +# detect the operating system
27 +
28 +OS_DETECTION="unknown"
29 +NAME="unknown"
30 +VERSION="unknown"
31 +VERSION_ID="unknown"
32 +ID="unknown"
33 +ID_LIKE="unknown"
34 +
35 +if [ -f "/etc/os-release" ]; then
36 + OS_DETECTION="/etc/os-release"
37 + eval "$(grep -E "^(NAME|ID|ID_LIKE|VERSION|VERSION_ID)=" </etc/os-release)"
38 +fi
39 +
40 +if [ "${NAME}" = "unknown" ] || [ "${VERSION}" = "unknown" ] || [ "${ID}" = "unknown" ]; then
41 + if [ -f "/etc/lsb-release" ]; then
42 + if [ "${OS_DETECTION}" = "unknown" ]; then OS_DETECTION="/etc/lsb-release"; else OS_DETECTION="Mixed"; fi
43 + DISTRIB_ID="unknown"
44 + DISTRIB_RELEASE="unknown"
45 + DISTRIB_CODENAME="unknown"
46 + eval "$(grep -E "^(DISTRIB_ID|DISTRIB_RELEASE|DISTRIB_CODENAME)=" </etc/lsb-release)"
47 + if [ "${NAME}" = "unknown" ]; then NAME="${DISTRIB_ID}"; fi
48 + if [ "${VERSION}" = "unknown" ]; then VERSION="${DISTRIB_RELEASE}"; fi
49 + if [ "${ID}" = "unknown" ]; then ID="${DISTRIB_CODENAME}"; fi
50 + elif [ -n "$(command -v lsb_release 2>/dev/null)" ]; then
51 + if [ "${OS_DETECTION}" = "unknown" ]; then OS_DETECTION="lsb_release"; else OS_DETECTION="Mixed"; fi
52 + if [ "${NAME}" = "unknown" ]; then NAME="$(lsb_release -is 2>/dev/null)"; fi
53 + if [ "${VERSION}" = "unknown" ]; then VERSION="$(lsb_release -rs 2>/dev/null)"; fi
54 + if [ "${ID}" = "unknown" ]; then ID="$(lsb_release -cs 2>/dev/null)"; fi
55 + fi
56 +fi
57 +
58 +# -------------------------------------------------------------------------------------------------
59 +# detect the kernel
60 +
61 +KERNEL_NAME="$(uname -s)"
62 +KERNEL_VERSION="$(uname -r)"
63 +ARCHITECTURE="$(uname -m)"
64 +
65 +# -------------------------------------------------------------------------------------------------
66 +# detect the virtualization
67 +
68 +VIRTUALIZATION="unknown"
69 +VIRT_DETECTION="none"
70 +
71 +if [ -n "$(command -v systemd-detect-virt 2>/dev/null)" ]; then
72 + VIRTUALIZATION="$(systemd-detect-virt)"
73 + VIRT_DETECTION="systemd-detect-virt"
74 +else
75 + if grep -q "^flags.*hypervisor" /proc/cpuinfo 2>/dev/null; then
76 + VIRTUALIZATION="hypervisor"
77 + VIRT_DETECTION="/proc/cpuinfo"
78 + fi
79 +fi
80 +
81 +# -------------------------------------------------------------------------------------------------
82 +# detect containers
83 +
84 +CONTAINER="none"
85 +CONT_DETECTION="none"
86 +
87 +IFS='(, ' read -r process _ </proc/1/sched
88 +if [ "${process}" = "netdata" ]; then
89 + CONTAINER="container"
90 + CONT_DETECTION="process"
91 +fi
92 +
93 +# ubuntu and debian supply /bin/running-in-container
94 +# https://www.apt-browse.org/browse/ubuntu/trusty/main/i386/upstart/1.12.1-0ubuntu4/file/bin/running-in-container
95 +if /bin/running-in-container >/dev/null 2>&1; then
96 + CONTAINER="container"
97 + CONT_DETECTION="/bin/running-in-container"
98 +fi
99 +
100 +# lxc sets environment variable 'container'
101 +#shellcheck disable=SC2154
102 +if [ -n "${container}" ]; then
103 + CONTAINER="lxc"
104 + CONT_DETECTION="containerenv"
105 +fi
106 +
107 +# docker creates /.dockerenv
108 +# http://stackoverflow.com/a/25518345
109 +if [ -f "/.dockerenv" ]; then
110 + CONTAINER="docker"
111 + CONT_DETECTION="dockerenv"
112 +fi
113 +
114 +# -------------------------------------------------------------------------------------------------
115 +# check netdata version
116 +
117 +if [ -z "${NETDATA_VERSION}" ]; then
118 + NETDATA_VERSION="uknown"
119 + netdata -V >/dev/null 2>&1 && NETDATA_VERSION="$(netdata -V 2>&1 | cut -d ' ' -f 2)"
120 +fi
121 +
122 +# -------------------------------------------------------------------------------------------------
123 +# check netdata unique id
124 +if [ -z "${NETDATA_REGISTRY_UNIQUE_ID}" ] ; then
125 + if [ -f "@registrydir_POST@/netdata.public.unique.id" ]; then
126 + NETDATA_REGISTRY_UNIQUE_ID="$(cat "@registrydir_POST@/netdata.public.unique.id")"
127 + else
128 + NETDATA_REGISTRY_UNIQUE_ID="unknown"
129 + fi
130 +fi
131 +
132 +
133 +# -------------------------------------------------------------------------------------------------
134 +# send the anonymous statistics to GA
