No description
Find a file
2023-09-01 16:58:12 +02:00
opnsense_exporter add labels 2023-09-01 16:23:20 +02:00
tests add labels 2023-09-01 16:23:20 +02:00
.coveragerc add coveragerc 2023-09-01 16:43:49 +02:00
.gitignore First implementation 2023-09-01 13:27:55 +02:00
.gitlab-ci.yml README: add badges 2023-09-01 15:57:07 +02:00
.pre-commit-config.yaml First implementation 2023-09-01 13:27:55 +02:00
LICENSE fix license to apache2 2023-09-01 13:40:46 +02:00
README.md README: improvemnets 2023-09-01 16:58:12 +02:00
requirements.dev.txt gitlab ci: fix lint and long descriptions 2023-09-01 15:41:11 +02:00
requirements.tests.txt First implementation 2023-09-01 13:27:55 +02:00
requirements.txt First implementation 2023-09-01 13:27:55 +02:00
setup.cfg First implementation 2023-09-01 13:27:55 +02:00
setup.py gitlab ci: fix lint and long descriptions 2023-09-01 15:41:11 +02:00

pipeline status coverage report Version status PyPi Package

OPNSense Prometheus exporter

I've configures OPNSense with High Availability settings using 2 servers.

So I've 2 servers: MAIN and BACKUP, in normal situation MAIN server is expected to be active and the BACKUP server to be in hot_standby state.

The initial needs was to be able to make sure that BACKUP server is ready (hot standby) to get the main server role with the active state at any time.

Unfortunately I've not found a proper configuration to call OPNSense HTTP API over opnvpn on backup server using blackbox configuratoin. That why I've started to develop this exporter install on a server on the LAN to be able to resquest both OPNSense servers.

Metrics

This exporter gives following metrics, all metrics received following labels:

  • instance: by default this is set with the hostname where is running this exporter service
  • host: the host of the OPNSense

Enums

  • opnsense_main_ha_state: OPNSense HA state of the MAIN server
  • opnsense_backup_ha_state: OPNSense HA state of the BACKUP server

Gauges

  • opnsense_active_server_bytes_received: Active OPNSense server bytes received on WAN interface
  • opnsense_active_server_bytes_transmitted: Active OPNSense server bytes transmitted on WAN interface

Usage

Note

: Most updated documentation from command line !

opnsense-exporter --help
usage: opnsense-exporter [-h] [--check-frequency-seconds FREQUENCY]
                         [--main-host MAIN] [--backup-host BACKUP]
                         [--opnsense-user USER]
                         [--opnsense-password PASSWORD]
                         [--prometheus-instance PROM_INSTANCE]

OPNSense prometheus exporter

optional arguments:
  -h, --help            show this help message and exit
  --check-frequency-seconds FREQUENCY, -c FREQUENCY
                        How often (in seconds) this server requests
                        OPNSense servers (default: 2)
  --main-host MAIN, -m MAIN
                        MAIN OPNsense server that should be in `active`
                        state in normal configuration.
  --backup-host BACKUP, -b BACKUP
                        BACKUP OPNsense server that should be
                        `hot_standby` state in normal configuration.
  --opnsense-user USER, -u USER
                        OPNsense user. Expect to be the same on MAIN and
                        BACKUP servers
  --opnsense-password PASSWORD, -p PASSWORD
                        OPNsense password. Expect to be the same on MAIN
                        and BACKUP servers
  --prometheus-instance PROM_INSTANCE
                        Exporter Instance name, default value computed
                        with hostname where the server is running. Use to

You can setup env through .env file or environment variables with defined as default values (so command line will get the precedent):

  • CHECK_FREQUENCY_SECONDS: default value for --check-frequency-seconds param
  • OPNSENSE_MAIN_HOST: default value for --main-host param
  • OPNSENSE_BACKUP_HOST: default value for --backup-host param
  • OPNSENSE_USERNAME: default value for --opnsense-user param
  • OPNSENSE_PASSWORD: default value for --opnsense-password param

Roadmap

  • allow to change the listening port (today it force using 8000)

Changelog

Version 0.1.0

Initial version