Skip to content

Monitoring $5 boxes without installing agents

General Discussion by haroldgsm 2 replies 106 views
#1

Back when we all ran bare metal in colos, you had exactly two tools: whatever the switch exposed via SNMP, and whatever you could scrape over the network. Kids these days think they need a 200MB Go binary on every VM to know if the CPU is warm. You do not.

Option 1: SNMP-only
Enable snmpd, lock it to your poller IP, read the standard OIDs. Load, memory, disk, network. Takes 2MB RAM. Works on a 128MB OpenVZ slice from 2011, mark my words.

Option 2: blackbox_exporter
Run it on one decent box. Probe the rest for HTTP, TCP, ICMP, whatever you exposed. You learn the service is up; you infer the host is not on fire. Good enough for a $5 VM hosting your static blog.

Both approaches leak nothing to the provider's monitoring. Both survive apt upgrade without surprise dependency hell. In twenty years in this business, the simple stuff still wins. The fancy agent will be abandoned by its vendor in eighteen months, and you'll be migrating again.

IPv4, IRC, and irssi — fight me
3 #2

What about SNMP community string? In my country we see brute force on port 161 every day. You use view restrict or VPN tunnel?

phở at 3AM, deploy at 4
#3

Simple is better, and SNMP is not
Snmp v3 or do not bother

rm -rf / --no-preserve-root ☯

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft