You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS集群中Apisix Prometheus目标Down问题排查求助

Apisix Prometheus指标采集失败排查(Prometheus目标Down)

问题描述

在EKS集群中通过Helm Chart部署Apisix作为API网关,已按要求配置Prometheus插件及ServiceMonitor,但Prometheus显示Apisix目标状态为Down。已完成以下操作:

  • 在gateway命名空间创建ServiceMonitor
  • 在ConfigMap的config.yaml中配置Prometheus插件
  • 将插件导出IP从127.0.0.1改为0.0.0.0
  • 可从Apisix-gateway服务的localhost获取指标,但Prometheus无法采集

已配置内容

ServiceMonitor配置

apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
  name: apisix-metrics
  labels:
    app: apisix
spec:
  namespaceSelector:
    matchNames:
      - gateway
  selector:
    matchLabels:
      helm.sh/chart: apisix-2.1.0
      app.kubernetes.io/name: apisix
      app.kubernetes.io/instance: apisix
      app.kubernetes.io/version: "3.4.0"
      app.kubernetes.io/managed-by: Helm
      app.kubernetes.io/service: apisix-gateway
  endpoints:
    - scheme: http
      targetPort: prometheus
      path: /apisix/prometheus/metrics
      interval: 15s

Apisix插件配置

plugins:
  - prometheus
plugin_attr:
  prometheus:
    export_uri: /apisix/prometheus/metrics
    metrics: apisix_
    enable_export_server: true
    export_addr:
      ip: 0.0.0.0
      port: 9091

排查步骤

  • 验证ServiceMonitor标签匹配
    执行命令查看Apisix Gateway Service的实际标签,与ServiceMonitor的spec.selector.matchLabels对比,确保无拼写或版本号不匹配问题:

    kubectl get svc apisix-gateway -n gateway --show-labels
    
  • 检查Apisix Service端口暴露
    确认Apisix Service已暴露Prometheus对应的9091端口,且端口名称为prometheus:

    kubectl get svc apisix-gateway -n gateway -o yaml
    

    需确保ports字段包含:

    - name: prometheus
      port: 9091
      targetPort: 9091
      protocol: TCP
    

    若缺失,需通过Helm values或直接修改Service补充配置。

  • 测试Prometheus到Apisix的网络连通性
    进入Prometheus Pod内部,测试能否访问Apisix的metrics端点:

    kubectl exec -it <prometheus-pod-name> -n <prometheus-namespace> -- /bin/sh
    curl http://apisix-gateway.gateway.svc.cluster.local:9091/apisix/prometheus/metrics
    

    若无法访问,排查EKS网络策略、安全组是否限制了9091端口的跨命名空间访问。

  • 确认Apisix插件配置生效
    查看Apisix Pod日志,验证Prometheus插件是否加载成功:

    kubectl logs <apisix-pod-name> -n gateway | grep prometheus
    

    检查日志中是否有插件初始化成功、export_addr配置正确应用的记录。

  • 检查Prometheus的ServiceMonitor发现规则
    确认Prometheus CRD配置的serviceMonitorSelector能匹配到app: apisix标签:

    kubectl get prometheus <prometheus-name> -n <prometheus-namespace> -o yaml
    

    需确保spec.serviceMonitorSelector.matchLabels包含app: apisix,或有更宽泛的选择器覆盖该标签。

  • 验证ServiceMonitor endpoints配置
    确认targetPort使用的是Service中定义的端口名称(prometheus)而非端口号,path与插件配置的export_uri完全一致,scheme与Apisix metrics端口的协议匹配(HTTP/HTTPS)。

内容的提问来源于stack exchange,提问作者iyin23

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 13:35:23