title: Update Cache Age: Age of a Package Manager's Update Metadata Cache
agents: linux, windows
catalog: os/misc
license: GPLv2
distribution: check_mk
description:
 Reports how old a package manager's local update metadata cache is (e.g. the
 result of {apt update}, {dnf makecache}, {zypper refresh}). A stale cache means
 the {Pending Updates} service's counts -- especially the security count -- may be
 understated: an update that was released after the last refresh isn't visible yet.

 This check goes {WARN}/{CRIT} based on the cache's age, configurable via the
 check's parameters (default {WARN} at 3 days, {CRIT} at 7 days). If the cache was
 refreshed during the same check run that produced this data, that is noted
 separately in the service details.

 Also warns ({WARN}, never escalates the service to a harder failure) if no
 security repository could be detected as configured for this backend -- currently
 determinable for {apt} only. Absence of this warning does not itself confirm a
 security repository is configured; it only means this can't be determined for the
 given backend.

 On Windows ({windows_update}), this service also shows when Windows' own automatic
 update scan is switched off (Group Policy {NoAutoUpdate=1}, Windows Update service
 {wuauserv} disabled, or Automatic Updates disabled), including which of these
 applies. If the agent rule's "Refresh before checking" is "Never", the update
 information is then never refreshed, and the service goes to a configurable state
 (default {WARN}); if the plug-in refreshes the information itself ("Always" or
 "Only if older than"), it is shown as information only ({OK}).

item:
 The package manager backend this cache belongs to, e.g. {apt}, {dnf}, {zypper},
 {apk}, {windows_update}.

discovery:
 One service is created per backend reported in the {system_updates_info} agent
 section's {package_managers} list, i.e. one per package manager actually detected
 on the host -- not one per host. On Windows, {windows_update} is discovered even if
 no cache age could be determined (e.g. Windows Update service disabled).
