I'm trying to find a way to poll for any zones where knot is currently
waiting on DS submission to the parent.

I'm aware of the structured logging sent to systemd-journald but I see
this as not particularly useful for monitoring, as the event could be
missed by a dead daemon, bug in code, etc.  I'd much prefer to be able
to actively monitor states by polling.

It looks like the only way I can do that right now is to run `keymgr
list` and analyze the output.  If I'm reading the documentation
correctly, all I need to look for is a key that is `ksk=yes`, `ready
!= 0`, and `active = 0`.

Does that seem correct?  Am I missing something simpler? :)
--

Reply via email to