135 +# https://developers.google.com/analytics/devguides/collection/protocol/v1/parameters
136 +if [ -n "$(command -v curl 2>/dev/null)" ]; then
137 + curl -X POST -Ss --max-time 2 \
138 + --data "v=1" \
139 + --data "tid=UA-64295674-3" \
140 + --data "aip=1" \
141 + --data "ds=shell" \
142 + --data-urlencode "cid=${NETDATA_REGISTRY_UNIQUE_ID}" \
143 + --data-urlencode "cs=${NETDATA_REGISTRY_UNIQUE_ID}" \
144 + --data "t=event" \
145 + --data "ni=1" \
146 + --data "an=anonymous-statistics" \
147 + --data-urlencode "av=${NETDATA_VERSION}" \
148 + --data-urlencode "ec=${ACTION}" \
149 + --data-urlencode "ea=${ACTION_RESULT}" \
150 + --data-urlencode "el=${ACTION_DATA}" \
151 + --data-urlencode "cd1=${NAME}" \
152 + --data-urlencode "cd2=${ID}" \
153 + --data-urlencode "cd3=${ID_LIKE}" \
154 + --data-urlencode "cd4=${VERSION}" \
155 + --data-urlencode "cd5=${VERSION_ID}" \
156 + --data-urlencode "cd6=${OS_DETECTION}" \
157 + --data-urlencode "cd7=${KERNEL_NAME}" \
158 + --data-urlencode "cd8=${KERNEL_VERSION}" \
159 + --data-urlencode "cd9=${ARCHITECTURE}" \
160 + --data-urlencode "cd10=${VIRTUALIZATION}" \
161 + --data-urlencode "cd11=${VIRT_DETECTION}" \
162 + --data-urlencode "cd12=${CONTAINER}" \
163 + --data-urlencode "cd13=${CONT_DETECTION}" \
164 + "https://www.google-analytics.com/collect" >/dev/null 2>&1
165 +else
166 + wget -q -O - --timeout=1 "https://www.google-analytics.com/collect?\
167 +&v=1\
168 +&tid=UA-64295674-3\
169 +&aip=1\
170 +&ds=shell\
171 +&cid=${NETDATA_REGISTRY_UNIQUE_ID}\
172 +&cs=${NETDATA_REGISTRY_UNIQUE_ID}\
173 +&t=event\
174 +&ni=1\
175 +&an=anonymous-statistics\
176 +&av=${NETDATA_VERSION}\
177 +&ec=${ACTION}\
178 +&ea=${ACTION_RESULT}\
179 +&el=${ACTION_DATA}\
180 +&cd1=${NAME}\
181 +&cd2=${ID}\
182 +&cd3=${ID_LIKE}\
183 +&cd4=${VERSION}\
184 +&cd5=${VERSION_ID}\
185 +&cd6=${OS_DETECTION}\
186 +&cd7=${KERNEL_NAME}\
187 +&cd8=${KERNEL_VERSION}\
188 +&cd9=${ARCHITECTURE}\
189 +&cd10=${VIRTUALIZATION}\
190 +&cd11=${VIRT_DETECTION}\
191 +&cd12=${CONTAINER}\
192 +&cd13=${CONT_DETECTION}\
193 +" > /dev/null 2>&1
194 +fi
daemon/common.h
+1
@@ -78,5 +78,6 @@ extern char *netdata_configured_varlib_dir;
78 extern char *netdata_configured_home_dir;
79 extern char *netdata_configured_host_prefix;
80 extern char *netdata_configured_timezone;
81 +extern int netdata_anonymous_statistics_enabled;
82
83 #endif /* NETDATA_COMMON_H */
daemon/daemon.h
+1
@@ -8,6 +8,7 @@ extern int become_user(const char *username, int pid_fd);
8 extern int become_daemon(int dont_fork, const char *user);
9
10 extern void netdata_cleanup_and_exit(int i);
11 +extern void send_statistics(const char *action, const char *action_result, const char *action_data);
12
13 extern char pidfile[];
14
daemon/main.c
+50
@@ -2,6 +2,8 @@
2
3 #include "common.h"
4
5 +int netdata_anonymous_statistics_enabled;
6 +
7 struct config netdata_config = {
8 .sections = NULL,
9 .mutex = NETDATA_MUTEX_INITIALIZER,
@@ -22,6 +24,8 @@ void netdata_cleanup_and_exit(int ret) {
24 error_log_limit_unlimited();
25 info("EXIT: netdata prepares to exit with code %d...", ret);
26
27 + send_statistics("EXIT", ret?"ERROR":"OK","-");
28 +
29 // cleanup/save the database and exit
30 info("EXIT: cleaning up the database...");
31 rrdhost_cleanup_all();
@@ -458,6 +462,7 @@ static void get_netdata_configured_variables() {
462 netdata_configured_plugins_dir_base = strdupz(config_get(CONFIG_SECTION_GLOBAL, "plugins directory", plugins_dirs));
463 quoted_strings_splitter(netdata_configured_plugins_dir_base, plugin_directories, PLUGINSD_MAX_DIRECTORIES, config_isspace);
464 netdata_configured_plugins_dir = plugin_directories[0];
465 +
466 }
467
468 // ------------------------------------------------------------------------
@@ -581,6 +586,7 @@ void set_global_environment() {
586 setenv("NETDATA_UPDATE_EVERY", b, 1);
587 }
588
589 + setenv("NETDATA_VERSION" , program_version, 1);
590 setenv("NETDATA_HOSTNAME" , netdata_configured_hostname, 1);
591 setenv("NETDATA_CONFIG_DIR" , verify_required_directory(netdata_configured_user_config_dir), 1);
592 setenv("NETDATA_USER_CONFIG_DIR" , verify_required_directory(netdata_configured_user_config_dir), 1);
