OTLP Collector上传Trace至Grafana Cloud Tempo报401未授权错误求助
OTLP Collector上传Grafana Cloud Tempo报401未授权的排查方案
核心问题分析
你的配置存在三个关键错误,导致认证失败:
- 地域端点不匹配:你的Tempo实例位于
eu-west-2区域,对应端点应为tempo-prod-10-prod-eu-west-2.grafana.net:443,但当前配置用了tempo-us-central1.grafana.net:443,请求发送到了错误实例。 - 重复配置认证冲突:同时启用
basicauth/otlp扩展和手动添加authorizationheader,两种方式相互干扰,导致凭证无法正确传递。 - 端点路径冗余:Grafana Cloud Tempo的gRPC端点不需要附加
/tempo路径,直接使用地域域名加端口即可。
修正后的配置示例
选择以下任意一种认证方式即可,推荐使用basicauth扩展(更符合OpenTelemetry规范):
方式一:使用basicauth扩展认证
extensions: basicauth/otlp: client_auth: username: <你的User Id> password: <你的API Access Token> receivers: otlp: protocols: grpc: http: exporters: otlp: auth: authenticator: basicauth/otlp endpoint: tempo-prod-10-prod-eu-west-2.grafana.net:443 tls: insecure: false service: extensions: [basicauth/otlp] pipelines: traces: receivers: [otlp] exporters: [otlp]
方式二:手动设置Authorization header
若不想使用扩展,直接配置header即可,注意不要同时启用basicauth扩展:
receivers: otlp: protocols: grpc: http: exporters: otlp: endpoint: tempo-prod-10-prod-eu-west-2.grafana.net:443 headers: authorization: Basic <你的Base64编码凭证> tls: insecure: false service: pipelines: traces: receivers: [otlp] exporters: [otlp]
额外验证步骤
- 确认
User Id和API Access Token正确:User Id是Grafana Cloud组织下Tempo实例对应的ID,不是账号邮箱;API Token需拥有metrics:write和traces:write权限。 - 重新生成Base64凭证时,确保命令
echo -n '<User Id>:<API Access Token>' | base64中无多余空格,-n参数避免添加换行符。
内容的提问来源于stack exchange,提问作者adkop
相关产品推荐
相关产品推荐

