Skip to content

Check rhel-version

Overview

Checks the installed Red Hat Enterprise Linux version against the endoflife.date API and alerts if the version is end-of-life or if newer major, minor, or patch releases are available. By default, alerts 30 days before the official EOL date. The offset is configurable.

Important Notes:

  • The check must run locally on the server because it reads the version from the local system.
  • It also works on Alma, CentOS, CentOS Stream, Oracle, Rocky and the other rebuilds, but reports the end-of-life date of RHEL.
  • On Fedora Workstation or Fedora Server, use fedora-version instead.

Data Collection:

  • Reads the installed version from the local distribution facts
  • Compares against the endoflife.date API to determine EOL status and available updates
  • Caches endoflife.date responses locally for 24 hours to reduce external requests

Fact Sheet

Fact Value
Check Plugin Download https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/rhel-version
Nagios/Icinga Check Name check_rhel_version
Check Interval Recommendation Every day
Can be called without parameters Yes
Runs on Cross-platform
Compiled for Windows No (runs with Python interpreter)
Uses State File $TEMP/linuxfabrik-lib-version.db

Help

usage: rhel-version [-h] [-V] [--always-ok] [--check-major] [--check-minor]
                    [--check-patch] [--extended-support] [--insecure]
                    [--no-perfdata] [--no-proxy] [--offset-eol OFFSET_EOL]
                    [--proxy PROXY] [--timeout TIMEOUT]
                    [--unreachable-severity {ok,warn,crit,unknown}]

Checks the installed Red Hat Enterprise Linux version against the
endoflife.date API and alerts if the version is end-of-life or if newer major,
minor, or patch releases are available. By default, alerts 30 days before the
official EOL date. The offset is configurable.

options:
  -h, --help            show this help message and exit
  -V, --version         show program's version number and exit
  --always-ok           Always returns OK.
  --check-major         Alert when a new major release is available, even if
                        the current version is not yet EOL. Example: running
                        v26 (not yet EOL) and v27 is available.
  --check-minor         Alert when a new major.minor release is available,
                        even if the current version is not yet EOL. Example:
                        running v26.2 (not yet EOL) and v26.3 is available.
  --check-patch         Alert when a new major.minor.patch release is
                        available, even if the current version is not yet EOL.
                        Example: running v26.2.7 (not yet EOL) and v26.2.8 is
                        available.
  --extended-support    Instead of "Maintenance Support" EOL (default), check
                        for "Extended Life Cycle Support" EOL.
  --insecure            This option explicitly allows insecure SSL
                        connections.
  --no-perfdata         Suppress the performance data section from the output.
                        The status message and the exit code are unaffected,
                        so alerting keeps working while trending data is
                        dropped.
  --no-proxy            Do not use a proxy, not even one the environment
                        names. Overrides `--proxy`.
  --offset-eol OFFSET_EOL
                        Alert n days before ("-30") or after an EOL date ("30"
                        or "+30"). Default: -30 days
  --proxy PROXY         Proxy to reach the target through. The scheme defaults
                        to `http` when omitted. Overrides the proxy the
                        environment names (`http_proxy`, `https_proxy`,
                        `all_proxy`) together with the exceptions it lists in
                        `no_proxy`, and is itself overridden by `--no-proxy`.
                        Without either parameter the environment applies.
                        Credentials belong into the environment variable
                        rather than here, because a command-line argument is
                        visible to every user on the host. Example:
                        `--proxy=http://proxy.example.com:3128`.
  --timeout TIMEOUT     Network timeout in seconds. Default: 8 (seconds)
  --unreachable-severity {ok,warn,crit,unknown}
                        State to report when the online source is unreachable.
                        What is used instead - bundled offline data, a cached
                        copy, or nothing at all - is named in the output, and
                        a clean result then only covers what that fallback
                        could confirm. Default: ok

Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/rhel-version/

Usage Examples

./rhel-version --offset-eol=-30

Output:

Rocky Linux 8.9 (Green Obsidian) (full support ended on 2024-05-31; EOL 2029-05-31 -30d, major 9.5 available, minor 8.10 available)

States

The end-of-life verdict, the --check-major / --check-minor / --check-patch alerts, --offset-eol, --always-ok and what happens when endoflife.date cannot be reached work the same way in every endoflife.date-based version plugin. They are described in Version Plugins.

UNKNOWN on a distribution outside the Red Hat family, and on Fedora, whose releases do not follow this lifecycle.

Perfdata / Metrics

Name Type Description
rhel-version Number Installed RHEL version as float. "8.7" becomes "87".

Credits, License