You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用TLS后GKE中Google托管Prometheus监控失败问题

问题描述

在GKE上运行应用,启用Google托管Prometheus(GMP)后原本监控正常。给应用启用外部通信TLS并重启后,监控服务出现证书验证失败的错误。按照GMP文档使用PodMonitor配置,但未找到对应的TLS配置项——仅Alert Manager和Prometheus Operator有相关配置,而GKE自行运行Operator,只需创建PodMonitor指向应用即可。

应用侧报错信息

2024-03-01 13:07:03,833 ERROR [prometheus-metrics-server-0] HOST: Failed to process request.
io.netty.handler.codec.DecoderException: io.netty.handler.ssl.ReferenceCountedOpenSslEngine$OpenSslHandshakeException: error:10000412:SSL routines:OPENSSL_internal:SSLV3_ALERT_BAD_CERTIFICATE

当前PodMonitor配置

# see https://github.com/GoogleCloudPlatform/prometheus-engine/blob/v0.7.0/doc/api.md  for more fields
# if we use TLS, we need to configure a TLSConfig
apiVersion: monitoring.googleapis.com/v1
kind: PodMonitoring
metadata:
  name: google-prom
  labels:
    examplelabel: test123
    examplelabel2: test1234
spec:
  selector:
    matchLabels:
      name: voltdb-cluster
      #app.kubernetes.io/name: voltdb-cluster
  endpoints:
  # this should be >= the interval that we create the metrics for
  - interval: 10s
    # the default is /metrics
    path: /metrics
    port: 11781
    scheme: https
    metricRelabeling:
    - action: drop
      regex: connection_.*
      sourceLabels: [__name__]
  targetLabels:
    metadata:
    - node
    - container
    - pod
    fromPod:
    - from: clustertype
      to: clustertype
    - from: testname
      to: testname
    - from: testid
      to: testid
    - from: branch
      to: branch

解决方案

GMP的PodMonitoring资源支持在endpoints字段中配置tlsConfig,用于处理HTTPS采集的证书验证问题,以下是几种常见场景的配置方式:

1. 临时禁用证书验证(仅测试环境)

如果是自签名证书导致的验证失败,可临时跳过验证(生产环境不推荐):

spec:
  endpoints:
  - interval: 10s
    path: /metrics
    port: 11781
    scheme: https
    tlsConfig:
      insecureSkipVerify: true  # 禁用证书验证
    metricRelabeling:
    - action: drop
      regex: connection_.*
      sourceLabels: [__name__]
  # 其他原有配置保持不变...

2. 使用自定义CA证书验证

如果应用使用自己的CA签发证书,需要将CA证书存入Kubernetes Secret,然后在PodMonitor中引用:

步骤1:创建CA证书Secret

kubectl create secret generic metrics-ca --from-file=ca.crt=/path/to/your/ca.crt

步骤2:修改PodMonitor配置

spec:
  endpoints:
  - interval: 10s
    path: /metrics
    port: 11781
    scheme: https
    tlsConfig:
      caFile: /etc/prometheus/secrets/metrics-ca/ca.crt  # 证书挂载路径
    secretMounts:  # 挂载Secret到采集器容器
    - name: metrics-ca
      mountPath: /etc/prometheus/secrets/metrics-ca
      readOnly: true
    metricRelabeling:
    - action: drop
      regex: connection_.*
      sourceLabels: [__name__]
  # 其他原有配置保持不变...

3. 客户端证书认证(双向TLS)

如果应用要求采集端提供客户端证书,需将客户端证书、密钥和CA证书存入Secret,再配置PodMonitor:

步骤1:创建客户端证书Secret

kubectl create secret generic metrics-client --from-file=ca.crt=/path/to/ca.crt --from-file=tls.crt=/path/to/client.crt --from-file=tls.key=/path/to/client.key

步骤2:修改PodMonitor配置

spec:
  endpoints:
  - interval: 10s
    path: /metrics
    port: 11781
    scheme: https
    tlsConfig:
      caFile: /etc/prometheus/secrets/metrics-client/ca.crt
      certFile: /etc/prometheus/secrets/metrics-client/tls.crt
      keyFile: /etc/prometheus/secrets/metrics-client/tls.key
    secretMounts:
    - name: metrics-client
      mountPath: /etc/prometheus/secrets/metrics-client
      readOnly: true
    metricRelabeling:
    - action: drop
      regex: connection_.*
      sourceLabels: [__name__]
  # 其他原有配置保持不变...

内容的提问来源于stack exchange,提问作者Kajal Jadeja

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 12:05:55