如何通过HTTPS连接Grafana与Loki?证书配置问题排查
Grafana与Loki HTTPS双向认证配置问题排查
问题背景
已获取组织签发的CA.cer及带密码保护的pfx文件(含双方私钥、公钥、证书链),并从pfx导出Grafana和Loki各自的私钥与证书链,配置了双方的HTTPS服务,但Grafana连接Loki数据源时失败,HTTP连接正常。
当前配置
Grafana HTTPS配置(grafana.ini)
[server] protocol = https http_addr = 0.0.0.0 http_port = 3000 domain = grafana.xyz.net enforce_domain = false root_url = %(protocol)s://%(domain)s:%(http_port)s/ cert_file = /opt/grafana/certs/grafana.xyz.net.cer cert_key = /opt/grafana/certs/grafana.xyz.net.key
Loki HTTPS配置(loki.yaml)
server: http_listen_port: 3100 grpc_listen_port: 9096 http_tls_config: client_auth_type: RequireAndVerifyClientCert client_ca_file: /opt/loki/certs/loki_CA_.cer cert_file: /opt/loki/certs/loki.xyz.net.cer key_file: /opt/loki/certs/loki.xyz.net.key grpc_tls_config: client_auth_type: RequireAndVerifyClientCert client_ca_file: /opt/loki/certs/loki_CA_.cer cert_file: /opt/loki/certs/loki.xyz.net.cer key_file: /opt/loki/certs/loki.xyz.net.key
错误日志
Grafana日志
logger=context userId=1 orgId=1 uname=admin t=2023-08-24T16:50:55.86218229+03:00 level=error msg="Failed to call resource" error="Get \"https://loki.xyz.net:3100/loki/api/v1/labels?start=1692884455845000000&end=1692885055845000000\": tls: failed to verify certificate: x509: certificate signed by unknown authority" traceID=
Loki日志
TLS handshake error from 10.244.199.30:33762: remote error: tls: bad certificate
缺失配置与修复方案
1. Grafana侧补充Loki证书信任及客户端认证配置
Grafana未信任签发Loki证书的组织根CA,导致证书验证失败;同时Loki要求强制客户端认证,Grafana需提供自身证书供Loki验证。
控制台配置方式
在Grafana控制台的Loki数据源配置页面:
- 进入HTTP > TLS/SSL区域
- 勾选With CA Cert,上传组织根CA文件
CA.cer(或填写文件路径/opt/grafana/certs/CA.cer) - 勾选With Client Cert,分别上传Grafana的证书
grafana.xyz.net.cer和私钥grafana.xyz.net.key - 确保Skip TLS Verify处于未勾选状态
配置文件方式(grafana.ini)
添加或修改Loki数据源配置段:
[datasources.loki] type = loki url = https://loki.xyz.net:3100 access = proxy tls_ca_cert = /opt/grafana/certs/CA.cer tls_client_cert = /opt/grafana/certs/grafana.xyz.net.cer tls_client_key = /opt/grafana/certs/grafana.xyz.net.key tls_skip_verify = false
2. Loki侧替换客户端信任CA为组织根CA
Loki当前配置的client_ca_file是自身CA,而非签发Grafana证书的组织根CA,导致无法验证Grafana的客户端证书。
修改Loki配置文件(loki.yaml),将http_tls_config和grpc_tls_config中的client_ca_file替换为组织根CA:
server: http_listen_port: 3100 grpc_listen_port: 9096 http_tls_config: client_auth_type: RequireAndVerifyClientCert client_ca_file: /opt/loki/certs/CA.cer # 替换为组织根CA文件 cert_file: /opt/loki/certs/loki.xyz.net.cer key_file: /opt/loki/certs/loki.xyz.net.key grpc_tls_config: client_auth_type: RequireAndVerifyClientCert client_ca_file: /opt/loki/certs/CA.cer # 替换为组织根CA文件 cert_file: /opt/loki/certs/loki.xyz.net.cer key_file: /opt/loki/certs/loki.xyz.net.key
3. 验证证书域名匹配
确认Loki证书的CN或SAN字段包含loki.xyz.net,Grafana证书的CN或SAN字段包含grafana.xyz.net,避免域名不匹配导致的验证失败。
重启服务
修改配置后,分别重启Grafana和Loki服务,重新测试数据源连接。
内容的提问来源于stack exchange,提问作者Mahirq8
相关产品推荐
相关产品推荐