@@ -643,6 +649,47 @@ static int load_netdata_conf(char *filename, char overwrite_used) {
649 return ret;
650 }
651
652 +
653 +void send_statistics( const char *action, const char *action_result, const char *action_data) {
654 + static char *as_script;
655 + if (netdata_anonymous_statistics_enabled == -1) {
656 + char *optout_file = mallocz(sizeof(char) * (strlen(netdata_configured_user_config_dir) +strlen(".opt-out-from-anonymous-statistics") + 2));
657 + sprintf(optout_file, "%s/%s", netdata_configured_user_config_dir, ".opt-out-from-anonymous-statistics");
658 + if (likely(access(optout_file, R_OK) != 0)) {
659 + as_script = mallocz(sizeof(char) * (strlen(netdata_configured_plugins_dir) + strlen("anonymous-statistics.sh") + 2));
660 + sprintf(as_script, "%s/%s", netdata_configured_plugins_dir, "anonymous-statistics.sh");
661 + if (unlikely(access(as_script, R_OK) != 0)) {
662 + netdata_anonymous_statistics_enabled=0;
663 + info("Anonymous statistics script %s not found.",as_script);
664 + freez(as_script);
665 + } else {
666 + netdata_anonymous_statistics_enabled=1;
667 + }
668 + } else {
669 + netdata_anonymous_statistics_enabled = 0;
670 + as_script = NULL;
671 + }
672 + freez(optout_file);
673 + }
674 + if(!netdata_anonymous_statistics_enabled) return;
675 + if (!action) return;
676 + if (!action_result) action_result="";
677 + if (!action_data) action_data="";
678 + char *command_to_run=mallocz(sizeof(char) * (strlen(action) + strlen(action_result) + strlen(action_data) + strlen(as_script) + 10));
679 + pid_t command_pid;
680 +
681 + sprintf(command_to_run,"%s '%s' '%s' '%s'", as_script, action, action_result, action_data);
682 + info("%s", command_to_run);
683 +
684 + FILE *fp = mypopen(command_to_run, &command_pid);
685 + if(fp) {
686 + char buffer[100 + 1];
687 + while (fgets(buffer, 100, fp) != NULL);
688 + mypclose(fp, command_pid);
689 + }
690 + freez(command_to_run);
691 +}
692 +
693 int main(int argc, char **argv) {
694 int i;
695 int config_loaded = 0;
@@ -915,6 +962,9 @@ int main(int argc, char **argv) {
962 get_netdata_configured_variables();
963 set_global_environment();
964
965 + netdata_anonymous_statistics_enabled=-1;
966 + send_statistics("START","-", "-");
967 +
968 // work while we are cd into config_dir
969 // to allow the plugins refer to their config
970 // files using relative filenames
daemon/main.h
+1
@@ -43,5 +43,6 @@ struct netdata_static_thread {
43 extern void cancel_main_threads(void);
44 extern int killpid(pid_t pid, int signal);
45 extern void netdata_cleanup_and_exit(int ret) NORETURN;
46 +extern void send_statistics(const char *action, const char *action_result, const char *action_data);
47
48 #endif /* NETDATA_MAIN_H */
docs/anonymous-statistics.md new
+62
@@ -0,0 +1,62 @@
1 +# Anonymous Statistics
2 +
3 +From Netdata v1.12 and above, anonymous usage information is collected by default and send to Google Analytics.
4 +The statistics calculated from this information will be used for:
5 +
6 +1. **Quality assurance**, to help us understand if netdata behaves as expected and help us identify repeating issues for certain distributions or environment.
7 +
8 +2. **Usage statistics**, to help us focus on the parts of netdata that are used the most, or help us identify the extend our development decisions influence the community.
9 +
10 +Information is sent to Netdata via two different channels:
11 +- Google Tag Manager is used when an agent's dashboard is accessed.
12 +- The script `anonymous-statistics.sh` is executed by the Netdata daemon, when Netdata starts, stops cleanly, or fails.
13 +
14 +Both methods are controlled via the same [opt-out mechanism](#opt-out)
15 +
16 +## Google tag manager
17 +
18 +Google tag manager (GTM) is the recommended way of collecting statistics for new implementations using GA. Unlike the older API, the logic of when to send information to GA and what information to send is controlled centrally.
19 +
20 +We have configured GTM to trigger the tag only when the variable `anonymous_statistics` is true. The value of this variable is controlled via the [opt-out mechanism](#opt-out).
