Forensik um Firewallregeln und redaktierten ISO-Diff erweitern
This commit is contained in:
parent
b65ff79097
commit
46f2293078
1 changed files with 11 additions and 0 deletions
11
app.py
11
app.py
|
|
@ -1266,6 +1266,14 @@ def run(command):
|
|||
proc = subprocess.run(command, shell=True, text=True, capture_output=True, timeout=30)
|
||||
return {{"rc": proc.returncode, "stdout": proc.stdout.strip()[-12000:], "stderr": proc.stderr.strip()[-1000:]}}
|
||||
|
||||
def redacted_git_diff():
|
||||
proc = subprocess.run(["git", "-C", "/app-config/ansible", "diff", "--", "iso-builder/build-iso.sh", "iso-builder/preseed.cfg.tpl", "pfannkuchen.ini"], text=True, capture_output=True, timeout=30)
|
||||
sensitive = ("password", "passwd", "secret", "token", "private", "credential", "ssh-rsa", "ssh-ed25519")
|
||||
lines = []
|
||||
for line in proc.stdout.splitlines():
|
||||
lines.append("[REDACTED SENSITIVE DIFF LINE]" if any(word in line.lower() for word in sensitive) else line)
|
||||
return {{"rc": proc.returncode, "stdout": "\\n".join(lines)[-12000:], "stderr": proc.stderr.strip()[-1000:]}}
|
||||
|
||||
checks = {{
|
||||
"hostname": run("hostnamectl --static 2>/dev/null || hostname"),
|
||||
"uptime": run("uptime"),
|
||||
|
|
@ -1279,6 +1287,7 @@ checks = {{
|
|||
"docker_volumes": run("docker volume ls --format '{{{{.Name}}}}' 2>/dev/null || true"),
|
||||
"docker_disk_usage": run("docker system df 2>/dev/null || true"),
|
||||
"iptables_docker_refs": run("iptables-save 2>/dev/null | grep -ci docker || true"),
|
||||
"iptables_docker_rules": run("iptables-save 2>/dev/null | grep -i docker || true"),
|
||||
"nft_docker_refs": run("nft list ruleset 2>/dev/null | grep -ci docker || true"),
|
||||
"forward_policy": run("iptables -S FORWARD 2>/dev/null | head -40"),
|
||||
"lvm": run("lvs -o lv_name,lv_size,data_percent,metadata_percent --units g --noheadings 2>/dev/null || true"),
|
||||
|
|
@ -1286,6 +1295,8 @@ checks = {{
|
|||
"recent_system_files": run("find /etc/systemd/system /etc/docker /etc/network -type f -mmin -{since_hours * 60} -printf '%TY-%Tm-%Td %TH:%TM:%TS %p\\n' 2>/dev/null | sort"),
|
||||
"recent_iso_builder_files": run("find /app-config/ansible/iso-builder -type f -mmin -{since_hours * 60} -printf '%TY-%Tm-%Td %TH:%TM:%TS %p\\n' 2>/dev/null | sort"),
|
||||
"ansible_git_status": run("git -C /app-config/ansible status --short 2>/dev/null || true"),
|
||||
"minecraft_inventory": run("grep -in 'minecraft' /app-config/ansible/pfannkuchen.ini 2>/dev/null || true"),
|
||||
"iso_builder_diff_redacted": redacted_git_diff(),
|
||||
"iso_builder_hashes": run("sha256sum /app-config/ansible/iso-builder/* 2>/dev/null || true"),
|
||||
}}
|
||||
print(json.dumps(checks))
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue