Update unbound module documenttion with troubleshooting section. (#5528)
Austin S. Hemmelgarn committed
Feb 28, 2019 at 13:41 UTC
7938af8e6c6570e1def6baa001fca72f84a40330
1 file changed
+27
-1
collectors/python.d.plugin/unbound/README.md
+27
-1
@@ -34,7 +34,7 @@ If extended stats are enabled, also provides:
34
* DNSCrypt Shared Secret Cache
35
* DNSCrypt Nonce Cache
36
37
-### configuration
37
+### Configuration
38
39
Unbound must be manually configured to enable the remote-control protocol.
40
Check the Unbound documentation for info on how to do this. Additionally,
@@ -73,6 +73,32 @@ local:
73
While it's a bit more complicated to set up correctly, it is recommended
74
that you use a UNIX socket as it provides far better performance.
75
76
+### Troubleshooting
77
+
78
+If you've configured the module and can't get it to work, make sure and
79
+check all of the following:
80
+
81
+* If you're using autodetection, double check that your `unbound.conf`
82
+ file is actually using spaces instead of tabs, and that appropriate
83
+ indentation is present. Most Linux distributions ship a default config
84
+ for Unbound that uses tabs, and the plugin can't read such a config file
85
+ correctly. Also, make sure this file is actually readable by Netdata.
86
+* Ensure that the control protocol is actually configured correctly.
87
+ You can check this quickly by running `unbound-control stats_noreset`
88
+ as root, which should print out a bunch of info about the internal
89
+ statistics of the server. If this returns an error, you don't have
90
+ the control protocol set up correctly.
91
+* If using the regular control interface, make sure that the certificate
92
+ and key file you have configured in `unbound.conf` are readable by
93
+ Netdata. In general, it's preferred to use ACL's on the files to
94
+ provide the required permissions.
95
+* If using a UNIX socket, make sure that the socket is both readable
96
+ _and_ writable by Netdata. Just like with the regular control
97
+ interface, it's preferred to use ACL's to provide these permissions.
98
+* Make sure that SELinux, Apparmor, or any other mandatory access control
99
+ system isn't interfering with the access requirements mentioned above.
100
+ In some cases, you may have to add a local rule to allow this access.
101
+
102
---
103
104
[]()