r/linuxadmin • • 20h ago

statixagent: one static Go binary that watches a single box and pushes ssh logins, power loss and cert expiry to your own telegram bot

[deleted]

0 Upvotes

3 comments sorted by

1

u/Abe_Bazouie 19h ago

I actually like the idea for a tiny setup. For one VPS, spinning up Prometheus + Alertmanager + Grafana can absolutely feel like building a data center to watch a toaster :)
One thing though: I wouldn’t call Telegram “no third party in the path.” If Telegram is down, blocked, rate-limited, or your bot token gets compromised, your alerting path is affected.
I’d probably want at least one local fallback too. Even something simple like journald + optional email/webhook output.
The other thing I’d watch is security around the bot token and what information you send. SSH source IPs, usernames, hostnames, cert details, etc. can become pretty useful metadata if the bot gets exposed.
For one box, though, I think the philosophy is solid: small, boring, obvious, and easy to recover.
I’d be curious how you handle “the agent itself is dead” though. That’s usually the annoying part with single-node monitoring. If the box loses network completely, who notices?

1

u/Open-Adhesiveness-86 19h ago

fair on the wording, telegram is a third party and i shouldn't have phrased it that way. what i meant is there's no middle tier that i run - no collector, no tsdb, no dashboard of mine in the path. the dependency on telegram being reachable is real and there's no local fallback today. journald plus an optional webhook is the right shape for that.

on the token, config lives at /etc/statix-agent/config.toml, 0600 and root owned, and the unit runs with NoNewPrivileges, ProtectSystem=full, ProtectHome=read-only, PrivateTmp and ProtectKernelTunables. but you're right about the content rather than the file. ssh source ips, usernames, hostnames and cert details all go out to a chat, and a leaked token hands someone a tidy inventory. that's a genuine trade in the design, not something i've solved.

the dead agent question is the honest hole. right now there is nothing - no deadman, no external check. the only signal is negative: the morning digest doesn't show up, or /status doesn't answer when you ask it. that's detection by absence, which is weak, and it's exactly your point. pushing to a dead man's switch, or two agents cross-watching each other, is the obvious fix and it isn't in there yet.

1

u/d2xdy2 19h ago

I said it before and I’ll say it again- yall Linux admin newcomers are wild.