servers/roles/collector/files/prometheus.nft
Timotej Lazar da3db8cc02 Add collector role
Sets up prometheus to pull metrics, with telegraf to process SNMP data.
2025-10-17 22:12:02 +02:00

12 lines
519 B
Text

table inet filter {
chain output {
type filter hook output priority 0; policy accept;
skuid prometheus ct state { established, related } accept
skuid prometheus th dport domain accept
skuid prometheus tcp dport { 443, 9100 } accept comment "prometheus"
skuid prometheus ip daddr 127.0.0.1 tcp dport 9090 accept comment "prometheus self"
skuid prometheus ip daddr 127.0.0.1 tcp dport 9273 accept comment "telegraf snmp exporter"
skuid prometheus drop
}
}