如何通过Kubernetes Secret提供Basic Auth凭证部署Prometheus(Helm)
通过Helm部署Prometheus并从Secret加载Basic Auth采集凭证
核心思路
Prometheus原生支持从文件读取Basic Auth凭证,结合Helm的extraVolumes和extraVolumeMounts配置,将你已创建的Secret挂载到Prometheus容器内,再在采集任务中引用这些文件路径即可,无需使用环境变量。
具体配置步骤
1. 在values.yaml中配置Secret挂载
将你的3个独立Secret挂载到Prometheus Server容器的指定路径:
prometheus: server: # 定义要挂载的Secret卷 extraVolumes: - name: secret-test secret: secretName: test-secret # 替换为你的第一个Secret名称 - name: secret-app1 secret: secretName: app1-secret # 替换为你的第二个Secret名称 - name: secret-app2 secret: secretName: app2-secret # 替换为你的第三个Secret名称 # 将卷挂载到容器内的目录 extraVolumeMounts: - name: secret-test mountPath: /etc/prometheus/secrets/test readOnly: true - name: secret-app1 mountPath: /etc/prometheus/secrets/app1 readOnly: true - name: secret-app2 mountPath: /etc/prometheus/secrets/app2 readOnly: true
2. 配置采集任务引用凭证文件
在extraScrapeConfigs中定义采集任务,用username_file和password_file替换明文凭证,指向挂载的Secret文件路径:
prometheus: server: extraScrapeConfigs: - job_name: test basic_auth: username_file: /etc/prometheus/secrets/test/username # 对应Secret中的username键 password_file: /etc/prometheus/secrets/test/password # 对应Secret中的password键 static_configs: - targets: - test.com - job_name: app1 basic_auth: username_file: /etc/prometheus/secrets/app1/username password_file: /etc/prometheus/secrets/app1/password static_configs: - targets: - app1.example.com - job_name: app2 basic_auth: username_file: /etc/prometheus/secrets/app2/username password_file: /etc/prometheus/secrets/app2/password static_configs: - targets: - app2.example.com
注意事项
- 确保你的每个Secret都包含
username和password两个键(如果你的Secret键名不同,需对应修改文件路径中的文件名,因为Secret挂载后,每个键会自动成为对应文件名的文件)。 - 这种方式不会将凭证明文写入Prometheus的ConfigMap,符合Kubernetes的安全最佳实践。
内容的提问来源于stack exchange,提问作者no746
相关产品推荐
相关产品推荐

