TF-X ITA check via ICMP; enable unprivileged ping (ping_group_range sysctl)

Gatus pings unprivileged when non-root (pro-bing UDP mode), which the kernel
denies unless net.ipv4.ping_group_range covers the gid. Set the namespaced
safe sysctl for gid 65534 in both the pod spec and compose.
This commit is contained in:
Josh Belke 2026-07-04 12:59:00 -04:00
commit 58acb08526
3 changed files with 25 additions and 10 deletions

View file

@ -136,13 +136,20 @@ endpoints:
conditions:
- "[STATUS] == 200"
# TFX Video - ITA
- name: TF-X ITA Media Player
# TFX Video - ITA
# - name: TF-X ITA Media Player
# group: etl
# url: "http://100.85.225.183:1986/api/v1/streams"
# interval: 30m
# conditions:
# - "[STATUS] == 200"
- name: TF-X ITA Media Server
group: etl
url: "http://100.85.225.183:1986/api/v1/streams"
interval: 30m
url: "icmp://100.85.225.183"
interval: 5m
conditions:
- "[STATUS] == 200"
- "[CONNECTED] == true"
# NodeRed fleet — generated from config/node-red-instances.tsv
- name: staging

View file

@ -15,6 +15,9 @@ services:
# sqlite: GATUS_STORAGE_PATH=/data/gatus.db | memory: GATUS_STORAGE_PATH=
# ("-" not ":-": memory storage requires an explicitly EMPTY path)
GATUS_STORAGE_PATH: ${GATUS_STORAGE_PATH-postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@postgres:5432/${POSTGRES_DB}?sslmode=disable}
# Unprivileged ICMP for icmp:// endpoints (gatus runs as 65534, no caps)
sysctls:
net.ipv4.ping_group_range: "65534 65534"
volumes:
- ./config:/config:ro
- gatus-data:/data

View file

@ -27,6 +27,11 @@ podSecurityContext:
runAsUser: 65534
runAsGroup: 65534
fsGroup: 65534
# Allow unprivileged (UDP-socket) ICMP for icmp:// endpoints — gatus runs as
# 65534 without CAP_NET_RAW. Namespaced sysctl on the k8s safe list.
sysctls:
- name: net.ipv4.ping_group_range
value: "65534 65534"
securityContext:
allowPrivilegeEscalation: false
@ -240,13 +245,13 @@ config: |
conditions:
- "[STATUS] == 200"
# TFX Video - ITA
- name: TF-X ITA Media Player
# TFX Video - ITA (VPN mesh peer — needs the netbird sidecar enrolled)
- name: TF-X ITA Media Server
group: etl
url: "http://100.85.225.183:1986/api/v1/streams"
interval: 30m
url: "icmp://100.85.225.183"
interval: 5m
conditions:
- "[STATUS] == 200"
- "[CONNECTED] == true"
# NodeRed fleet — generated from config/node-red-instances.tsv
- name: staging