如何无需端口通过API调用将节点Metrics发送至Prometheus?私有网络监控求方案
私有网络节点向公网Prometheus推送/同步指标的可行方案
针对私有节点部署在跳板机后方、无法暴露端口的场景,以下几种方案完全可行:
方案1:使用Prometheus Pushgateway(主动推送)
Pushgateway作为指标中转节点,私有节点主动将指标推送到它,公网Prometheus从这里拉取数据,无需节点暴露端口:
- 部署:把Pushgateway放在公网可访问的服务器,或在跳板机上做端口转发让公网Prometheus能访问它。
- 操作:
- 私有节点上用exporter(如node_exporter)采集指标,然后通过
curl推送:
也可以用专用工具(如prometheus-pushgateway-client)批量推送exporter的完整指标。echo "node_cpu_usage 0.7" | curl --data-binary @- http://<pushgateway地址>:9091/metrics/job/node_monitor/instance/<节点标识> - 公网Prometheus的
scrape_configs中添加Pushgateway的地址,配置定期拉取。
- 私有节点上用exporter(如node_exporter)采集指标,然后通过
- 注意:Pushgateway默认是内存存储,重启会丢失数据,长期监控需开启持久化配置。
方案2:跳板机端口转发(间接拉取)
利用跳板机做中转,让公网Prometheus通过跳板机访问私有节点的exporter,节点无需暴露到公网:
- 操作:
- 在跳板机上建立SSH端口转发,把跳板机的某个端口映射到私有节点的exporter端口:
(示例中将跳板机的9100端口转发到私有节点的node_exporter端口9100)ssh -N -L 0.0.0.0:9100:<私有节点IP>:9100 <私有节点用户名>@<私有节点IP> - 公网Prometheus的
scrape_configs目标设为跳板机的IP和9100端口,即可拉取私有节点的指标。
- 在跳板机上建立SSH端口转发,把跳板机的某个端口映射到私有节点的exporter端口:
- 注意:给跳板机的转发端口配置IP白名单,只允许公网Prometheus服务器访问,降低安全风险。
方案3:指标文件导出+同步(离线导入)
如果接受离线方式,可定期导出指标文件,通过跳板机同步到公网后导入Prometheus/Grafana:
- 操作:
- 私有节点用crontab定时导出指标:
*/5 * * * * curl http://localhost:9100/metrics > /tmp/node_metrics.prom - 通过跳板机把文件同步到公网服务器(以scp为例):
scp -o ProxyJump=<跳板机用户名>@<跳板机IP> /tmp/node_metrics.prom <公网服务器用户名>@<公网服务器IP>:/prometheus/data/ - 公网Prometheus配置
file_sd_configs读取该文件的指标,或直接把文件导入Grafana作为数据源(需配合自定义脚本解析)。
- 私有节点用crontab定时导出指标:
方案4:Prometheus Remote Write(远程写入)
用Prometheus Agent在私有节点采集指标,通过remote write API主动推送到公网Prometheus,无需暴露任何端口:
- 操作:
- 公网Prometheus开启remote write接收,配置
remote_write端点并开启认证(如API Key、TLS)。 - 私有节点部署Prometheus Agent,配置scrape本地exporter的指标,同时在
remote_write中指向公网Prometheus的端点:remote_write: - url: "https://<公网Prometheus地址>/api/v1/write" basic_auth: username: "<用户名>" password: "<密码>" - Agent会自动采集并推送指标到公网Prometheus。
- 公网Prometheus开启remote write接收,配置
内容的提问来源于stack exchange,提问作者Sreekanth Chityala
相关产品推荐
相关产品推荐

