@cryptotaxi247 / netdata-1 / commits / c6cce6bd2

Disable python sudo modules by default (#4477)

* adaptec_raid: check if `arcconf` is available first * adaptec_raid: disable by default and update docs * megacli: disable by default and update docs * samba: disable by default and update docs * samba megacli adaptec readme fix * adaptec readme fix

Ilya Mashchenko committed Oct 26, 2018 at 08:57 UTC c6cce6bd2accec27a61243e1ffa38826ac2a4892
8 files changed +70 -28
collectors/python.d.plugin/adaptec_raid/README.md
+21 -2
@@ -3,7 +3,9 @@
3 Module collects logical and physical devices health metrics.
4
5 **Requirements:**
6 - * `netdata` user needs to be able to sudo the `arcconf` program without password
6 +* `arcconf` program
7 +* `sudo` program
8 +* `netdata` user needs to be able to sudo the `arcconf` program without password
9
10 To grab stats it executes:
11 * `sudo -n arcconf GETCONFIG 1 LD`
@@ -20,7 +22,24 @@ It produces:
22
23 4. **Physical Device Temperature**
24
23 -Screenshot:
25 +### prerequisite
26 +This module uses `arcconf` which can only be executed by root. It uses
27 +`sudo` and assumes that it is configured such that the `netdata` user can
28 +execute `arcconf` as root without password.
29 +
30 +Add to `sudoers`:
31 +
32 + netdata ALL=(root) NOPASSWD: /path/to/arcconf
33 +
34 +### configuration
35 +
36 + **adaptec_raid** is disabled by default. Should be explicitly enabled in `python.d.conf`.
37 +
38 +```yaml
39 +adaptec_raid: yes
40 +```
41 +
42 +#### Screenshot:
43
44 ![image](https://user-images.githubusercontent.com/22274335/47278133-6d306680-d601-11e8-87c2-cc9c0f42d686.png)
45
collectors/python.d.plugin/adaptec_raid/adaptec_raid.chart.py
+7 -5
@@ -12,6 +12,8 @@ from bases.FrameworkServices.ExecutableService import ExecutableService
12 from bases.collection import find_binary
13
14
15 +disabled_by_default = True
16 +
17 update_every = 5
18
19 ORDER = [
@@ -158,6 +160,11 @@ class Service(ExecutableService):
160 return self._get_raw_data(command=command, stderr=stderr)
161
162 def check(self):
163 + arcconf = find_binary(ARCCONF)
164 + if not arcconf:
165 + self.error('can\'t locate "{0}" binary'.format(ARCCONF))
166 + return False
167 +
168 sudo = find_binary(SUDO)
169 if self.use_sudo:
170 if not sudo:
@@ -168,11 +175,6 @@ class Service(ExecutableService):
175 self.error(' '.join(err))
176 return False
177
171 - arcconf = find_binary(ARCCONF)
172 - if not arcconf:
173 - self.error('can\'t locate "{0}" binary'.format(ARCCONF))
174 - return False
175 -
178 if self.use_sudo:
179 self.arcconf = SudoArcconf(arcconf, sudo)
180 else:
collectors/python.d.plugin/adaptec_raid/adaptec_raid.conf
-4
@@ -53,7 +53,3 @@
53 # retries: 60 # the JOB's number of restoration attempts
54 # autodetection_retry: 0 # the JOB's re-check interval in seconds
55 # ----------------------------------------------------------------------
56 -
57 -# IMPORTANT
58 -# The netdata user needs to be able to sudo the arcconf program without password:
59 -# netdata ALL=(root) NOPASSWD: /path/to/arcconf
collectors/python.d.plugin/megacli/README.md
+21 -1
@@ -3,6 +3,8 @@
3 Module collects adapter, physical drives and battery stats.
4
5 **Requirements:**
6 + * `megacli` program
7 + * `sudo` program
8 * `netdata` user needs to be able to be able to sudo the `megacli` program without password
9
10 To grab stats it executes:
@@ -22,7 +24,25 @@ It produces:
24
25 5. **Battery Cycle Count**
