如何将GKE集群中Netdata父容器指标写入Google Managed Prometheus?
将Netdata指标推送到Google Managed Prometheus(GMP)的配置说明
关键问题答案
GMP支持Prometheus Remote Write协议吗?
完全支持,这是GMP官方认可的指标写入方式,兼容标准的Prometheus Remote Write规范。GMP的远程写入端点格式
端点地址需要根据你的Google Cloud项目和集群区域调整,格式如下:https://<集群所在区域>-gmp.googleapis.com/v1/projects/<你的项目ID>/remote/write比如你的集群在
us-east1,项目ID是my-gcp-project,端点就是https://us-east1-gmp.googleapis.com/v1/projects/my-gcp-project/remote/write。
GKE中Netdata的具体配置步骤
修改Netdata的导出配置
在Netdata的配置目录下创建或编辑prometheus_remote_write.conf文件,添加针对GMP的配置:[exporting:prometheus_remote_write:gmp] enabled = yes destination = <集群所在区域>-gmp.googleapis.com port = 443 path = /v1/projects/<你的项目ID>/remote/write data source = average # 可根据需求选择raw、sum等 prefix = netdata_ # 给Netdata指标加前缀,方便在GMP中识别 timeout ms = 10000 ssl enabled = yes配置Workload Identity认证
GMP要求请求携带有效的Google Cloud身份凭证,在GKE中用Workload Identity是最安全的方式:- 创建一个Google Cloud IAM服务账号,给它绑定
roles/monitoring.metricWriter角色(该角色拥有写入指标的权限) - 在Kubernetes中创建一个ServiceAccount,将其与上述IAM服务账号绑定
- 修改Netdata的Deployment,指定
serviceAccountName为这个K8s ServiceAccount,确保Pod能自动获取身份凭证
- 创建一个Google Cloud IAM服务账号,给它绑定
验证推送是否成功
重启Netdata Pod后,查看Pod日志确认没有remote write相关的错误。然后登录Google Cloud控制台,进入GMP的指标浏览器,搜索带netdata_前缀的指标,就能看到推送过来的数据了。
内容的提问来源于stack exchange,提问作者Matanya
相关产品推荐
相关产品推荐

