Prometheus Alert Manager OAuth2凭证集成失败,邮件发送报错求助
初始配置与错误
我的AlertManager.yml片段如下:
global: smtp_smarthost: "smtp.office365.com:587" smtp_from: "noreply.myteam@myorg.com" http_config: oauth2: client_id: "76214c65-6283-4368-abbe-987********" client_secret: "Vp_8Q~********~97~*********~b~D" token_url: "https://login.microsoftonline.com/5d471751-917b-********/oauth2/v2.0/token" scopes: ["https://outlook.office365.com/.default"] tls_config: insecure_skip_verify: true endpoint_params: grant_type: "client_credentials"
加载AlertManager后,发送邮件时出现以下错误:
time=2025-05-08T15:16:47.536Z level=ERROR source=dispatch.go:360
msg="Notify for alerts failed" component=dispatcher num_alerts=1
err="email-alert/email[0]: notify retry canceled after 7 attempts:
send MAIL command: 530 5.7.57 Client not authenticated to send mail.
[*****.INDP287.PROD.OUTLOOK.COM 2025-05-08T15:16:42.409Z.****]"
我参考了相关文档,但不知道配置哪里出了问题?
更新后的尝试与新错误
我尝试了以下配置,但仍然失败,SMTP服务器将其识别为BASIC认证:
global: smtp_smarthost: 'smtp.office365.com:587' smtp_from: 'your-email@domain.com' smtp_auth_username: 'your-email@domain.com' smtp_auth_password: 'YOUR_ACCESS_TOKEN' smtp_require_tls: true
对应的错误信息:
err="email-alert/email[0]: notify retry canceled after 4 attempts:
email.loginAuth auth: 535 5.7.139 Authentication unsuccessful, basic authentication is disabled. [MA0***0074.INDPRD01.PROD.OUTLOOK.COM
2025-05-09T07:00:20.974Z ********]"
为什么即使提供了access_token,SMTP服务器还是把它当成基本认证?
问题分析与解决办法
初始配置无效原因
AlertManager的http_config.oauth2配置仅用于HTTP请求的OAuth2认证(比如Prometheus的HTTP抓取、webhook通知),完全不适用于SMTP邮件发送流程。你的第一个配置相当于没给SMTP设置任何有效认证,自然触发"未授权"的530错误。更新后配置失败原因
AlertManager原生不支持SMTP协议的OAuth2认证,当你把access_token填入smtp_auth_password时,它会默认使用SMTP BASIC/PLAIN认证方式发送凭据,而Office365已经禁用了基本认证,因此返回535错误。可行解决方案
- 方案一:使用第三方邮件代理
部署支持SMTP OAuth2的代理服务(如msmtp配合OAuth2配置),让AlertManager将邮件发送到本地代理,再由代理完成OAuth2认证后转发至Office365 SMTP。 - 方案二:改用Graph API发送邮件
放弃SMTP方式,配置AlertManager通过webhook调用Microsoft Graph API的/sendMail接口发送邮件。需要给应用注册添加Mail.Send应用权限,并在webhook中配置OAuth2令牌获取逻辑。
内容的提问来源于stack exchange,提问作者raikumardipak