21 +
22 +To ensure anonymity of the stored information, we have configured GTM's GA variable "Fields to set" as follows:
23 +
24 +|Field Name|Value
25 +|---|---
26 +|page|netdata-dashboard
27 +|hostname|dashboard.my-netdata.io
28 +|anonymizeIp|true
29 +|title|netdata dashboard
30 +|campaignSource|{{machine_guid}}
31 +|campaignMedium|web
32 +|referrer|http://dashboard.my-netdata.io
33 +|Page URL|http://dashboard.my-netdata.io/netdata-dashboard
34 +|Page Hostname|http://dashboard.my-netdata.io
35 +|Page Path|/netdata-dashboard
36 +|location|http://dashboard.my-netdata.io
37 +
38 +In addition, the netdata-generated unique machine guid is sent to GA via a custom dimension.
39 +You can verify the effect of these settings by examining the GA `collect` request parameters.
40 +
41 +The only thing that's impossible for us to prevent from being **sent** is the URL in the "Referrer" Header of the browser request to GA. However, the settings above ensure that all **stored** URLs and host names are anonymized.
42 +
43 +## Anonymous Statistics Script
44 +
45 +Every time the daemon is started or stopped and every time a fatal condition is encountered, netdata uses the anonymous statistics script to collect system information and send it to GA via an http call. The information collected for all events is:
46 + - Netdata version
47 + - OS name, version, id, id_like
48 + - Kernel name, version, architecture
49 + - Virtualization technology
50 + - Containerization technology
51 +
52 +Furthermore, the FATAL event sends the Netdata process & thread name, along with the source code function, source code filename and source code line number of the fatal error.
53 +
54 +To see exactly what and how is collected, you can review the script template `daemon/anonymous-statistics.sh.in`. The template is converted to a bash script called `anonymous-statistics.sh`, installed under the Netdata `plugins directory`, which is usually `/usr/libexec/netdata/plugins.d`.
55 +
56 +## Opt-Out
57 +
58 +To opt-out from sending anonymous statistics, you can create a file called `.opt-out-from-anonymous-statistics` under the user configuration directory (usually `/etc/netdata`). The effect of creating the file is the following:
59 +- The daemon will never execute the anonymous statistics script
60 +- The anonymous statistics script will exit immediately if called via any other way (e.g. shell)
61 +- The Google Tag Manager Javascript snippet will remain in the page, but the linked tag will not be fired. The effect is that no data will ever be sent to GA.
62 +
docs/generator/buildyaml.sh
+2 -1
@@ -116,6 +116,7 @@ navpart 1 . README "About"
116
117 echo -ne " - 'docs/Demo-Sites.md'
118 - 'docs/netdata-security.md'
119 + - 'docs/anonymous-statistics.md'
120 - 'docs/Donations-netdata-has-received.md'
121 - 'docs/a-github-star-is-important.md'
122 - REDISTRIBUTED.md
@@ -229,7 +230,7 @@ echo -ne "- Hacking netdata:
230 - 'docs/Netdata-Security-and-Disclosure-Information.md'
231 - CONTRIBUTORS.md
232 "
232 -navpart 2 makeself "" "" 4
233 +navpart 2 packaging/makeself "" "" 4
234 navpart 2 libnetdata "" "libnetdata" 4
235 navpart 2 contrib
236 navpart 2 tests "" "" 2
docs/netdata-security.md
+13 -1
@@ -149,7 +149,9 @@ Of course, there are many more methods you could use to protect Netdata:
149
150 - install all your Netdata in **headless data collector** mode, forwarding all metrics in real-time to a master Netdata server, which will be protected with authentication using an nginx server running locally at the master Netdata server. This requires more resources (you will need a bigger master Netdata server), but does not require any firewall changes, since all the slave Netdata servers will not be listening for incoming connections.
151
152 -## Registry or how to not send any information to a third party server
152 +## Anonymous Statistics
153 +
154 +### Registry or how to not send any information to a third party server
155
156 The default configuration uses a public registry under registry.my-netdata.io (more information about the registry here: [mynetdata-menu-item](../registry/) ). Please be aware that if you use that public registry, you submit the following information to a third party server:
157 - The url where you open the web-ui in the browser (via http request referer)
@@ -157,6 +159,16 @@ The default configuration uses a public registry under registry.my-netdata.io (m
159
160 If sending this information to the central Netdata registry violates your security policies, you can configure Netdat to [run your own registry](../registry/#run-your-own-registry).
161
162 +### Opt out of anonymous statistics
163 +
164 +Starting with v1.12 Netdata also collects [anonymous statistics](anonymous-statistics.md) on certain events for:
165 +
166 +1. **Quality assurance**, to help us understand if netdata behaves as expected and help us identify repeating issues for certain distributions or environments.
167 +
168 +2. **Usage statistics**, to help us focus on the parts of Netdata that are used the most, or help us identify the extent our development decisions influence the community.
169 +
170 +To opt-out from sending anonymous statistics, you can create a file called `.opt-out-from-anonymous-statistics` under the user configuration directory (usually `/etc/netdata`).
171 +
172 ## Netdata directories
173
174 path|owner|permissions| netdata |comments|
docs/privacy-policy.md
+38 -18
@@ -1,12 +1,12 @@
1 -# Privacy policy
1 +# Privacy Policy
2
3 ## 1. Preamble
4
5 -This Privacy Policy explains the collection, use, processing, transferring and disclosure of personal information by Netdata, Inc (“ND” or “Netdata”), a Delaware corporation.
