You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为作为JavaAgent运行的Kafka配置JMX Exporter的SSL?

为JMX Exporter暴露的Kafka指标端口配置SSL失败

环境信息

  • 运行环境:AWS Kubernetes集群
  • 使用组件:Kafka,搭配jmx_prometheus_javaagent-1.0.1.jar(该工具最新版本支持SSL)
  • 需求:对JMX Exporter暴露的Kafka指标端口启用SSL保护,但配置后无法生效

当前Pod内的Config.yaml配置

lowercaseOutputName: true
ssl: 
  keyStore: /etc/identity/certificates/peer.pem 
  keyStorePassword: /etc/identity/keys/peer-key.pem 
  trustStore: /etc/identity/ca/cacerts.pem

rules:
- pattern : kafka_controller<type=(KafkaController), name=(ActiveControllerCount|OfflinePartitionsCount)><>Value
  name: kafka_controller_$1_$2

本地验证操作步骤

执行端口转发命令:

kubectl port-forward kafka 9100:9100

使用curl携带证书请求指标接口:

curl -vk https://localhost:9100/metrics --cacert /etc/identity/ca/cacert.pem --key /etc/identity/client/keys/client-key.pem --cert /etc/identity/client/certificates/client.pem

内容的提问来源于stack exchange,提问作者curious_cat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 15:17:31