Telemt's Prometheus endpoint exposes only active-IP counts, while its loopback control API includes both the address list and sensitive proxy links. Add a root systemd timer that enters the Telemt container network namespace, filters the API response in memory, and publishes only username/address rows through the Zabbix agent key telemt.active_ips.list.\n\nThe collector refreshes every 30 seconds, writes atomically with root:zabbix 0640 permissions, and leaves the control API unexposed. Document the host installation and recommend one-day Zabbix history because client IP addresses are sensitive operational data.
13 lines
256 B
Desktop File
13 lines
256 B
Desktop File
[Unit]
|
|
Description=Collect sanitized Telemt active IP addresses for Zabbix
|
|
After=docker.service
|
|
Requires=docker.service
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
ExecStart=/usr/local/libexec/zabbix-telemt-active-ips
|
|
User=root
|
|
Group=root
|
|
PrivateTmp=true
|
|
NoNewPrivileges=true
|