Prometheus 2.28开启Basic Auth后健康端点认证问题及解决方案咨询
解决方案:Prometheus健康端点认证优化
针对你的问题,有两种可行的优化方向,分别解决「禁用健康端点认证」和「更安全传递凭证」的需求:
方案1:让健康端点跳过Basic认证
Prometheus支持通过web.config.yml配置文件细粒度控制认证规则,你可以单独让/-/healthy和/-/ready这两个端点免认证,这样Kubernetes探针就能直接访问,无需携带凭证。
步骤:
- 在Prometheus服务器上创建
web.config.yml配置文件,内容如下:
basic_auth_users: # 这里保留你原来的用户名和bcrypt哈希后的密码(禁止使用明文) user: "$2a$10$xxxxxx..." authorization: rules: # 允许所有请求访问健康检查端点 - url: "/-/healthy" users: [] allow_all: true - url: "/-/ready" users: [] allow_all: true # 对其他所有路径启用Basic认证 - url: "/*" users: ["user"]
注意:
basic_auth_users里的密码必须是bcrypt哈希值,你可以用htpasswd工具生成:htpasswd -nBC 10 user,将输出的哈希值填入即可。
修改Prometheus启动参数,添加
--web.config.file=/path/to/web.config.yml,让Prometheus加载这个配置文件。重启Prometheus服务后,
/-/healthy和/-/ready就会跳过认证,Kubernetes探针可以用最简配置访问:
livenessProbe: httpGet: path: /-/healthy port: 9090 readinessProbe: httpGet: path: /-/ready port: 9090
方案2:更安全的凭证传递方式(不修改Prometheus认证配置)
如果你不想调整Prometheus的认证规则,可以通过Kubernetes Secret安全存储凭证,避免直接在Deployment YAML中暴露Base64编码内容。
步骤:
- 创建存储Basic认证凭证的Secret:
# 直接从命令行输入创建Secret(自动处理Base64编码) kubectl create secret generic prometheus-probe-auth --from-literal=auth-header="Basic dXNlcjpwYXNz"
或者通过文件创建:
# 先将Authorization头内容写入文件 echo "Basic dXNlcjpwYXNz" > auth-header.txt # 基于文件创建Secret kubectl create secret generic prometheus-probe-auth --from-file=auth-header=auth-header.txt
- 在Deployment的探针配置中引用这个Secret:
livenessProbe: httpGet: path: /-/healthy port: 9090 httpHeaders: - name: Authorization valueFrom: secretKeyRef: name: prometheus-probe-auth key: auth-header readinessProbe: httpGet: path: /-/ready port: 9090 httpHeaders: - name: Authorization valueFrom: secretKeyRef: name: prometheus-probe-auth key: auth-header
凭证会存储在Kubernetes Secret中(默认加密存储),不会直接暴露在Deployment YAML里,还能单独更新Secret而无需修改Deployment配置,安全性大幅提升。
总结
- 如果你希望探针访问最简洁,推荐方案1——直接让健康端点免认证,这也是Prometheus官方认可的做法(健康检查端点本身不包含敏感信息)。
- 如果你必须保持所有端点的认证保护,那么方案2是更安全的凭证传递方式,避免硬编码凭证风险。
内容的提问来源于stack exchange,提问作者amrit sandhu
相关产品推荐
相关产品推荐

