You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Kubernetes Secret提供Basic Auth凭证部署Prometheus(Helm)

通过Helm部署Prometheus并从Secret加载Basic Auth采集凭证

核心思路

Prometheus原生支持从文件读取Basic Auth凭证,结合Helm的extraVolumes和extraVolumeMounts配置,将你已创建的Secret挂载到Prometheus容器内,再在采集任务中引用这些文件路径即可,无需使用环境变量。

具体配置步骤

1. 在values.yaml中配置Secret挂载

将你的3个独立Secret挂载到Prometheus Server容器的指定路径:

prometheus:
  server:
    # 定义要挂载的Secret卷
    extraVolumes:
      - name: secret-test
        secret:
          secretName: test-secret  # 替换为你的第一个Secret名称
      - name: secret-app1
        secret:
          secretName: app1-secret  # 替换为你的第二个Secret名称
      - name: secret-app2
        secret:
          secretName: app2-secret  # 替换为你的第三个Secret名称
    # 将卷挂载到容器内的目录
    extraVolumeMounts:
      - name: secret-test
        mountPath: /etc/prometheus/secrets/test
        readOnly: true
      - name: secret-app1
        mountPath: /etc/prometheus/secrets/app1
        readOnly: true
      - name: secret-app2
        mountPath: /etc/prometheus/secrets/app2
        readOnly: true

2. 配置采集任务引用凭证文件

在extraScrapeConfigs中定义采集任务,用username_file和password_file替换明文凭证,指向挂载的Secret文件路径:

prometheus:
  server:
    extraScrapeConfigs:
      - job_name: test
        basic_auth:
          username_file: /etc/prometheus/secrets/test/username  # 对应Secret中的username键
          password_file: /etc/prometheus/secrets/test/password  # 对应Secret中的password键
        static_configs:
        - targets:
          - test.com

      - job_name: app1
        basic_auth:
          username_file: /etc/prometheus/secrets/app1/username
          password_file: /etc/prometheus/secrets/app1/password
        static_configs:
        - targets:
          - app1.example.com

      - job_name: app2
        basic_auth:
          username_file: /etc/prometheus/secrets/app2/username
          password_file: /etc/prometheus/secrets/app2/password
        static_configs:
        - targets:
          - app2.example.com

注意事项

  • 确保你的每个Secret都包含username和password两个键(如果你的Secret键名不同,需对应修改文件路径中的文件名,因为Secret挂载后,每个键会自动成为对应文件名的文件)。
  • 这种方式不会将凭证明文写入Prometheus的ConfigMap,符合Kubernetes的安全最佳实践。

内容的提问来源于stack exchange,提问作者no746

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 20:42:17