You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Prometheus 2.28开启Basic Auth后健康端点认证问题及解决方案咨询

解决方案:Prometheus健康端点认证优化

针对你的问题,有两种可行的优化方向,分别解决「禁用健康端点认证」和「更安全传递凭证」的需求:

方案1:让健康端点跳过Basic认证

Prometheus支持通过web.config.yml配置文件细粒度控制认证规则,你可以单独让/-/healthy和/-/ready这两个端点免认证,这样Kubernetes探针就能直接访问,无需携带凭证。

步骤:

  1. 在Prometheus服务器上创建web.config.yml配置文件,内容如下:
basic_auth_users:
  # 这里保留你原来的用户名和bcrypt哈希后的密码(禁止使用明文)
  user: "$2a$10$xxxxxx..."
authorization:
  rules:
  # 允许所有请求访问健康检查端点
  - url: "/-/healthy"
    users: []
    allow_all: true
  - url: "/-/ready"
    users: []
    allow_all: true
  # 对其他所有路径启用Basic认证
  - url: "/*"
    users: ["user"]

注意:basic_auth_users里的密码必须是bcrypt哈希值,你可以用htpasswd工具生成:htpasswd -nBC 10 user,将输出的哈希值填入即可。

  1. 修改Prometheus启动参数,添加--web.config.file=/path/to/web.config.yml,让Prometheus加载这个配置文件。

  2. 重启Prometheus服务后,/-/healthy和/-/ready就会跳过认证,Kubernetes探针可以用最简配置访问:

livenessProbe:
  httpGet:
    path: /-/healthy
    port: 9090
readinessProbe:
  httpGet:
    path: /-/ready
    port: 9090

方案2:更安全的凭证传递方式(不修改Prometheus认证配置)

如果你不想调整Prometheus的认证规则,可以通过Kubernetes Secret安全存储凭证,避免直接在Deployment YAML中暴露Base64编码内容。

步骤:

  1. 创建存储Basic认证凭证的Secret:
# 直接从命令行输入创建Secret(自动处理Base64编码)
kubectl create secret generic prometheus-probe-auth --from-literal=auth-header="Basic dXNlcjpwYXNz"

或者通过文件创建:

# 先将Authorization头内容写入文件
echo "Basic dXNlcjpwYXNz" > auth-header.txt
# 基于文件创建Secret
kubectl create secret generic prometheus-probe-auth --from-file=auth-header=auth-header.txt
  1. 在Deployment的探针配置中引用这个Secret:
livenessProbe:
  httpGet:
    path: /-/healthy
    port: 9090
  httpHeaders:
  - name: Authorization
    valueFrom:
      secretKeyRef:
        name: prometheus-probe-auth
        key: auth-header
readinessProbe:
  httpGet:
    path: /-/ready
    port: 9090
  httpHeaders:
  - name: Authorization
    valueFrom:
      secretKeyRef:
        name: prometheus-probe-auth
        key: auth-header

凭证会存储在Kubernetes Secret中(默认加密存储),不会直接暴露在Deployment YAML里,还能单独更新Secret而无需修改Deployment配置,安全性大幅提升。

总结

  • 如果你希望探针访问最简洁,推荐方案1——直接让健康端点免认证,这也是Prometheus官方认可的做法(健康检查端点本身不包含敏感信息)。
  • 如果你必须保持所有端点的认证保护,那么方案2是更安全的凭证传递方式,避免硬编码凭证风险。

内容的提问来源于stack exchange,提问作者amrit sandhu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 22:49:05