You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

迁移至aws-loadbalancer-controller后Prometheus/AlertManager UI访问404问题

AWS ALB Controller 下 Prometheus/AlertManager 访问404问题排查与解决

问题描述

我正从ingress-nginx-controller迁移到aws-loadbalancer-controller,通过Ingress为K8S集群内多个UI提供访问,目标是用单个ALB路由ArgoCD、Grafana、Prometheus和AlertManager的请求。目前ArgoCD和Grafana可正常访问,AlertManager与Prometheus的Pod IP已成功注册到对应目标组且状态健康,但存在以下问题:

  • 浏览器访问Prometheus URL时,/graph重定向返回404;但在集群内其他Pod中执行curl -L http://prom-pod-ip:9090可正常重定向至/graph。
  • AlertManager UI请求时加载script.js返回404。

当前Prometheus的Ingress配置如下:

ingress:
    enabled: true
    annotations:
      #kubernetes.io/tls-acme: "true"
      kubernetes.io/ingress.class: alb
      alb.ingress.kubernetes.io/scheme: internal
      alb.ingress.kubernetes.io/group.name: internal-support
      alb.ingress.kubernetes.io/listen-ports: '[{"HTTPS":443}]'
      alb.ingress.kubernetes.io/certificate-arn: {{ .Values.internalIngress.sslCertArn }}
      alb.ingress.kubernetes.io/healthcheck-path: "/graph"
      alb.ingress.kubernetes.io/healthcheck-port: "traffic-port"
      alb.ingress.kubernetes.io/healthcheck-interval-seconds: '10'
      alb.ingress.kubernetes.io/healthcheck-timeout-seconds: '5'
      alb.ingress.kubernetes.io/healthy-threshold-count: '2'
      alb.ingress.kubernetes.io/unhealthy-threshold-count: '2'
      alb.ingress.kubernetes.io/tags: {{ .Values.internalIngress.resourceTags }}
      alb.ingress.kubernetes.io/target-type: ip
      alb.ingress.kubernetes.io/ssl-policy: ELBSecurityPolicy-TLS-1-2-2017-01
    hosts:
      - demo.product.company.com 

已尝试调整hosts(如使用demo.product.company.com/*)、添加externalUrl配置等方案,但均未解决问题。

问题根源分析

Prometheus和AlertManager的UI依赖正确的根路径配置,当通过ALB路由时,如果没有明确指定服务的外部访问路径,服务会将请求路径解析为集群内部的路径,导致静态资源或重定向路径不匹配,从而返回404。

具体解决步骤

1. 修复Prometheus访问问题

(1)修改Ingress配置,添加路径规则与重写

为Prometheus分配独立路径前缀(如/prometheus),并配置ALB路径重写,确保请求正确转发:

ingress:
    enabled: true
    annotations:
      # 保留原有注解,新增路径匹配与重写配置
      alb.ingress.kubernetes.io/conditions.prometheus: |
        [{"field":"path-pattern","pathPatternConfig":{"values":["/prometheus/*"]}}]
      alb.ingress.kubernetes.io/actions.prometheus: |
        {"type":"forward","forwardConfig":{"targetGroups":[{"serviceName":"prometheus-server","servicePort":"9090"}],"pathPatternConfig":{"pathPattern":"/prometheus/*","rewrite":{"target":"/$1"}}}}}
      # 原有注解保留...
    hosts:
      - demo.product.company.com
    paths:
      - path: /prometheus/*
        pathType: ImplementationSpecific
        backend:
          service:
            name: prometheus-server
            port:
              number: 9090

(2)配置Prometheus的external-url

在Prometheus的Helm values或Deployment中设置外部访问URL,确保服务生成的重定向和静态资源路径匹配:

prometheus:
  server:
    externalUrl: "https://demo.product.company.com/prometheus"
    routePrefix: "/"

2. 修复AlertManager访问问题

(1)修改AlertManager的Ingress配置

同样为AlertManager分配独立路径前缀(如/alertmanager)并配置重写:

ingress:
    enabled: true
    annotations:
      alb.ingress.kubernetes.io/conditions.alertmanager: |
        [{"field":"path-pattern","pathPatternConfig":{"values":["/alertmanager/*"]}}]
      alb.ingress.kubernetes.io/actions.alertmanager: |
        {"type":"forward","forwardConfig":{"targetGroups":[{"serviceName":"alertmanager-main","servicePort":"9093"}],"pathPatternConfig":{"pathPattern":"/alertmanager/*","rewrite":{"target":"/$1"}}}}}
      # 复用ALB共用注解(如ingress.class、scheme等)
    hosts:
      - demo.product.company.com
    paths:
      - path: /alertmanager/*
        pathType: ImplementationSpecific
        backend:
          service:
            name: alertmanager-main
            port:
              number: 9093

(2)配置AlertManager的external-url

在AlertManager的配置中指定外部访问URL:

alertmanager:
  config:
    global:
      external_url: "https://demo.product.company.com/alertmanager/"

3. 验证配置生效

  • 应用修改后的配置:kubectl apply -f <你的配置文件.yaml>
  • 等待ALB规则更新完成(约1-2分钟)
  • 访问https://demo.product.company.com/prometheus/graph和https://demo.product.company.com/alertmanager验证是否正常加载

关键注意事项

  • 禁止用根路径(/)同时映射多个服务,必须为每个服务分配独立路径前缀,避免路径冲突
  • ALB的路径重写规则必须正确,确保将/prefix/*重写为/*后转发到后端服务
  • Prometheus和AlertManager的externalUrl必须严格匹配外部访问的完整URL(包含路径前缀),否则静态资源和重定向路径会出错

内容的提问来源于stack exchange,提问作者user2295803

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 01:42:38