Outline-Monitore in Uptime Kuma read-only auditieren
This commit is contained in:
parent
03e69d1157
commit
2f2d498e7f
1 changed files with 24 additions and 7 deletions
31
app.py
31
app.py
|
|
@ -1284,19 +1284,35 @@ async def system_sysctl_audit(host: str, _=Depends(_verify)):
|
|||
|
||||
|
||||
def _host_forensics_command(since_hours: int) -> str:
|
||||
script = f'''import glob, json, os, subprocess
|
||||
script = f'''import glob, json, os, re, subprocess
|
||||
|
||||
def run(command):
|
||||
proc = subprocess.run(command, shell=True, text=True, capture_output=True, timeout=30)
|
||||
return {{"rc": proc.returncode, "stdout": proc.stdout.strip()[-12000:], "stderr": proc.stderr.strip()[-1000:]}}
|
||||
|
||||
def redacted_git_diff():
|
||||
proc = subprocess.run(["git", "-C", "/app-config/ansible", "diff", "--", "iso-builder/build-iso.sh", "iso-builder/preseed.cfg.tpl", "pfannkuchen.ini"], text=True, capture_output=True, timeout=30)
|
||||
sensitive = ("password", "passwd", "secret", "token", "private", "credential", "ssh-rsa", "ssh-ed25519")
|
||||
def safe_git_diff(paths):
|
||||
proc = subprocess.run(["git", "-C", "/app-config/ansible", "diff", "--"] + paths, text=True, capture_output=True, timeout=30)
|
||||
sensitive = re.compile(r"pass|secret|token|api[_-]?key|private[_-]?key", re.I)
|
||||
lines = []
|
||||
for line in proc.stdout.splitlines():
|
||||
lines.append("[REDACTED SENSITIVE DIFF LINE]" if any(word in line.lower() for word in sensitive) else line)
|
||||
return {{"rc": proc.returncode, "stdout": "\\n".join(lines)[-12000:], "stderr": proc.stderr.strip()[-1000:]}}
|
||||
lines.append("[REDACTED SENSITIVE DIFF LINE]" if sensitive.search(line) else line)
|
||||
return {{"rc": proc.returncode, "stdout": "\\n".join(lines)[-12000:], "stderr": proc.stderr.strip()[-4000:]}}
|
||||
|
||||
def kuma_outline_monitors():
|
||||
path = "/app-config/kuma/kuma.db"
|
||||
if not os.path.exists(path):
|
||||
return {{"rc": 0, "stdout": "[]", "stderr": ""}}
|
||||
try:
|
||||
import sqlite3
|
||||
connection = sqlite3.connect("file:" + path + "?mode=ro", uri=True)
|
||||
columns = [row[1] for row in connection.execute("pragma table_info(monitor)")]
|
||||
wanted = [name for name in ("id", "name", "url", "hostname", "active") if name in columns]
|
||||
rows = [dict(zip(wanted, row)) for row in connection.execute("select " + ",".join(wanted) + " from monitor")]
|
||||
selected = [row for row in rows if "outline" in json.dumps(row).lower() or "wiki.sascha-lutz.de" in json.dumps(row).lower()]
|
||||
connection.close()
|
||||
return {{"rc": 0, "stdout": json.dumps(selected), "stderr": ""}}
|
||||
except Exception as exc:
|
||||
return {{"rc": 1, "stdout": "", "stderr": str(exc)}}
|
||||
|
||||
checks = {{
|
||||
"hostname": run("hostnamectl --static 2>/dev/null || hostname"),
|
||||
|
|
@ -1320,8 +1336,9 @@ checks = {{
|
|||
"recent_iso_builder_files": run("find /app-config/ansible/iso-builder -type f -mmin -{since_hours * 60} -printf '%TY-%Tm-%Td %TH:%TM:%TS %p\\n' 2>/dev/null | sort"),
|
||||
"ansible_git_status": run("git -C /app-config/ansible status --short 2>/dev/null || true"),
|
||||
"minecraft_inventory": run("grep -in 'minecraft' /app-config/ansible/pfannkuchen.ini 2>/dev/null || true"),
|
||||
"iso_builder_diff_redacted": redacted_git_diff(),
|
||||
"iso_builder_diff_redacted": safe_git_diff(["iso-builder/build-iso.sh", "iso-builder/preseed.cfg.tpl", "pfannkuchen.ini"]),
|
||||
"iso_builder_hashes": run("sha256sum /app-config/ansible/iso-builder/* 2>/dev/null || true"),
|
||||
"kuma_outline_monitors": kuma_outline_monitors(),
|
||||
}}
|
||||
print(json.dumps(checks))
|
||||
'''
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue