mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-08-15 17:16:12 +02:00
patchmon: fetch SCAP Security Guide content, bump disk default
This commit is contained in:
+19
-1
@@ -9,7 +9,7 @@ APP="PatchMon"
|
||||
var_tags="${var_tags:-monitoring}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-4}"
|
||||
var_disk="${var_disk:-6}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
@@ -30,6 +30,24 @@ function update_script() {
|
||||
exit
|
||||
fi
|
||||
|
||||
msg_info "Checking SCAP Security Guide content"
|
||||
SSG_DIR="/opt/patchmon/ssg-content"
|
||||
SSG_LATEST=$(get_latest_github_release "ComplianceAsCode/content") || SSG_LATEST=""
|
||||
SSG_CURRENT=$(cat "$SSG_DIR/.ssg-version" 2>/dev/null || echo "")
|
||||
if [[ -n "$SSG_LATEST" && "$SSG_LATEST" != "$SSG_CURRENT" ]]; then
|
||||
rm -rf "$SSG_DIR"
|
||||
mkdir -p "$SSG_DIR"
|
||||
if curl -fsSL "https://github.com/ComplianceAsCode/content/releases/download/v${SSG_LATEST}/scap-security-guide-${SSG_LATEST}.tar.gz" |
|
||||
tar -xz -C "$SSG_DIR" --strip-components=1 --wildcards '*/ssg-*-ds.xml'; then
|
||||
echo "$SSG_LATEST" >"$SSG_DIR/.ssg-version"
|
||||
msg_ok "Updated SCAP Security Guide content (v${SSG_LATEST})"
|
||||
else
|
||||
msg_warn "Could not update SCAP Security Guide content"
|
||||
fi
|
||||
else
|
||||
msg_ok "SCAP Security Guide content is current"
|
||||
fi
|
||||
|
||||
if check_for_gh_release "PatchMon" "PatchMon/PatchMon"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop patchmon-server
|
||||
|
||||
@@ -60,6 +60,7 @@ REDIS_PORT=6379
|
||||
# OIDC_ENFORCE_HTTPS=true
|
||||
|
||||
AGENT_BINARIES_DIR=/opt/patchmon/agents
|
||||
SSG_CONTENT_DIR=/opt/patchmon/ssg-content
|
||||
EOF
|
||||
msg_ok "Configured PatchMon"
|
||||
|
||||
@@ -85,6 +86,18 @@ for arch in "${AGENT_NAME[@]}"; do
|
||||
done
|
||||
msg_ok "Fetched PatchMon agent binaries"
|
||||
|
||||
msg_info "Fetching SCAP Security Guide content"
|
||||
SSG_DIR="/opt/patchmon/ssg-content"
|
||||
mkdir -p "$SSG_DIR"
|
||||
SSG_RELEASE=$(get_latest_github_release "ComplianceAsCode/content") || SSG_RELEASE=""
|
||||
if [[ -n "$SSG_RELEASE" ]] && curl -fsSL "https://github.com/ComplianceAsCode/content/releases/download/v${SSG_RELEASE}/scap-security-guide-${SSG_RELEASE}.tar.gz" |
|
||||
tar -xz -C "$SSG_DIR" --strip-components=1 --wildcards '*/ssg-*-ds.xml'; then
|
||||
echo "$SSG_RELEASE" >"$SSG_DIR/.ssg-version"
|
||||
msg_ok "Fetched SCAP Security Guide content (v${SSG_RELEASE})"
|
||||
else
|
||||
msg_warn "Could not fetch SCAP Security Guide content; it will be fetched on the next update"
|
||||
fi
|
||||
|
||||
msg_info "Creating service"
|
||||
cat <<EOF >/etc/systemd/system/patchmon-server.service
|
||||
[Unit]
|
||||
|
||||
Reference in New Issue
Block a user