You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Prometheus Blackbox探测HTTPS地址遇证书验证错误求助

问题:Blackbox Exporter HTTPS证书验证失败

尝试将Blackbox Exporter与Web服务器配合使用时,持续出现证书验证错误。网站已配置DigiCert的SSL证书,日志中IP与域名已做隐去处理,探测日志如下:

Logs for the probe:
level=info msg="Making HTTP request" url=https://00.00.40.248 host=DOMAINNAME
level=error msg="Error for HTTP request" err="Get "https://00.00.40.248": tls: failed to verify certificate: x509: certificate signed by unknown authority"

当前使用的配置文件如下:

Prometheus.yml

scrape_configs:
  - job_name: 'webserver'
    metrics_path: /probe
    params:
      module: [http_2xx]
    static_configs:
      - targets:
        - https://DOMAINNAME  
    relabel_configs:
      - source_labels: [__address__]
        target_label: __param_target
      - source_labels: [__param_target]
        target_label: instance
      - target_label: __address__
        replacement: 192.00.00.18:9115  

  - job_name: 'prometheus'
    static_configs:
      - targets:
        - localhost:9090  # Replace with the address where Prometheus is running

Blackbox.yml

modules:
  http_2xx:
    prober: http
    timeout: 5s
    http:
      valid_http_versions: ["HTTP/1.1", "HTTP/2.0"]
      valid_status_codes: []
      method: GET
      preferred_ip_protocol: "ip4"
      ip_protocol_fallback: false
  icmp:
    prober: icmp
    icmp:
      preferred_ip_protocol: "ip4"
      ip_protocol_fallback: false

解决方案

核心问题分析

日志显示Blackbox直接请求了服务器IP(https://00.00.40.248),但你的SSL证书是绑定在DOMAINNAME域名上的。TLS验证时,证书的主体名称(CN)或SAN扩展中不包含该IP;同时如果Blackbox所在系统的根证书存储中缺少DigiCert的根证书,也会触发这个错误。

具体修复步骤

1. 让Blackbox通过域名而非IP发起请求

修改blackbox.yml的http模块配置,强制指定TLS验证的服务器名称,确保请求使用域名而非直接访问IP:

modules:
  http_2xx:
    prober: http
    timeout: 5s
    http:
      valid_http_versions: ["HTTP/1.1", "HTTP/2.0"]
      valid_status_codes: []
      method: GET
      preferred_ip_protocol: "ip4"
      ip_protocol_fallback: false
      # 添加TLS配置,指定服务器域名
      tls_config:
        server_name: DOMAINNAME  # 替换为你的实际域名

2. 确保Blackbox所在系统信任DigiCert根证书

如果系统缺少DigiCert的根证书,需要手动安装:

  • Linux系统:将DigiCert根证书文件(如DigiCertGlobalRootCA.crt)复制到/usr/local/share/ca-certificates/目录,执行sudo update-ca-certificates更新证书存储。
  • Docker部署的Blackbox:构建自定义镜像时加入根证书,或通过挂载宿主机的证书目录到容器的/etc/ssl/certs/路径。

3. 验证Prometheus relabel规则

确认当前relabel规则未将目标域名转换为IP。现有配置中static_configs的targets是https://DOMAINNAME,relabel后__param_target应保留该域名,Blackbox会直接请求域名并通过DNS解析获取IP,而非直接访问IP。

可选:临时禁用证书验证(仅测试用,禁止生产环境使用)

若仅用于测试,可临时关闭TLS验证,但会失去安全保障:

modules:
  http_2xx:
    prober: http
    timeout: 5s
    http:
      # ... 其他原有配置
      tls_config:
        insecure_skip_verify: true

内容的提问来源于stack exchange,提问作者StackUser2014

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 01:02:41