5 +This Privacy Policy explains the collection, use, processing, transferring and disclosure of personal information by Netdata, Inc (“ND” or “Netdata”), a Delaware Corporation.
6
7 -This Privacy Policy is incorporated into and made part of Netdata Master Terms of Use (“Master Terms”) located [here](terms-of-use.md).
7 +This Privacy Policy is incorporated into and made part of the Netdata Master Terms of Use (“Master Terms”) located [here](terms-of-use.md).
8
9 -Unless otherwise noted on a particular website or service hosted by Netdata, this Privacy Policy applies to your use of all websites that Netdata operates. These include https://netdata.io and https://netdata.cloud, together with all other subdomains thereof, (collectively, the “Websites”). This Privacy Policy also applies to all products, information, and services provided through the Websites, including without limitation the license chooser, legal tools, the ND Login Services (defined below), and the ND Global Network community website (together with the Websites, the “Services”).
9 +Unless otherwise noted on a particular website or service hosted by Netdata, this Privacy Policy applies to your use of all websites that Netdata operates. These include https://my-netdata.io and https://netdata.cloud, together with all other subdomains thereof, (collectively, the “Websites”). This Privacy Policy also applies to all products, information, and services provided through the Websites, including without limitation the ND agent, the ND registry, the ND hub and the ND cloud website (together with the Websites, the “Services”).
10
11 In addition, supplemental Privacy Policy terms (“Supplemental Privacy Policy Terms”) may apply to a particular Service. All such Supplemental Privacy Policy Terms will be accessible for you to read either within, or through your use of, that particular Service.
12
@@ -26,28 +26,52 @@ As used in this policy, “personal information” means information that would
26
27 ND collects and uses personal information in the following ways:
28
29 -Website and Fundraising Analytics: When you visit our Websites and use our Services, ND collects some information about your activities through tools such as Google Analytics. The type of information that we collect focuses on general information such as country or city where you are located, pages visited, time spent on pages, heat-map of visitors’ activity on the site, information about the browser you are using, etc. ND collects and uses this information pursuant to our legitimate interest in enhancing the security and utility of our Services. The information we gather and process is used in the aggregate to spot trends without deliberately identifying individuals, except in cases where you engage in a transaction with Netdata by donating money, or purchasing services. In those cases, ND retains certain information about your visit to the Services pursuant to its legitimate interest in understanding its community of supporters for fundraising purposes, and this information is stored in connection with other personal information you provide to ND.
29 +Website and Analytics: When you visit our Websites and use our Services, ND collects some information about your activities through tools such as Google Analytics. The type of information that we collect focuses on general information such as country or city where you are located, pages visited, time spent on pages, heat-map of visitors’ activity on the site, information about the browser you are using, etc. ND collects and uses this information pursuant to our legitimate interest in enhancing the security and utility of our Services. The information we gather and process is used in the aggregate to spot trends without deliberately identifying individuals.
30
31 -Note that you can learn about Google’s practices in connection with its analytics services and how to opt out of it by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout. If you would like to opt out of ND’s fundraising analytics, please contact legal@netdata.cloud with your request.
31 +Note that you can learn about Google’s practices in connection with its analytics services and how to opt out of it by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.
32
33 Information from Cookies: We and our service providers (for example, Google Analytics as described above) may collect information using cookies or similar technologies for the purposes described above and below. Cookies are pieces of information that are stored by your browser on the hard drive or memory of your computer or other Internet access device. Cookies may enable us to personalize your experience on the Services, maintain a persistent session, passively collect demographic information about your computer, and monitor advertisements and other activities. The Websites may use different kinds of cookies and other types of local storage (such as browser-based or plugin-based local storage).
34
35 -Log-In Services: When you register to obtain a user account on any of the Services (any such person, a “Registered User”), including but not limited to the NDID service, you will be asked to provide personal information to create your account and establish a password and profile. ND collects and uses this personal information pursuant to its legitimate interest in establishing and maintaining your account providing you with the features we provide Registered Users. We may use your email address to contact you regarding changes to this policy or other applicable policies. The name or nickname you provide in connection with your account may be used to attribute you in connection with any content you submit to any Service. In addition, whenever you use a ND Login Service to log into a Website or use the Services, our servers keep a plain text log of the Websites you visit and when you visit them.
35 +
36 +ND Registry: The global registry, together with certain browser features, allow netdata to provide unified cross-server dashboards, via the `my-netdata` menu. The menu lists the netdata servers you have visited. For example, when you jump from server to server using the `my-netdata` menu, several session settings (like the currently viewed charts, the current zoom and pan operations on the charts, etc.) are propagated to the new server, so that the new dashboard will come with exactly the same view. The global registry keeps track of 3 entities:
37 +
38 +1. **machines**: i.e. the netdata installations (a random GUID generated by each netdata the first time it starts; we call this **machine_guid**). For each netdata installation (each `machine_guid`) the registry keeps track of the different URLs it is accessed.
39 +
40 +2. **persons**: i.e. the web browsers accessing the netdata installations (a random GUID generated by the registry the first time it sees a new web browser; we call this **person_guid**). For each person, the registry keeps track of the netdata installations it has accessed and their URLs.
