summaryrefslogtreecommitdiffstats
path: root/admin/zabbix/patches/020-zabbix_server-tweak-config-file-for-openwrt.patch
blob: 04f8b5684d932d5a9061e13248489abc993e8934 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
From 6655a1f2e5bff8d0082f41cf2711339f0d75d788 Mon Sep 17 00:00:00 2001
From: "Daniel F. Dickinson" <dfdpublic@wildtechgarden.ca>
Date: Wed, 17 Dec 2025 06:39:16 -0500
Subject: zabbix_server: tweak config file for OpenWrt

Created 2025-12-17. Updated 2026-07-16.

1. Log to syslog, not a file.
2. Update PidFile path so correct permissions can be set for access by
   Zabbix server running without privileges.
3. If started as root, drop privileges to zabbix-server user (instead of
   zabbix user shared with agent and proxy, or root) per upstream
   recommendation:
   https://www.zabbix.com/documentation/7.0/en/manual/installation/install#security-recommendation.
4. Set the fping location properly for OpenWrt (/usr/bin not /usr/sbin).
5. Configure fping as the ipv6 fping as well.
6. For privacy, disable the public API call to check Zabbix version.
7. Include configurations under /etc/zabbix_server.conf.d/.
8. Require configurations under /etc/zabbix_server.conf.d/ end in .conf
   (other files are ignored for configuration purposes).

Signed-off-by: Daniel F. Dickinson <dfdpublic@wildtechgarden.ca>
---
 conf/zabbix_server.conf | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

--- a/conf/zabbix_server.conf
+++ b/conf/zabbix_server.conf
@@ -27,6 +27,7 @@
 # Mandatory: no
 # Default:
 # LogType=file
+LogType=system
 
 ### Option: LogFile
 #	Log file name for LogType 'file' parameter.
@@ -35,7 +36,7 @@
 # Default:
 # LogFile=
 
-LogFile=/tmp/zabbix_server.log
+# LogFile=/tmp/zabbix_server.log
 
 ### Option: LogFileSize
 #	Maximum size of log file in MB.
@@ -67,6 +68,10 @@ LogFile=/tmp/zabbix_server.log
 # Default:
 # PidFile=/tmp/zabbix_server.pid
 
+# Although procd does not require a pid file, zabbix uses the pidfile to
+# shut down correctly on receipt of a TERM or INT signal.
+PidFile=/var/run/zabbix-server/zabbix_server.pid
+
 ### Option: SocketDir
 #	IPC socket directory.
 #		Directory to store IPC sockets used by internal Zabbix services.
@@ -611,6 +616,7 @@ Timeout=4
 # Mandatory: no
 # Default:
 # FpingLocation=/usr/sbin/fping
+FpingLocation=/usr/bin/fping
 
 ### Option: Fping6Location
 #	Location of fping6.
@@ -620,6 +626,7 @@ Timeout=4
 # Mandatory: no
 # Default:
 # Fping6Location=/usr/sbin/fping6
+Fping6Location=
 
 ### Option: SSHKeyLocation
 #	Location of public and private keys for SSH checks and actions.
@@ -699,6 +706,7 @@ LogSlowQueries=3000
 # Mandatory: no
 # Default:
 # User=zabbix
+User=zabbix-server
 
 ### Option: SSLCertLocation
 #	Location of SSL client certificates.
@@ -1050,7 +1058,7 @@ EnableGlobalScripts=0
 #
 # Mandatory: no
 # Default:
-# AllowSoftwareUpdateCheck=1
+AllowSoftwareUpdateCheck=0
 
 ### Option: SMSDevices
 #	List of comma delimited modem files allowed to use Zabbix server
@@ -1125,3 +1133,4 @@ EnableGlobalScripts=0
 # Include=/usr/local/etc/zabbix_server.general.conf
 # Include=/usr/local/etc/zabbix_server.conf.d/
 # Include=/usr/local/etc/zabbix_server.conf.d/*.conf
+Include=/etc/zabbix_server.conf.d/*.conf