image-checker/go/main.go

271 lines
6.4 KiB
Go
Raw Normal View History

2025-07-17 02:35:36 +02:00
package main
import (
2025-07-21 09:23:50 +02:00
"context"
"fmt"
"log"
"net/http"
"os"
2025-07-21 09:23:50 +02:00
"regexp"
"strings"
"sync"
"time"
"github.com/docker/docker/api/types/container"
"github.com/docker/docker/api/types/image"
"github.com/docker/docker/client"
"github.com/prometheus/client_golang/prometheus"
"github.com/prometheus/client_golang/prometheus/promhttp"
"github.com/regclient/regclient"
"github.com/regclient/regclient/types/ref"
2025-07-17 10:24:53 +02:00
)
type ImageStatus struct {
2025-07-21 09:24:31 +02:00
ContainerName string
Image string
Tag string
UpdateAvailable float64
LocalDigest string
RemoteDigest string
2025-07-17 10:24:53 +02:00
}
type StatusCache struct {
2025-07-21 09:23:50 +02:00
sync.RWMutex
Data []ImageStatus
LastCheck time.Time
2025-07-17 10:24:53 +02:00
}
var (
cache = &StatusCache{Data: []ImageStatus{}, LastCheck: time.Time{}}
interval = 6 * time.Hour // Default wird ggf. überschrieben durch CHECK_INTERVAL
excludeContainers = map[string]struct{}{}
2025-07-17 02:35:36 +02:00
)
// Helper: image ohne ":tag" erhält "latest"
func normalizeImageTag(tag string) string {
if !strings.Contains(tag, ":") {
return tag + ":latest"
}
return tag
}
2025-07-17 03:04:35 +02:00
func toRegistryImage(imageTag string) (string, error) {
2025-07-21 09:23:50 +02:00
r := regexp.MustCompile(`^(?:(?P<registry>[^/]+)/)?(?P<repo>[^:]+)(?::(?P<tag>.+))?$`)
match := r.FindStringSubmatch(imageTag)
if len(match) == 0 {
return "", fmt.Errorf("Image-Tag nicht erkannt: %s", imageTag)
}
registry := match[r.SubexpIndex("registry")]
repo := match[r.SubexpIndex("repo")]
tag := match[r.SubexpIndex("tag")]
if registry == "" {
registry = "registry-1.docker.io"
}
if tag == "" {
tag = "latest"
}
return fmt.Sprintf("%s/%s:%s", registry, repo, tag), nil
2025-07-17 02:35:36 +02:00
}
2025-07-17 03:04:35 +02:00
func extractDigest(s string) string {
2025-07-21 09:23:50 +02:00
for _, part := range strings.Split(s, "@") {
if strings.HasPrefix(part, "sha256:") {
return part
}
}
return s
2025-07-17 10:24:53 +02:00
}
func checkImageUpdates() {
2025-07-21 09:23:50 +02:00
ctx := context.Background()
cli, err := client.NewClientWithOpts(client.FromEnv)
if err != nil {
log.Printf("Fehler bei Docker-Client: %v", err)
return
}
defer cli.Close()
rc := regclient.New()
containers, err := cli.ContainerList(ctx, container.ListOptions{All: false})
if err != nil {
log.Printf("Fehler beim ContainerList: %v", err)
return
}
images, err := cli.ImageList(ctx, image.ListOptions{All: true})
if err != nil {
log.Printf("Fehler beim ImageList: %v", err)
return
}
imageTagToDigest := make(map[string]string)
for _, img := range images {
for _, tag := range img.RepoTags {
2025-07-21 09:42:05 +02:00
normalizedTag := normalizeImageTag(tag)
2025-07-21 09:23:50 +02:00
if len(img.RepoDigests) > 0 {
2025-07-21 09:42:05 +02:00
imageTagToDigest[normalizedTag] = extractDigest(img.RepoDigests[0])
2025-07-21 09:23:50 +02:00
} else {
2025-07-21 09:42:05 +02:00
imageTagToDigest[normalizedTag] = img.ID
2025-07-21 09:23:50 +02:00
}
}
}
2025-07-21 11:33:41 +02:00
for tag, digest := range imageTagToDigest {
fmt.Printf("imageTagToDigest: %s -> %s\n", tag, digest)
}
2025-07-21 09:23:50 +02:00
results := make([]ImageStatus, 0)
for _, ctr := range containers {
containerName := "unknown"
if len(ctr.Names) > 0 {
containerName = strings.TrimPrefix(ctr.Names[0], "/")
2025-07-21 09:23:50 +02:00
}
// Überspringen, wenn im EXCLUDE_CONTAINERS enthalten
if _, excluded := excludeContainers[containerName]; excluded {
fmt.Printf("⏭️ Container '%s' ist ausgeschlossen.\n", containerName)
2025-07-21 09:23:50 +02:00
continue
}
rawTag := normalizeImageTag(ctr.Image)
localDigest := imageTagToDigest[rawTag]
2025-07-21 09:23:50 +02:00
imageRef, err := toRegistryImage(rawTag)
if err != nil {
log.Printf("Ungültige Image-Referenz (%s): %v", rawTag, err)
continue
}
2025-07-21 09:23:50 +02:00
refObj, err := ref.New(imageRef)
if err != nil {
log.Printf("Fehler beim Erzeugen der Referenz (%s): %v", rawTag, err)
2025-07-21 09:23:50 +02:00
continue
}
desc, err := rc.ManifestHead(ctx, refObj)
if err != nil {
log.Printf("Remote-Manifest nicht gefunden (%s): %v", rawTag, err)
2025-07-21 09:23:50 +02:00
continue
}
remoteDigest := desc.GetDigest().String()
2025-07-21 09:23:50 +02:00
update := 0.0
2025-07-21 11:33:41 +02:00
fmt.Printf("Container: %s\n", containerName)
fmt.Printf(" Image: %s\n", rawTag)
fmt.Printf(" Local Digest: %s\n", localDigest)
fmt.Printf(" Remote Digest: %s\n", remoteDigest)
2025-07-21 09:23:50 +02:00
if localDigest != remoteDigest {
update = 1.0
2025-07-21 11:33:41 +02:00
fmt.Println(" -> ⚠️ Update verfügbar!")
