Check rpm-updates¶
Overview¶
Checks for available RPM package updates on RHEL, CentOS, Fedora, and compatible systems. Reports the number and type of available advisories (bugfix, enhancement, security). Alerts when the number of pending updates reaches the warning threshold, and when the number of security updates reaches the critical threshold. This check only lists updates and never actually installs anything.
Important Notes:
- The
--queryparameter accepts an SQL WHERE clause to filter the list of available updates. The following database columns can be used:arch(TEXT)package(TEXT)repo_installed(TEXT)repo_upgrade(TEXT)version_installed(TEXT)version_upgrade(TEXT)
- The "State" column says whether a package is
overdueor still counting down (due in 1W 23h), and marks the ones a WARNING or CRITICAL hangs on, so an alert can be traced back to the packages responsible for it - The "Type" column in the output lists the type of update for each intermediate version. Abbreviation meanings:
- B: Bugfix
- E: Enhancement
- S: Security
- U: Unspecified
- no character: unknown
Data Collection:
- Executes
yum list --upgrades,yum list --installed, andyum updateinfo list --available - Stores all package and advisory information in a local SQLite database that lives only for the duration of the run, for SQL-based filtering via
--query - Counts an update as security-critical when it carries a security advisory (
Sin the "Type" column). Optionally narrows the report down to those updates (--only-critical); the security count is reported either way - Records when an update for a package first showed up, so
--grace-updatesand--grace-securitycan hold the alert back until the host has had a patch window. An update inside its grace period is still listed and still counted in the performance data, it just does not drive the check state yet. The clock keys on the package name, so a newer candidate version does not restart it, and it starts over if the package drops off the list and comes back. A security update is governed by--grace-securityalone, which by default is0D, so security never waits. Both are0Dout of the box; the shipped Icinga Director service template sets--grace-updates=8Dto cover a weekly patch window - Plugin execution may take more than 10 seconds due to yum operations (default timeout: 120 seconds)
Fact Sheet¶
| Fact | Value |
|---|---|
| Check Plugin Download | https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/rpm-updates |
| Nagios/Icinga Check Name | check_rpm_updates |
| Check Interval Recommendation | Every day |
| Can be called without parameters | Yes |
| Runs on | Linux |
| Compiled for Windows | No |
| Uses State File | $TEMP/linuxfabrik-monitoring-plugins-rpm-updates.db |
Help¶
usage: rpm-updates [-h] [-V] [--always-ok] [-c CRIT]
[--grace-security GRACE_SECURITY]
[--grace-updates GRACE_UPDATES] [--no-perfdata]
[--only-critical] [--query QUERY] [--timeout TIMEOUT]
[-w WARN]
Checks for available RPM package updates on RHEL, CentOS, Fedora, and
compatible systems. Reports the number and type of available advisories
(bugfix, enhancement, security). Alerts when the number of pending updates
reaches the warning threshold, and when the number of security updates reaches
the critical threshold. This check only lists updates and never actually
installs anything.
options:
-h, --help show this help message and exit
-V, --version show program's version number and exit
--always-ok Always returns OK.
-c, --critical CRIT Minimum number of pending security updates to trigger
a CRITICAL. Counts the updates carrying a security
advisory, within the scope of `--query`. Unset by
default, so security updates raise a WARNING like any
other update until a threshold is given. Example:
`--critical=1` Default: None
--grace-security GRACE_SECURITY
How long a pending security update is tolerated before
it counts towards the thresholds. Starts when the
update is first seen, and starts over if the package
drops off the list and comes back. A duration such as
`12h`, `8D` or `2W`; `0D` disables the grace period.
Default: 0D
--grace-updates GRACE_UPDATES
How long a pending update is tolerated before it
counts towards the thresholds. Set this to cover the
interval between two patch windows, so a host stays
quiet about updates it has had no chance to install
yet. Starts when the update is first seen, and starts
over if the package drops off the list and comes back.
A duration such as `12h`, `8D` or `2W`; `0D` disables
the grace period. Default: 0D
--no-perfdata Suppress the performance data section from the output.
The status message and the exit code are unaffected,
so alerting keeps working while trending data is
dropped.
--only-critical Only report security updates and upgrades.
--query QUERY SQL WHERE clause to filter the list of available
updates. Supports regular expressions via a REGEXP
statement. See the README for a list of available
columns. If specified, a list of matching updates is
printed. Example: `--query='package like "bind9-%"'`.
Default: 1
--timeout TIMEOUT Network timeout in seconds. Default: 120 (seconds)
-w, --warning WARN Minimum number of pending updates to trigger a
WARNING. Default: 1
Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/rpm-updates/
Usage Examples¶
./rpm-updates --only-critical --query='package in ("audit", "bind-utils", "gcc-c++")'
Output:
30 updates available. [WARNING]
Package ! Installed ! Upgrade to ! Type ! State
-----------+--------------------+----------------------+------+------------------
audit ! 3.0.7-5.el8 ! 3.1.2-1.el8 ! B ! overdue [WARNING]
bind-utils ! 32:9.11.36-11.el8 ! 32:9.11.36-16.el8_10 ! ! overdue [WARNING]
gcc-c++ ! 8.5.0-20.el8 ! 8.5.0-26.el8_10 ! BSB ! overdue [WARNING]
Wake somebody up as soon as an update carrying a security advisory is pending:
./rpm-updates --critical=1
Output:
2 updates available, 2 of them critical. [CRITICAL]
Package ! Installed ! Upgrade to ! Type ! State
------------+------------------+------------------+------+-------------------
vim-data ! 2:9.2.240-1.fc42 ! 2:9.2.280-1.fc42 ! S ! overdue [CRITICAL]
vim-minimal ! 2:9.2.240-1.fc42 ! 2:9.2.280-1.fc42 ! S ! overdue [CRITICAL]
Hold ordinary updates back until the host has had its weekly patch window, while security updates keep alerting right away. The "State" column says which packages the alert hangs on, and when the rest follow:
./rpm-updates --grace-updates=8D
Output:
5 updates available, 2 of them critical. 3 of them within the grace period (updates: 8D, security: 0D). [WARNING]
Package ! Installed ! Upgrade to ! Type ! State
--------------+-------------------+-------------------+------+------------------
glib2 ! 2.56.4-170.el8_10 ! 2.56.4-177.el8_10 ! S ! overdue [WARNING]
libssh ! 0.9.6-16.el8_10 ! 0.9.6-17.el8_10 ! ! due in 1W 18h
libssh-config ! 0.9.6-16.el8_10 ! 0.9.6-17.el8_10 ! ! due in 1W 18h
libxml2 ! 2.9.7-21.el8_10.6 ! 2.9.7-21.el8_10.7 ! S ! overdue [WARNING]
wget ! 1.19.5-12.el8_10 ! 1.19.5-16.el8_10 ! ! due in 1W 18h
States¶
- OK if no updates are available (or both counts stay below their thresholds).
- WARN if the number of pending updates is >=
--warning(default: 1). - CRIT if the number of security updates is >=
--critical. Unset by default, so security updates raise a WARNING like any other update until a threshold is given. - UNKNOWN if one of the
yumcalls fails. --always-oksuppresses all alerts and always returns OK.
Perfdata / Metrics¶
| Name | Type | Description |
|---|---|---|
| critical_updates | Number | Number of updates carrying a security advisory, matching the current --query. |
| updates | Number | Number of updatable packages matching the current --query. With --only-critical this is the security count. |
Credits, License¶
- Authors: Linuxfabrik GmbH, Zurich
- License: The Unlicense, see LICENSE file.