41 +
42 +3. **URLs** of netdata installations (as seen by the web browsers). For each URL, the registry keeps the URL and nothing more. Each URL is linked to *persons* and *machines*. The only way to find a URL is to know its **machine_guid** or have a **person_guid** it is linked to it.
43 +
44 +If sending this information is against your policies, you can [run your own registry](../registry/#run-your-own-registry).
45 +Note that ND versions with the 'Sign in' feature of the ND Cloud do not use the global registry.
46 +
47 +ND Cloud: When you sign up to obtain a user account via the 'Sign in' link on the ND agent user interface, ND is granted access to personal information in the user profile of the authentication provider you choose (e.g. GitHub or Google). ND collects and uses this personal information pursuant to its legitimate interest in establishing and maintaining your account providing you with the features we provide Registered Users. We may use your email address to contact you regarding changes to this policy or other applicable policies. The login name or email address of your profile may be used to attribute you in connection with any content you submit to any Service.
48 +
49 +Anonymous Usage Statistics: From Netdata v1.12 and above, anonymous usage information is collected by default on certain events of the ND daemon and send to Google Analytics. Every time the daemon is started or stopped and every time a fatal condition is encountered, netdata collects system information and sends it to GA via an http call. The information collected for all events is:
50 + - Netdata version
51 + - OS name, version, id, id_like
52 + - Kernel name, version, architecture
53 + - Virtualization technology
54 + - Containerization technology
55 +Furthermore, the FATAL event sends the Netdata process & thread info, along with the file, function and line of the fatal error.
56 +
57 +The statistics calculated from this information are used for:
58 +
59 +1. **Quality assurance**, to help us understand if netdata behaves as expected and help us identify repeating issues for certain distributions or environment.
60 +
61 +2. **Usage statistics**, to help us focus on the parts of netdata that are used the most, or help us identify the extend our development decisions influence the community.
62 +
63 +To opt-out from sending anonymous statistics, you can create reate a file called `.opt-out-from-anonymous-statistics` under the user configuration directory (usually `/etc/netdata`).
64
65 Emails and Newsletters: When you sign up to receive updates from Netdata or otherwise subscribe to one of our mailing lists, you will be asked to provide some personal information. ND collects and uses this personal information pursuant to its legitimate interest in providing news and updates to, and collaborating with, its supporters and volunteers.
66
67 Email Analytics: When you receive communications from ND after signing up for the ND newsletter, campaign updates, or other ongoing email communications from ND, we may use analytics to track whether you open the mail, click on the links, and otherwise interact with what we send. You may opt out of this tracking by choosing to get plain-text emails from ND. ND collects and uses this personal information pursuant to its legitimate interest in understanding the interests of its community of supporters and volunteers in order to provide more relevant news and updates.
68
41 -Donations: When you donate money to Netdata or purchase Services, you will be asked to provide personal information, including payment information. ND collects and uses this personal information pursuant to its legitimate interest in raising funds to ensure the sustainability of our nonprofit organization and, where applicable, to provide you with the merchandise, event, or program you purchased.
42 -
69 Other Voluntarily Provided Information: When you provide feedback to Netdata, sign a petition distributed by ND, or otherwise submit personal information to Netdata, ND collects and uses this personal information pursuant to its legitimate interest in better understanding our community of supporters and volunteers and in furtherance of the particular program or activity to which you provided feedback or other input.
70
71 ## 4. Retention of Personal Information
72
73 The majority of the personal information collected and used as explained in Section 3 above is aggregated and stored in a central database provided by a third party service provider. ND aggregates this data pursuant to its legitimate interest in having information stored in a single location to minimize complexity, increase consistency in internal practices, better understand its community of supporters and volunteers, and enhance the security of the data.
74
49 -ND erases the web browser logs described above on a regular, rolling basis.
50 -
75 ## 5. Access to Your Personal Information
76
77 You are generally entitled to access personal information that Netdata holds and to have inaccurate data corrected or removed to the extent ND still maintains it. In certain circumstances, you also may have the right to object for legitimate reasons to the processing or transfer of personal information. If you wish to exercise any of these rights, please write to legal@netdata.cloud explaining your request.
@@ -56,15 +80,13 @@ You are generally entitled to access personal information that Netdata holds and
80
81 ND does not disclose personal information to third parties except as specified elsewhere in this policy and in the following instances:
82
59 -Netdata may share personal information with our contractors and service providers in order to undertake the activities described in Section 3.
60 -
83 We may disclose your personal information to third parties in a good faith belief that such disclosure is reasonably necessary to (a) take action regarding suspected illegal activities; (b) enforce or apply our Master Terms and this Privacy Policy; (c) enforce our Charter, including the Code of Conduct and policies contained and incorporated therein, or (d) comply with legal process, such as a search warrant, subpoena, statute, or court order.
84
85 ## 7. Security of Your Personal Information
86
65 -Netdata has implemented reasonable physical, technical, and organizational security measures for personal information that Netdata processes against accidental or unlawful destruction, or accidental loss, alteration, unauthorized disclosure or access, in compliance with applicable law. However, no website can fully eliminate security risks. Third parties may circumvent our security measures to unlawfully intercept or access transmissions or private communications. If any data breach occurs, we will post a reasonably prominent notice to the Websites and comply with all other applicable data privacy requirements including, when required, personal notice to you if you have provided and we have maintained an email address for you.