26
27 +### prerequisite
28 +This module uses `megacli` which can only be executed by root. It uses
29 +`sudo` and assumes that it is configured such that the `netdata` user can
30 +execute `megacli` as root without password.
31 +
32 +Add to `sudoers`:
33 +
34 + netdata ALL=(root) NOPASSWD: /path/to/megacli
35 +
36 ### configuration
26 -Battery stats disabled by default in the module configuration file.
37 +
38 +**megacli** is disabled by default. Should be explicitly enabled in `python.d.conf`.
39 +```yaml
40 +megacli: yes
41 +```
42 +
43 +Battery stats disabled by default. To enable them modify `megacli.conf`.
44 +```yaml
45 +do_battery: yes
46 +```
47
48 ---
collectors/python.d.plugin/megacli/megacli.chart.py
+2
@@ -10,6 +10,8 @@ from bases.FrameworkServices.ExecutableService import ExecutableService
10 from bases.collection import find_binary
11
12
13 +disabled_by_default = True
14 +
15 update_every = 5
16
17
collectors/python.d.plugin/megacli/megacli.conf
-6
@@ -58,11 +58,5 @@
58 # do_battery: yes/no # default is no. Battery stats (adds additional call to megacli `megacli -AdpBbuCmd -a0`).
59 #
60 # ----------------------------------------------------------------------
61 -
62 -# IMPORTANT
63 -# The netdata user needs to be able to be able to sudo the megacli program without password:
64 -# netdata ALL=(root) NOPASSWD: /path/to/megacli
65 -
66 -
61 # uncomment the line below to collect battery statistics
62 # do_battery: yes
collectors/python.d.plugin/samba/README.md
+16 -10
@@ -2,6 +2,13 @@
2
3 Performance metrics of Samba file sharing.
4
5 +**Requirements:**
6 +* `smbstatus` program
7 +* `sudo` program
8 +* `smbd` must be compiled with profiling enabled
9 +* `smbd` must be started either with the `-P 1` option or inside `smb.conf` using `smbd profiling level`
10 +* `netdata` user needs to be able to sudo the `smbstatus` program without password
11 +
12 It produces the following charts:
13
14 1. **Syscall R/Ws** in kilobytes/s
@@ -40,22 +47,21 @@ It produces the following charts:
47 * break
48 * sessetup
49
43 -### configuration
50 +### prerequisite
51 +This module uses `smbstatus` which can only be executed by root. It uses
52 +`sudo` and assumes that it is configured such that the `netdata` user can
53 +execute `smbstatus` as root without password.
54
45 -Requires that smbd has been compiled with profiling enabled. Also required
46 -that `smbd` was started either with the `-P 1` option or inside `smb.conf`
47 -using `smbd profiling level`.
55 +Add to `sudoers`:
56
49 -This plugin uses `smbstatus -P` which can only be executed by root. It uses
50 -sudo and assumes that it is configured such that the `netdata` user can
51 -execute smbstatus as root without password.
57 + netdata ALL=(root) NOPASSWD: /path/to/smbstatus
58
53 -For example:
59 +### configuration
60
55 - netdata ALL=(ALL) NOPASSWD: /usr/bin/smbstatus -P
61 + **samba** is disabled by default. Should be explicitly enabled in `python.d.conf`.
62
63 ```yaml
58 -update_every : 5 # update frequency
64 +samba: yes
65 ```
66
67 ---
collectors/python.d.plugin/samba/samba.chart.py
+3
@@ -21,6 +21,9 @@ import re
21 from bases.collection import find_binary
22 from bases.FrameworkServices.ExecutableService import ExecutableService
23
24 +
25 +disabled_by_default = True
26 +
27 # default module values (can be overridden per job in `config`)
28 update_every = 5
29 priority = 60000