Prometheus Basic Authentication:认证有效期及自定义过期方法咨询
Prometheus Basic Authentication 有效期与自定义配置
一、默认有效期说明
HTTP Basic Auth 本身是无状态的认证方式,Prometheus 原生的 Basic Auth 配置(比如通过 web.basic_auth_users 定义的用户)没有内置的过期机制。实际有效期由客户端行为决定:
- 浏览器通常会缓存认证凭证,有效期为当前浏览器会话(关闭浏览器后缓存失效)。
- 使用 curl、Postman 等工具时,默认不会持久化凭证,每次请求需手动携带;若工具配置了保存凭证,有效期则由工具设置决定。
二、自定义认证过期时间的配置方法
Prometheus 原生不支持 Basic Auth 凭证过期控制,需要通过反向代理层实现,以 Nginx 为例,步骤如下:
1. 配置 Nginx 反向代理接管 Prometheus 访问
让 Nginx 作为前端负责认证和过期控制,配置示例:
server { listen 80; server_name your-prometheus-domain.com; # 开启 Basic Auth 并指定认证文件 auth_basic "Prometheus 访问验证"; auth_basic_user_file /etc/nginx/.htpasswd; # 设置会话 Cookie 控制过期时间(此处设为 1 小时,即 3600 秒) auth_request_set $auth_cookie $upstream_http_set_cookie; add_header Set-Cookie $auth_cookie; proxy_set_header Cookie $http_cookie; # 统一设置各类超时时间为 3600 秒 proxy_connect_timeout 3600; proxy_send_timeout 3600; proxy_read_timeout 3600; send_timeout 3600; # 将请求转发到本地 Prometheus 实例 location / { proxy_pass http://localhost:9090; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } }
2. 生成认证文件
使用 htpasswd 工具生成包含用户名和密码的认证文件:
# Debian/Ubuntu 系统先安装工具 apt-get install apache2-utils # 生成认证文件并添加用户(示例用户名为 admin) htpasswd -c /etc/nginx/.htpasswd admin
3. 限制 Prometheus 直接访问
修改 Prometheus 配置文件 prometheus.yml,让其仅监听本地地址,避免绕过反向代理:
web: listen-address: 127.0.0.1:9090
4. 重启服务生效
# 重启 Nginx systemctl restart nginx # 重启 Prometheus systemctl restart prometheus
配置完成后,用户通过 Nginx 访问 Prometheus 时,认证状态会由 Cookie 控制,到达设置的超时时间后需重新登录。
内容的提问来源于stack exchange,提问作者lubrum
相关产品推荐
相关产品推荐

