Disable python sudo modules by default (#4477)
* adaptec_raid: check if `arcconf` is available first * adaptec_raid: disable by default and update docs * megacli: disable by default and update docs * samba: disable by default and update docs * samba megacli adaptec readme fix * adaptec readme fix
Ilya Mashchenko committed
Oct 26, 2018 at 08:57 UTC
c6cce6bd2accec27a61243e1ffa38826ac2a4892
8 files changed
+70
-28
collectors/python.d.plugin/adaptec_raid/README.md
+21
-2
@@ -3,7 +3,9 @@
3
Module collects logical and physical devices health metrics.
4
5
**Requirements:**
6
- * `netdata` user needs to be able to sudo the `arcconf` program without password
6
+* `arcconf` program
7
+* `sudo` program
8
+* `netdata` user needs to be able to sudo the `arcconf` program without password
9
10
To grab stats it executes:
11
* `sudo -n arcconf GETCONFIG 1 LD`
@@ -20,7 +22,24 @@ It produces:
22
23
4. **Physical Device Temperature**
24
23
-Screenshot:
25
+### prerequisite
26
+This module uses `arcconf` which can only be executed by root. It uses
27
+`sudo` and assumes that it is configured such that the `netdata` user can
28
+execute `arcconf` as root without password.
29
+
30
+Add to `sudoers`:
31
+
32
+ netdata ALL=(root) NOPASSWD: /path/to/arcconf
33
+
34
+### configuration
35
+
36
+ **adaptec_raid** is disabled by default. Should be explicitly enabled in `python.d.conf`.
37
+
38
+```yaml
39
+adaptec_raid: yes
40
+```
41
+
42
+#### Screenshot:
43
44

45
collectors/python.d.plugin/adaptec_raid/adaptec_raid.chart.py
+7
-5
@@ -12,6 +12,8 @@ from bases.FrameworkServices.ExecutableService import ExecutableService
12
from bases.collection import find_binary
13
14
15
+disabled_by_default = True
16
+
17
update_every = 5
18
19
ORDER = [
@@ -158,6 +160,11 @@ class Service(ExecutableService):
160
return self._get_raw_data(command=command, stderr=stderr)
161
162
def check(self):
163
+ arcconf = find_binary(ARCCONF)
164
+ if not arcconf:
165
+ self.error('can\'t locate "{0}" binary'.format(ARCCONF))
166
+ return False
167
+
168
sudo = find_binary(SUDO)
169
if self.use_sudo:
170
if not sudo:
@@ -168,11 +175,6 @@ class Service(ExecutableService):
175
self.error(' '.join(err))
176
return False
177
171
- arcconf = find_binary(ARCCONF)
172
- if not arcconf:
173
- self.error('can\'t locate "{0}" binary'.format(ARCCONF))
174
- return False
175
-
178
if self.use_sudo:
179
self.arcconf = SudoArcconf(arcconf, sudo)
180
else:
collectors/python.d.plugin/adaptec_raid/adaptec_raid.conf
-4
@@ -53,7 +53,3 @@
53
# retries: 60 # the JOB's number of restoration attempts
54
# autodetection_retry: 0 # the JOB's re-check interval in seconds
55
# ----------------------------------------------------------------------
56
-
57
-# IMPORTANT
58
-# The netdata user needs to be able to sudo the arcconf program without password:
59
-# netdata ALL=(root) NOPASSWD: /path/to/arcconf
collectors/python.d.plugin/megacli/README.md
+21
-1
@@ -3,6 +3,8 @@
3
Module collects adapter, physical drives and battery stats.
4
5
**Requirements:**
6
+ * `megacli` program
7
+ * `sudo` program
8
* `netdata` user needs to be able to be able to sudo the `megacli` program without password
9
10
To grab stats it executes:
@@ -22,7 +24,25 @@ It produces:
24
25
5. **Battery Cycle Count**
26
27
+### prerequisite
28
+This module uses `megacli` which can only be executed by root. It uses
29
+`sudo` and assumes that it is configured such that the `netdata` user can
30
+execute `megacli` as root without password.
31
+
32
+Add to `sudoers`:
33
+
34
+ netdata ALL=(root) NOPASSWD: /path/to/megacli
35
+
36
### configuration
26
-Battery stats disabled by default in the module configuration file.
37
+
38
+**megacli** is disabled by default. Should be explicitly enabled in `python.d.conf`.
39
+```yaml
40
+megacli: yes
41
+```
42
+
43
+Battery stats disabled by default. To enable them modify `megacli.conf`.
44
+```yaml
45
+do_battery: yes
46
+```
47
48
---
collectors/python.d.plugin/megacli/megacli.chart.py
+2
@@ -10,6 +10,8 @@ from bases.FrameworkServices.ExecutableService import ExecutableService
10
from bases.collection import find_binary
11
12
13
+disabled_by_default = True
14
+
15
update_every = 5
16
17
collectors/python.d.plugin/megacli/megacli.conf
-6
@@ -58,11 +58,5 @@
58
# do_battery: yes/no # default is no. Battery stats (adds additional call to megacli `megacli -AdpBbuCmd -a0`).
59
#
60
# ----------------------------------------------------------------------
61
-
62
-# IMPORTANT
63
-# The netdata user needs to be able to be able to sudo the megacli program without password:
64
-# netdata ALL=(root) NOPASSWD: /path/to/megacli
65
-
66
-
61
# uncomment the line below to collect battery statistics
62
# do_battery: yes
collectors/python.d.plugin/samba/README.md
+16
-10
@@ -2,6 +2,13 @@
2
3
Performance metrics of Samba file sharing.
4
5
+**Requirements:**
6
+* `smbstatus` program
7
+* `sudo` program
8
+* `smbd` must be compiled with profiling enabled
9
+* `smbd` must be started either with the `-P 1` option or inside `smb.conf` using `smbd profiling level`
10
+* `netdata` user needs to be able to sudo the `smbstatus` program without password
11
+
12
It produces the following charts:
13
14
1. **Syscall R/Ws** in kilobytes/s
@@ -40,22 +47,21 @@ It produces the following charts:
47
* break
48
* sessetup
49
43
-### configuration
50
+### prerequisite
51
+This module uses `smbstatus` which can only be executed by root. It uses
52
+`sudo` and assumes that it is configured such that the `netdata` user can
53
+execute `smbstatus` as root without password.
54
45
-Requires that smbd has been compiled with profiling enabled. Also required
46
-that `smbd` was started either with the `-P 1` option or inside `smb.conf`
47
-using `smbd profiling level`.
55
+Add to `sudoers`:
56
49
-This plugin uses `smbstatus -P` which can only be executed by root. It uses
50
-sudo and assumes that it is configured such that the `netdata` user can
51
-execute smbstatus as root without password.
57
+ netdata ALL=(root) NOPASSWD: /path/to/smbstatus
58
53
-For example:
59
+### configuration
60
55
- netdata ALL=(ALL) NOPASSWD: /usr/bin/smbstatus -P
61
+ **samba** is disabled by default. Should be explicitly enabled in `python.d.conf`.
62
63
```yaml
58
-update_every : 5 # update frequency
64
+samba: yes
65
```
66
67
---
collectors/python.d.plugin/samba/samba.chart.py
+3
@@ -21,6 +21,9 @@ import re
21
from bases.collection import find_binary
22
from bases.FrameworkServices.ExecutableService import ExecutableService
23
24
+
25
+disabled_by_default = True
26
+
27
# default module values (can be overridden per job in `config`)
28
update_every = 5
29
priority = 60000