2025-07-21 09:23:50 +02:00
} else {
2025-07-21 11:33:41 +02:00
fmt.Println(" -> ✅ Kein Update erforderlich.")
2025-07-21 09:23:50 +02:00
}
imageName, imageTag := rawTag, "latest"
if cp := strings.Split(rawTag, ":"); len(cp) == 2 {
2025-07-21 09:42:05 +02:00
imageName, imageTag = cp[0], cp[1]
2025-07-21 09:23:50 +02:00
}
results = append(results, ImageStatus{
ContainerName: containerName,
2025-07-21 09:42:05 +02:00
Image: imageName,
Tag: imageTag,
2025-07-21 09:23:50 +02:00
UpdateAvailable: update,
LocalDigest: localDigest,
RemoteDigest: remoteDigest,
})
}
cache.Lock()
cache.Data = results
cache.LastCheck = time.Now()
cache.Unlock()
2025-07-17 02:35:36 +02:00
}
2025-07-17 03:15:14 +02:00
type imageUpdateCollector struct {
2025-07-21 09:23:50 +02:00
metric *prometheus.Desc
2025-07-17 03:12:27 +02:00
}
2025-07-17 03:15:14 +02:00
func newImageUpdateCollector() *imageUpdateCollector {
2025-07-21 09:23:50 +02:00
return &imageUpdateCollector{
metric: prometheus.NewDesc(
"docker_image_update_available",
2025-07-21 09:42:05 +02:00
"Ob ein Update für das verwendete Image eines laufenden Containers verfügbar ist (1 = Update)",
2025-07-21 09:23:50 +02:00
[]string{"container_name", "image", "tag"},
nil,
),
}
2025-07-17 03:12:27 +02:00
}
2025-07-17 03:15:14 +02:00
func (c *imageUpdateCollector) Describe(ch chan<- *prometheus.Desc) {
2025-07-21 09:23:50 +02:00
ch <- c.metric
2025-07-17 03:12:27 +02:00
}
2025-07-17 03:15:14 +02:00
func (c *imageUpdateCollector) Collect(ch chan<- prometheus.Metric) {
2025-07-21 09:23:50 +02:00
cache.RLock()
defer cache.RUnlock()
for _, stat := range cache.Data {
ch <- prometheus.MustNewConstMetric(
c.metric, prometheus.GaugeValue,
stat.UpdateAvailable, stat.ContainerName, stat.Image, stat.Tag,
)
}
2025-07-17 02:35:36 +02:00
}
2025-07-17 03:12:27 +02:00
func loadIntervalFromEnv() {
if val := os.Getenv("CHECK_INTERVAL"); val != "" {
dur, err := time.ParseDuration(val)
if err != nil {
log.Printf("❌ Ungültiger CHECK_INTERVAL: %s verwende Default (%s)", val, interval)
} else {
interval = dur
}
}
}
func loadExclusionsFromEnv() {
raw := os.Getenv("EXCLUDE_CONTAINERS")
if raw == "" {
return
}
list := strings.Split(raw, ",")
for _, name := range list {
clean := strings.TrimSpace(name)
if clean != "" {
excludeContainers[clean] = struct{}{}
}
}
}
2025-07-17 03:12:27 +02:00
func main() {
log.Println("🚀 Docker Image Update Exporter startet...")
loadIntervalFromEnv()
loadExclusionsFromEnv()
log.Printf("🔁 Prüfintervall: %v", interval)
if len(excludeContainers) > 0 {
log.Printf("🙈 Ignorierte Container: %v", keys(excludeContainers))
}
2025-07-21 09:23:50 +02:00
go func() {
for {
checkImageUpdates()
time.Sleep(interval)
}
}()
2025-07-21 09:23:50 +02:00
exporter := newImageUpdateCollector()
prometheus.MustRegister(exporter)
http.Handle("/metrics", promhttp.Handler())
log.Fatal(http.ListenAndServe(":9788", nil))
2025-07-17 03:12:27 +02:00
}
func keys(m map[string]struct{}) []string {
var result []string
for k := range m {
result = append(result, k)
}
return result
}