You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过HTTPS连接Grafana与Loki?证书配置问题排查

Grafana与Loki HTTPS双向认证配置问题排查

问题背景

已获取组织签发的CA.cer及带密码保护的pfx文件(含双方私钥、公钥、证书链),并从pfx导出Grafana和Loki各自的私钥与证书链,配置了双方的HTTPS服务,但Grafana连接Loki数据源时失败,HTTP连接正常。

当前配置

Grafana HTTPS配置(grafana.ini)

[server]
protocol = https
http_addr = 0.0.0.0
http_port = 3000
domain = grafana.xyz.net
enforce_domain = false
root_url = %(protocol)s://%(domain)s:%(http_port)s/
cert_file = /opt/grafana/certs/grafana.xyz.net.cer
cert_key = /opt/grafana/certs/grafana.xyz.net.key

Loki HTTPS配置(loki.yaml)

server:
  http_listen_port: 3100
  grpc_listen_port: 9096

  http_tls_config:
   client_auth_type: RequireAndVerifyClientCert    
   client_ca_file: /opt/loki/certs/loki_CA_.cer   
   cert_file: /opt/loki/certs/loki.xyz.net.cer
   key_file: /opt/loki/certs/loki.xyz.net.key
    
  grpc_tls_config:
   client_auth_type: RequireAndVerifyClientCert
   client_ca_file: /opt/loki/certs/loki_CA_.cer   
   cert_file: /opt/loki/certs/loki.xyz.net.cer
   key_file: /opt/loki/certs/loki.xyz.net.key

错误日志

Grafana日志

logger=context userId=1 orgId=1 uname=admin t=2023-08-24T16:50:55.86218229+03:00 level=error msg="Failed to call resource" error="Get \"https://loki.xyz.net:3100/loki/api/v1/labels?start=1692884455845000000&end=1692885055845000000\": tls: failed to verify certificate: x509: certificate signed by unknown authority" traceID=

Loki日志

TLS handshake error from 10.244.199.30:33762: remote error: tls: bad certificate

缺失配置与修复方案

1. Grafana侧补充Loki证书信任及客户端认证配置

Grafana未信任签发Loki证书的组织根CA,导致证书验证失败;同时Loki要求强制客户端认证,Grafana需提供自身证书供Loki验证。

控制台配置方式

在Grafana控制台的Loki数据源配置页面:

  • 进入HTTP > TLS/SSL区域
  • 勾选With CA Cert,上传组织根CA文件CA.cer(或填写文件路径/opt/grafana/certs/CA.cer)
  • 勾选With Client Cert,分别上传Grafana的证书grafana.xyz.net.cer和私钥grafana.xyz.net.key
  • 确保Skip TLS Verify处于未勾选状态

配置文件方式(grafana.ini)

添加或修改Loki数据源配置段:

[datasources.loki]
type = loki
url = https://loki.xyz.net:3100
access = proxy
tls_ca_cert = /opt/grafana/certs/CA.cer
tls_client_cert = /opt/grafana/certs/grafana.xyz.net.cer
tls_client_key = /opt/grafana/certs/grafana.xyz.net.key
tls_skip_verify = false

2. Loki侧替换客户端信任CA为组织根CA

Loki当前配置的client_ca_file是自身CA,而非签发Grafana证书的组织根CA,导致无法验证Grafana的客户端证书。

修改Loki配置文件(loki.yaml),将http_tls_config和grpc_tls_config中的client_ca_file替换为组织根CA:

server:
  http_listen_port: 3100
  grpc_listen_port: 9096

  http_tls_config:
   client_auth_type: RequireAndVerifyClientCert    
   client_ca_file: /opt/loki/certs/CA.cer   # 替换为组织根CA文件
   cert_file: /opt/loki/certs/loki.xyz.net.cer
   key_file: /opt/loki/certs/loki.xyz.net.key
    
  grpc_tls_config:
   client_auth_type: RequireAndVerifyClientCert
   client_ca_file: /opt/loki/certs/CA.cer   # 替换为组织根CA文件
   cert_file: /opt/loki/certs/loki.xyz.net.cer
   key_file: /opt/loki/certs/loki.xyz.net.key

3. 验证证书域名匹配

确认Loki证书的CN或SAN字段包含loki.xyz.net,Grafana证书的CN或SAN字段包含grafana.xyz.net,避免域名不匹配导致的验证失败。

重启服务

修改配置后,分别重启Grafana和Loki服务,重新测试数据源连接。

内容的提问来源于stack exchange,提问作者Mahirq8

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 11:14:52