87 +Netdata has implemented reasonable physical, technical, and organizational security measures for personal information that Netdata processes against accidental or unlawful destruction, or accidental loss, alteration, unauthorized disclosure or access, in compliance with applicable law. However, no website can fully eliminate security risks. If any data breach occurs, we will post a reasonably prominent notice to the Websites and comply with all other applicable data privacy requirements including, when required, personal notice to you if you have provided and we have maintained an email address for you.
88
67 -The ND Login Services account systems have security risks in addition to those described above. Among other things, they are vulnerable to DNS attacks, and using any ND Login Service may increase the risk of phishing.
89 +The ND Cloud Services have security risks in addition to those described above. Among other things, they are vulnerable to DNS attacks, and using any ND Cloud Service may increase the risk of phishing.
90
91 ## 8. Children
92
@@ -82,14 +104,12 @@ The Services may provide links to a wide variety of third party websites. You sh
104
105 If you are accessing or using the Services in regions with laws governing data collection, processing, transfer and use, please note that when we use and share your data as specified in this policy, we may transfer your information to recipients in countries other than the country in which the information was originally collected. Those countries may not have the same data protection laws as the country in which you initially provided the information.
106
85 -The Services are currently hosted in the United States and the United Kingdom, which means your personal information may be located on servers in the United States and/or the United Kingdom. The majority of contractors that Netdata is using as of the effective date of this Privacy Policy are located in the United States and in Canada, but this may change from time to time.
86 -
107 Data transferred from the European Union to the United States or outside the European Union will be made on the grounds of a certification to the E.U./U.S. Privacy Shield regime and/or a data transfer agreement based on the Standard Contractual Clauses approved of by the European Commission respectively, consistent with applicable data privacy requirements.
108
109 ## 12. Changes to this Privacy Policy
110
111 We may occasionally update this Privacy Policy. When we do, we will provide you with notice of such update through (at a minimum) a reasonably prominent notice on the Websites and Services, and will revise the Effective Date below. We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting, using, processing and transferring the personal information we collect.
112
93 -***Effective Date: 10 November 2018.***
113 +Effective Date: 8 January 2019.
114
115 [![analytics](https://www.google-analytics.com/collect?v=1&aip=1&t=pageview&_s=1&ds=github&dr=https%3A%2F%2Fgithub.com%2Fnetdata%2Fnetdata&dl=https%3A%2F%2Fmy-netdata.io%2Fgithub%2Fdocs%2Fprivacy-policy&_u=MAC~&cid=5792dfd7-8dc4-476b-af31-da2fdb9f93d2&tid=UA-64295674-3)]()
docs/terms-of-use.md
+4 -5
@@ -1,12 +1,11 @@
1 -# Terms of use
2 -
3 -Netdata Terms of Use for the sites https://my-netdata.io and https://netdata.cloud and their subdomains. For the Netdata agent and the included redistributed software terms of use, refer to [Redistributed software](../REDISTRIBUTED.md)
1 +# Terms of Use
2
3 +Netdata Master Terms of Use
4 Effective as of 25 May 2018
5
6 ## 1. General Information Regarding These Terms of Use
7
9 -Master terms: Welcome, and thank you for your interest in Netdata (“Netdata,” “ND,” “we,” “our,” or “us”). Unless otherwise noted on a particular site or service, these master terms of use (“Master Terms”) apply to your use of all of the websites that Netdata Corporation operates. These include https://my-netdata.io and https://netdata.cloud, together with all other subdomains thereof, (collectively, the “Websites”). The Master Terms also apply to all products, information, and services provided through the Websites, such as the NDID Login Service.
8 +Master terms: Welcome, and thank you for your interest in Netdata (“Netdata, Inc.” “ND,” “we,” “our,” or “us”). Unless otherwise noted on a particular site or service, these master terms of use (“Master Terms”) apply to your use of all of the websites that Netdata Corporation operates. These include https://my-netdata.io and https://netdata.cloud, together with all other subdomains thereof, (collectively, the “Websites”). The Master Terms also apply to all products, information, and services provided through the Websites, such as the NDID Login Service.
9
10 Additional terms: In addition to the Master Terms, your use of any Services may also be subject to specific terms applicable to a particular Service (“Additional Terms”). If there is any conflict between the Additional Terms and the Master Terms, then the Additional Terms apply in relation to the relevant Service.
11
@@ -38,7 +37,7 @@ Provided as-is: You acknowledge that Netdata does not make any representations o
37
38 You agree that you are solely responsible for your reuse of Content made available through the Services, including providing proper attribution. You should review the terms of the applicable license before you use the Content so that you know what you can and cannot do.
39
41 -Licensing: ND-Owned Content: Other than the text of Netdata licenses, CC licenses, and other legal tools and the text of the deeds for all legal tools (all of which are made available under the CC Public Domain Dedication), Netdata trademarks (subject to the Trademark Policy), and the software code, all Content on the Websites is licensed under the Creative Commons Attribution 4.0 license, unless otherwise marked. See the ND Policies page for more information.
40 +Licensing: ND-Owned Content: Other than the text of Netdata licenses, ND licenses, and other legal tools and the text of the deeds for all legal tools, Netdata trademarks (subject to the Trademark Policy), and the software code, all Content on the Websites is licensed under the Creative Commons Attribution 4.0 license, unless otherwise marked. See the ND Policies page for more information.
