title: MKP Updates: Extension package update check
agents: special/mkp_updates
catalog: os/misc
license: GPL-2.0-only
distribution: check_mk
description:
 Monitors the MKP extension packages installed on this Checkmk site for
 available updates. For every package whose manifest has a Download-URL,
 the special agent determines the latest version via the matching git
 provider's REST API (GitHub, GitLab, Gitea/Forgejo) or, for anything
 else including an offline server, {git ls-remote --tags}. Which
 provider applies is detected automatically at runtime.

 For packages that still have no usable version afterwards, the Checkmk
 Exchange catalog is checked as a fallback, matched by package name.
 This is disableable ("Also check Checkmk Exchange" in the rule); it
 always fetches the whole catalog in one request, cached for 24 hours
 regardless of check interval - see the README for the full design.

 One service "MKP Updates" is created per host. Its summary shows the
 total number of installed packages and how many have an update
 available; the service details list every package, grouped by status,
 with its installed/latest version, the provider used, and its Homepage
 (Download-URL) address, clickable via Checkmk's automatic URL
 detection.

 Configured under Setup > Agents > Other integrations > MKP Updates
 (source/timeouts/credentials) and the service monitoring rule MKP
 Updates (thresholds, states, exclusions).

item:
 This check has no item: exactly one "MKP Updates" service is created
 per host.

discovery:
 One service is discovered whenever the special agent returns a
 mkp_updates section, regardless of how many packages are installed.

check:
 Goes {WARN}/{CRIT} once the number of packages with an available update
 reaches the configured levels (default: {WARN} at 1). Packages without a
 Download-URL or that could not be checked (network error, no
 releases/tags found) contribute their own, separately configurable
 state to the service.

notes:
 Assign the special agent's rule to a host representing this Checkmk
 site itself (e.g. "localhost"), not a remote host - it inspects the
 packages of the site it runs in.

 IMPORTANT: do not use Checkmk's default 1-minute check interval.
 GitHub's 60 requests/hour unauthenticated rate limit can be exhausted
 by a single run alone on sites with more than ~20 GitHub-hosted
 packages. Set "Normal check interval for service checks" (for the
 "Check_MK" service on this host) to at least 60 minutes, and/or add a
 GitHub token in the special agent rule (raises the limit to 5000/hour).

 If a package name has several stored versions at once, only one is
 checked - the active version wins, then inactive-but-enabled, then the
 highest-numbered disabled leftover - so each package name is checked
 once per run regardless of how many old versions remain in the store.

 On sites with many packages, the service details can exceed Checkmk's
 own default 2 kB display limit ("Lost data due to truncation of long
 output") - unrelated to this extension, raise it under Setup > General
 > Global settings > "Maximum long output size" (display-only, never
 affects the summary or state). The special agent rule's "Sections
 shown in the service details" setting is another way to keep it short.
