tailscale proxy: collect sanitized Telemt active IP list
Telemt's Prometheus endpoint exposes only active-IP counts, while its loopback control API includes both the address list and sensitive proxy links. Add a root systemd timer that enters the Telemt container network namespace, filters the API response in memory, and publishes only username/address rows through the Zabbix agent key telemt.active_ips.list.\n\nThe collector refreshes every 30 seconds, writes atomically with root:zabbix 0640 permissions, and leaves the control API unexposed. Document the host installation and recommend one-day Zabbix history because client IP addresses are sensitive operational data.
This commit is contained in:
@@ -48,3 +48,27 @@ Cockpit. The Telemt application whitelist permits only the client-02 Zabbix
|
||||
server (`192.168.0.34/32`). In Zabbix, import Telemt's upstream
|
||||
`tools/zbx_telemt_template.yaml`, link it to the Docker host, and set
|
||||
`{$TELEMT_URL}` to the URL above.
|
||||
|
||||
Prometheus deliberately exposes only active-IP counts. The files in
|
||||
`zabbix/` add the text key `telemt.active_ips.list` without publishing
|
||||
Telemt's control API. A root timer enters only the container's network
|
||||
namespace, reads `/v1/users`, discards links/secrets in memory, and writes a
|
||||
sanitized username/IP list readable by the Zabbix agent:
|
||||
|
||||
```bash
|
||||
install -o root -g root -m 0755 zabbix/zabbix-telemt-active-ips \
|
||||
/usr/local/libexec/zabbix-telemt-active-ips
|
||||
install -o root -g root -m 0644 zabbix/zabbix-telemt-active-ips.service \
|
||||
zabbix/zabbix-telemt-active-ips.timer /etc/systemd/system/
|
||||
install -o root -g root -m 0644 zabbix/telemt-active-ips.conf \
|
||||
/etc/zabbix/zabbix_agent2.d/telemt-active-ips.conf
|
||||
systemctl daemon-reload
|
||||
systemctl enable --now zabbix-telemt-active-ips.timer
|
||||
systemctl start zabbix-telemt-active-ips.service
|
||||
systemctl restart zabbix-agent2
|
||||
```
|
||||
|
||||
Create a Zabbix agent item on `Fedora Kirochnaya` with key
|
||||
`telemt.active_ips.list`, information type **Text**, a 30-second update
|
||||
interval, and one-day history. IP addresses are operationally sensitive; do
|
||||
not retain this item longer or expose it on unrestricted dashboards.
|
||||
|
||||
Reference in New Issue
Block a user