41
42 ND-Owned Code: All of CC’s software code is free software; please check our code repository for the specific license on software you want to reuse.
43
libnetdata/libnetdata.h
+1 -1
@@ -283,8 +283,8 @@ extern void recursive_config_double_dir_load(
283
284
285 extern void netdata_cleanup_and_exit(int ret) NORETURN;
286 +extern void send_statistics(const char *action, const char *action_result, const char *action_data);
287 extern char *netdata_configured_host_prefix;
287 -
288 #include "os.h"
289 #include "storage_number/storage_number.h"
290 #include "threads/threads.h"
libnetdata/log/log.c
+7
@@ -1,5 +1,6 @@
1 // SPDX-License-Identifier: GPL-3.0-or-later
2
3 +#include <daemon/main.h>
4 #include "../libnetdata.h"
5
6 int web_server_is_multithreaded = 1;
@@ -400,6 +401,12 @@ void fatal_int( const char *file, const char *function, const unsigned long line
401
402 log_unlock();
403
404 + static char action_data[60];
405 + snprintfz(action_data, 60, "%04lu@%-10.10s:%-15.15s", line, file, function);
406 + static char action_result[60];
407 + snprintfz(action_result, 60, "%s:%s",program_name, netdata_thread_tag());
408 + send_statistics("FATAL", action_result, action_data);
409 +
410 netdata_cleanup_and_exit(1);
411 }
412
libnetdata/log/log.h
+1
@@ -85,6 +85,7 @@ static inline void debug_dummy(void) {}
85 #define error(args...) error_int("ERROR", __FILE__, __FUNCTION__, __LINE__, ##args)
86 #define fatal(args...) fatal_int(__FILE__, __FUNCTION__, __LINE__, ##args)
87
88 +extern void send_statistics(const char *action, const char *action_result, const char *action_data);
89 extern void debug_int( const char *file, const char *function, const unsigned long line, const char *fmt, ... ) PRINTFLIKE(4, 5);
90 extern void info_int( const char *file, const char *function, const unsigned long line, const char *fmt, ... ) PRINTFLIKE(4, 5);
91 extern void error_int( const char *prefix, const char *file, const char *function, const unsigned long line, const char *fmt, ... ) PRINTFLIKE(5, 6);
packaging/installer/functions.sh
+4 -2
@@ -392,8 +392,10 @@ iscontainer() {
392 IFS='(),#:' read name pid th threads
393 echo $pid
394 })
395 - pid=$((pid + 0))
396 - [ ${pid} -ne 1 ] && return 0
395 + if [ ! -z "${pid}" ]; then
396 + pid=$(( pid + 0 ))
397 + [ ${pid} -gt 1 ] && return 0
398 + fi
399
400 # lxc sets environment variable 'container'
401 [ ! -z "${container}" ] && return 0
registry/registry.c
+2 -2
@@ -132,9 +132,9 @@ int registry_request_hello_json(RRDHOST *host, struct web_client *w) {
132 registry_json_header(host, w, "hello", REGISTRY_STATUS_OK);
133
134 buffer_sprintf(w->response.data,
135 - ",\n\t\"registry\": \"%s\",\n\t\"cloud_base_url\": \"%s\"",
135 + ",\n\t\"registry\": \"%s\",\n\t\"cloud_base_url\": \"%s\",\n\t\"anonymous_statistics\": %s",
136 registry.registry_to_announce,
137 - registry.cloud_base_url);
137 + registry.cloud_base_url, netdata_anonymous_statistics_enabled?"true":"false");
138
139 registry_json_footer(w);
140 return 200;
web/gui/dashboard.js
+1 -1
@@ -9742,7 +9742,7 @@ NETDATA.registry = {
9742 NETDATA.registry.cloudBaseURL = data.cloud_base_url;
9743 NETDATA.registry.machine_guid = data.machine_guid;
9744 NETDATA.registry.hostname = data.hostname;
9745 -
9745 + if (data.anonymous_statistics) dataLayer.push({"anonymous_statistics" : "true", "machine_guid" : data.machine_guid});
9746 NETDATA.registry.access(2, function (person_urls) {
9747 NETDATA.registry.parsePersonUrls(person_urls);
9748
web/gui/index.html
+7
@@ -2,6 +2,13 @@
2 <!-- SPDX-License-Identifier: GPL-3.0-or-later -->
3 <html lang="en">
4 <head>
5 + <script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':
6 + new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],
7 + j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src=
8 + 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);
9 + })(window,document,'script','dataLayer','GTM-N6CBMJD');
10 + dataLayer.push({"anonymous_statistics" : "false"});
11 + </script>
12 <title>netdata dashboard</title>
13 <meta name="application-name" content="netdata">
14
web/gui/src/dashboard.js/registry.js
+1 -1
@@ -68,7 +68,7 @@ NETDATA.registry = {
68 NETDATA.registry.cloudBaseURL = data.cloud_base_url;
69 NETDATA.registry.machine_guid = data.machine_guid;
70 NETDATA.registry.hostname = data.hostname;
71 -
71 + if (data.anonymous_statistics) dataLayer.push({"anonymous_statistics" : "true", "machine_guid" : data.machine_guid});
72 NETDATA.registry.access(2, function (person_urls) {
73 NETDATA.registry.parsePersonUrls(person_urls);
74