From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4gfzM50yVjz333n for ; Tue, 16 Jun 2026 20:37:37 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4gfzM163vxz2xHy for ; Tue, 16 Jun 2026 20:37:33 +0000 (UTC) Received: from layka.disroot.org (layka.disroot.org [178.21.23.139]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client did not present a certificate) by mail01.ipfire.org (Postfix) with ESMTPS id 4gfzM11DMyz33B for ; Tue, 16 Jun 2026 20:37:33 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=fkfGfkcd; dmarc=pass (policy=reject) header.from=disroot.org; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1781642253; b=t4ryBwD0wZvOMyYJlNdAokE3LuOsizzfK0kCEcSNlFqiLzZfupaj3khYpnfEQ727yUxLCn xBrgOHr39A57jyqzcSAQbEPMqzk9TErBK1CTkiE0t/w8KEESMUvlbaUsNj/E/7rv1ll+Ja A6LIwKd+kTc7GoB3RBd2kyGrrB5vEHfuBmnvf6CtLU4TmypIEY6bO7ACBaD4l7dGwpaxMx cEFkS6xKFZLt2Qj7E9V0xzn/B22jEMPXZmwtHCkUw19cnzFl2mRME3+Jc70Lq/o11mOA24 auJ/gxF5GoNjEYESz9OtAaRUYnaIooTqC3/UU4yyACOtEaURTX0ZpPaBemXf5w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1781642253; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:dkim-signature; bh=Dr1CxyeMLnrcZcUbe1oYCAWucCwJbnQQw3pC/Lfo6s0=; b=oUc2t+qNS794aojaDpooe/sBXLlmx5aaXw6Py73WE8Yj5WkaL+GlME86RBXyxyj1TuMUlI Cik3EvJY8w5gm17dW7hHAwNQLr2VHR/a55akr2f4H7YaDxeo9va3UXtw0/a0Xi2sOJG9nl YX7PHNvKbT8uKFZGsOlNrg/OwJdN67RZgMXsFHTYBPTocjfszDtV8NqMuQEh2zzjdlRmQm 4j2geWXJl98uYJnLav9KQ9Lf6WnwWMpzK+a+KSHcc332pVKa/a8iuqlmfcIm/GiZQazprx 4kK9H0Ey5hMXu6u1eR6ZNHmI36doxK3XjPHkfueQC/Nnc6qFMubD+b5tlIVS4g== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=fkfGfkcd; dmarc=pass (policy=reject) header.from=disroot.org; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org Received: from mail01.disroot.lan (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id B8D6A27635 for ; Tue, 16 Jun 2026 22:37:32 +0200 (CEST) X-Virus-Scanned: SPAM Filter at disroot.org Received: from layka.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavis, port 10024) with ESMTP id 1eQ1XxZq5ll1 for ; Tue, 16 Jun 2026 22:37:32 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1781642252; bh=yi6lmfx654V4RSyXYZPJi8Iejnr+qbiBdmek1OMFmR4=; h=From:To:Subject:Date; b=fkfGfkcdPTJd2WxYf3hpL3QjNQOkhpDIK8Peo/5HLMFPpz0BER0q7DX2jRZmQ+TiQ ppdt31JHEAXcnbDg+QQh7i/yXX/LQyqIhxJLPUgyzcG3fbb/wA+sFE7hsWWmaqgFkJ 87R1lfSW5ahERaZaf21ZYcr6HvRxgb2pyiK6fwVAj2oRp9bBW+NpbpXf8bUeHmKkoi lBCKL0UJhlG2N68Y4QrTqy1bnY40sGsX6pyLEOyYlJsqTzxhaBNsWcK3JmO1ha5W3O qdAsyQCG9bH/+wocNxUKMSoGXVFFrQEf7ObZJLXLMVzJRgusKfdHECGT7X1aPzh5mv AWMba376EKJig== Received: from chojin.roevenslambrechts.be (chojin.roevenslambrechts.be [192.168.0.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (no client certificate requested) (Authenticated sender) by hachiman (MailScanner Milter) with SMTP id 3E0C554FC15 for ; Tue, 16 Jun 2026 22:37:22 +0200 (CEST) From: Robin Roevens To: development@lists.ipfire.org Subject: Knot resolver in CU 203: enable HTTP API Date: Tue, 16 Jun 2026 22:15:44 +0200 Message-ID: <20260616203719.1383402-1-robin.roevens@disroot.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-RoevensLambrechts-MailScanner-ID: 3E0C554FC15.A4A0D X-RoevensLambrechts-MailScanner: Found to be clean X-RoevensLambrechts-MailScanner-From: robin.roevens@disroot.org X-RoevensLambrechts-MailScanner-Watermark: 1782247043.90186@IWC7K4kOqERzLSNy6C/bxA X-Spamd-Result: default: False [-5.15 / 11.00]; BAYES_HAM(-3.00)[100.00%]; R_DKIM_ALLOW(-1.66)[disroot.org:s=mail]; MID_CONTAINS_FROM(1.00)[]; DKIM_REPUTATION(-0.93)[-0.93013458570948]; R_MISSING_CHARSET(0.50)[]; DMARC_POLICY_ALLOW(-0.50)[disroot.org,reject]; R_SPF_ALLOW(-0.20)[+a:c]; SPF_REPUTATION_HAM(-0.15)[-0.15089918156123]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.10)[disroot.org]; IP_REPUTATION_HAM(-0.01)[asn: 50673(0.00), country: NL(-0.01), ip: 178.21.23.139(0.00)]; TO_DN_NONE(0.00)[]; MISSING_XM_UA(0.00)[]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:50673, ipnet:178.21.23.0/24, country:NL]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; ARC_NA(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; FROM_EQ_ENVFROM(0.00)[]; RCVD_COUNT_THREE(0.00)[3]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; RCVD_TLS_LAST(0.00)[]; DKIM_TRACE(0.00)[disroot.org:+] X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4gfzM11DMyz33B X-Rspamd-Action: no action Hi all For Zabbix to be able to get knot-resolver metrics, I would like to have the HTTP API enabled (https://www.knot-resolver.cz/documentation/latest/manager-api.html). Receving the same metrics is currently already possible using kresctl however this is very slow and seems to use quite some resources (especially on my mini appliance v1: one cpu goes to 100% for 2s) while when using curl to get the metrics from the HTTP API, they are returned instantly without noticable cpu usage: Timings for kresctl: real 0m1.979s user 0m1.825s sys 0m0.126s Timings for curl using the http api: real 0m0.051s user 0m0.015s sys 0m0.018s And secondly, if I would use kresctl, I would need an additional config to zabbix_agent and sudoers to support calling that binary, while using the HTTP API is natively built in into the zabbix_agent and much more performant. I have added a patch that will enable the HTTP API in the knot resolver config. If possible, I would like this to be applied already to CU 203 so that I can release a Zabbix template to monitor knot without the need for additional changes to the zabbix_agent pak that would then probably have to wait for at least CU 204. Regards Robin -- Dit bericht is gescanned op virussen en andere gevaarlijke inhoud door MailScanner en lijkt schoon te zijn.