Reference
The 22 checks
Each check reads one thing on the server and reports it in one sentence, with the command that fixes it. The words on these pages come from the same file the agent prints from.
22 of 22 checks are built today: 8 health, 9 security and 5 data location. A scan never counts a check that did not run as passed.
Health
- LoadThe 15-minute load average in /proc/loadavg and the number of CPU cores in /proc/cpuinfo.
- Memory and swapMemory and swap totals in /proc/meminfo.
- DiskThe mounted file systems in /proc/self/mounts, and the space and inodes on each.
- ContainersEach container's state, restart count and health status, read from the Docker socket.
- Out-of-memory killsThe kernel log for the last 24 hours, through journalctl or /var/log/kern.log.
- SSL certificatesThe certificates in /etc/letsencrypt/live, Caddy's certificate folders, and the certificate files named in nginx and Apache settings.
- BackupsThe age of the newest file in each backup folder named in /etc/kiyesi/config.yaml.
- Pending updatesThe security updates apt has waiting, from a dry run that changes nothing (apt-get -s upgrade), and the date Kiyesi first saw each one.
Security
- Open portsThe ports listening on public addresses, from /proc/net/tcp and /proc/net/tcp6, and the ports Docker publishes.
- Exposed databasesWhether MongoDB, Redis, PostgreSQL or MySQL listen on a public address or are published by Docker, and whether the firewall on this server blocks them.
- Docker bypassing the firewallThe ports Docker publishes on all addresses, and the ufw rules for them.
- SSH settings/etc/ssh/sshd_config and the files in /etc/ssh/sshd_config.d.
- FirewallWhether ufw, firewalld or an nftables or iptables rule set is on.
- Login attack protectionWhether fail2ban, sshguard or CrowdSec is running, and whether SSH allows password login.
- Secrets in filesEnvironment files, Compose files and shell history in the folders listed under secrets.paths in /etc/kiyesi/config.yaml. Kiyesi reports where a secret is, never its value.
- Risky containersEach running container's settings for privileged mode, mounted volumes and user, read from the Docker socket.
- Known vulnerabilitiesSystem packages and container images, checked by Trivy if it is already installed. Kiyesi never downloads Trivy or its database during a scan.
Data location
- Server locationThe cloud provider's own details: /run/cloud-init/instance-data.json, the maker in /sys/class/dmi/id/sys_vendor, and the provider's metadata address on its local network (169.254.169.254). Nothing is sent there; the scan only reads the region.
- Database connectionsThe database hosts in env files, Compose files and connection settings in the folders under secrets.paths. Only the host and port are kept, never the user or password.
- Backup destinationsThe storage targets in rclone settings, restic repositories, AWS CLI settings, and the backup commands in cron jobs and scripts under secrets.paths.
- Outside servicesThe log, monitoring, email and SMS services named in env files and Compose files, such as Sentry, SMTP hosts, Twilio and Termii.
- Payment data tagThe databases listed under payment_data in /etc/kiyesi/config.yaml.