Sign inSign up

omitsis/prodchecker

By omitsis

•Updated over 2 years ago

Image
0

1.8K

omitsis/prodchecker repository overview

⁠ProdChecker

ProdChecker is a simple docker container that runs a very simple bash script. The bash script uses a json file to determine what to look for, and check for a condition. When the condition is met, it will trigger a warning for the name of that check. Finally, it sends a healthchecks.io fail ping if there are any warnings, or success if there are none.

This tool is useful to run periodic checks on systems, searching for undesired patters or files.

⁠Environment variables

  • CHECKER_JSON_COMMAND (required) - A command that will provide plain text json string. For example:

    • cat config.json
    • curl https://example.com/config.json
  • LOG_FILEPATH - A file to output logs to. Example: /var/log/prodchecker.log

  • DISABLE_HEALTHCHECKS - Do not send healthchecks pings.

  • HC_PING_KEY - The healthchecks.io ping key for your project.

  • HC_PING_API_HOST - The healthchecks.io api host. No protocol and no trailing slashes. Should be hc-ping.com if you're on the SaaS service.

⁠Usage

You can run prodchecker with a simple docker run command:

docker run \
       -v /var/www:/var/www:ro \
       -v /opt/checker.json:/checker.json:ro \
       -v /etc/hostname:/etc/hostname:ro \
       -e CHECKER_JSON_COMMAND="cat /checker.json" \
       -e HC_PING_KEY="vn5gzyXXXToxXXXaMXXXdA" \
       -e HC_PING_API_HOST="hc-ping.com" \
       omitsis/prodchecker:latest

or using docker compose:

version: "3.9"

services:
    ofelia:
        image: mcuadros/ofelia:latest
        command: daemon --docker
        volumes:
            - /var/run/docker.sock:/var/run/docker.sock:ro

    prodchecker:
        image: omitsis/prodchecker:latest
        command: tail -f /dev/null
        volumes:
            - /var/www:/var/www:ro
            - /opt/checker.json:/checker.json:ro
            - /etc/hostname:/etc/hostname:ro
        environment:
            CHECKER_JSON_COMMAND: "cat /checker.json"
            HC_PING_KEY: vn5gzyXXXToxXXXaMXXXdA
            HC_PING_API_HOST: hc-ping.com
        labels:
            ofelia.enabled: "true"
            ofelia.job-exec.prodchecker.schedule: "@every 5s"
            ofelia.job-exec.prodchecker.command: "prodchecker"

Here's an example json that you could use to run checks:

{
    "scripts": [
         {
             "name": "Found info.php file",
             "command": "find /var/www/ -name '*info.php*' | wc -l",
             "condition": "-gt 0"
         },
         {
            "name": "Found phpinfo() calls",
            "command": "rg -uuu -i -g '*.php' 'phpinfo' /var/www | wc -l",
            "condition": "-gt 0"
        },
        {
            "name": "DEV*=true in *.env",
            "command": "rg -uuu -i -g '*.env' 'DEV.*=true' /var/www/ | wc -l",
            "condition": "-gt 0"
        },           
        {
            "name": "WP_DEBUG=true in wp-config.php",
            "command": "rg -uuu -i -g 'wp-config.php' \"define\\s*\\(\\s*'WP_DEBUG'\\s*,\\s*true\\s*\\)\\s*;\" /var/www/ | wc -l",
            "condition": "-gt 0"
        }
    ]
 }

⁠Predefined variables

At the top of your json, you can define variables and then use them in your scripts as env variables.

{
    "vars": {
        "COMMENTS_RGX": "'^\\s*(//|#|/\\*|<!--|\\ \\*)|(\\*/|-->|\\ \\*)\\s*$'"
    },
    "scripts": [
        {
           "name": "Find die() calls",
           "command": "rg --no-filename -uuu --type php -v $COMMENTS_RGX /var/www | rg -uuu -i 'die\\(\\)' | wc -l",
           "condition": "-gt 0"
        }
    ]
}

ProdChecker will automatically export your defined vars as environment variables and will then perform an envsubst on each command before running, so that env variables will be replaced with the actual values.

Tag summary

Content type

Image

Digest

sha256:dccf0c96b…

Size

12.9 MB

Last updated

over 2 years ago

docker pull omitsis/prodchecker