Skip to content

Check postgresql-version

Overview

Checks the installed PostgreSQL version against the endoflife.date API and alerts if the version is end-of-life or if newer major, minor, or patch releases are available. By default, alerts 30 days before the official EOL date. The offset is configurable.

Important Notes:

  • The check must run locally on the PostgreSQL server because it queries the running server for its version.

Data Collection:

  • Runs psql --username=<user> --command="SELECT version();" to read the installed PostgreSQL version (configurable via --path)
  • Compares against the endoflife.date API to determine EOL status and available updates
  • Where the software comes from a package the distribution maintains itself, the end of life is the one the distribution gives it rather than the upstream one: on Red Hat Enterprise Linux and its rebuilds such as AlmaLinux and Rocky Linux the date Red Hat gives the package or its Application Stream, on Debian the end of the release's security support including LTS, on Ubuntu the end of its standard support for main and restricted. Software from EPEL, Ubuntu's universe, backports or a third-party repository keeps the upstream date
  • Caches endoflife.date responses locally for 24 hours to reduce external requests

Fact Sheet

Fact Value
Check Plugin Download https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/postgresql-version
Nagios/Icinga Check Name check_postgresql_version
Check Interval Recommendation Every day
Can be called without parameters Yes
Runs on Cross-platform
Compiled for Windows No (runs with Python interpreter)
Uses State File $TEMP/linuxfabrik-lib-version.db

Help

usage: postgresql-version [-h] [-V] [--always-ok] [--check-major]
                          [--check-minor] [--check-patch] [--insecure]
                          [--no-perfdata] [--no-proxy]
                          [--offset-eol OFFSET_EOL] [--path PATH]
                          [--proxy PROXY] [--timeout TIMEOUT]
                          [--unreachable-severity {ok,warn,crit,unknown}]
                          [--username USERNAME]

Checks the installed PostgreSQL version against the endoflife.date API and
alerts if the version is end-of-life or if newer major, minor, or patch
releases are available. By default, alerts 30 days before the official EOL
date. The offset is configurable.

options:
  -h, --help            show this help message and exit
  -V, --version         show program's version number and exit
  --always-ok           Always returns OK.
  --check-major         Alert when a new major release is available, even if
                        the current version is not yet EOL. Example: running
                        v26 (not yet EOL) and v27 is available.
  --check-minor         Alert when a new major.minor release is available,
                        even if the current version is not yet EOL. Example:
                        running v26.2 (not yet EOL) and v26.3 is available.
  --check-patch         Alert when a new major.minor.patch release is
                        available, even if the current version is not yet EOL.
                        Example: running v26.2.7 (not yet EOL) and v26.2.8 is
                        available.
  --insecure            This option explicitly allows insecure SSL
                        connections.
  --no-perfdata         Suppress the performance data section from the output.
                        The status message and the exit code are unaffected,
                        so alerting keeps working while trending data is
                        dropped.
  --no-proxy            Do not use a proxy, not even one the environment
                        names. Overrides `--proxy`.
  --offset-eol OFFSET_EOL
                        Alert n days before ("-30") or after an EOL date ("30"
                        or "+30"). Default: -30 days
  --path PATH           Path to the psql binary. Resolved via $PATH when given
                        without a directory. Default: psql
  --proxy PROXY         Proxy to reach the target through. The scheme defaults
                        to `http` when omitted. Overrides the proxy the
                        environment names (`http_proxy`, `https_proxy`,
                        `all_proxy`) together with the exceptions it lists in
                        `no_proxy`, and is itself overridden by `--no-proxy`.
                        Without either parameter the environment applies.
                        Credentials belong into the environment variable
                        rather than here, because a command-line argument is
                        visible to every user on the host. Example:
                        `--proxy=http://proxy.example.com:3128`.
  --timeout TIMEOUT     Network timeout in seconds. Default: 8 (seconds)
  --unreachable-severity {ok,warn,crit,unknown}
                        State to report when the online source is unreachable.
                        What is used instead - bundled offline data, a cached
                        copy, or nothing at all - is named in the output, and
                        a clean result then only covers what that fallback
                        could confirm. Default: ok
  --username USERNAME   PostgreSQL username for running `psql`. Default:
                        postgres

Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/postgresql-version/

Usage Examples

./postgresql-version --offset-eol=-30

Output:

PostgreSQL v10.16 (EOL 2022-11-10 -30d [WARNING], major 16.0 available, minor 10.23 available)

States

The end-of-life verdict, the --check-major / --check-minor / --check-patch alerts, --offset-eol, --always-ok and what happens when endoflife.date cannot be reached work the same way in every endoflife.date-based version plugin. They are described in Version Plugins.

Perfdata / Metrics

Name Type Description
postgresql-version Number Installed PostgreSQL version as float. "10.23" becomes 10.23.

Troubleshooting

Peer authentication failed for user "postgres"

psql logs in over the local socket as the database user given by --username (postgres by default), and the default peer authentication of PostgreSQL accepts that only from the operating system account of the same name. Run the check as that account, for example with a sudo rule for the monitoring user such as icinga ALL=(postgres) NOPASSWD: /usr/lib64/nagios/plugins/postgresql-version and sudo -u postgres in front of the command.

PostgreSQL server not reachable

could not connect to server: No such file or directory (older psql) or connection to server on socket "..." failed (newer psql)

The PostgreSQL server is not running, or it does not listen on the local socket psql uses. Start the server, or check unix_socket_directories in postgresql.conf.

Credits, License