You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Prometheus Basic Authentication:认证有效期及自定义过期方法咨询

Prometheus Basic Authentication 有效期与自定义配置

一、默认有效期说明

HTTP Basic Auth 本身是无状态的认证方式,Prometheus 原生的 Basic Auth 配置(比如通过 web.basic_auth_users 定义的用户)没有内置的过期机制。实际有效期由客户端行为决定:

  • 浏览器通常会缓存认证凭证,有效期为当前浏览器会话(关闭浏览器后缓存失效)。
  • 使用 curl、Postman 等工具时,默认不会持久化凭证,每次请求需手动携带;若工具配置了保存凭证,有效期则由工具设置决定。

二、自定义认证过期时间的配置方法

Prometheus 原生不支持 Basic Auth 凭证过期控制,需要通过反向代理层实现,以 Nginx 为例,步骤如下:

1. 配置 Nginx 反向代理接管 Prometheus 访问

让 Nginx 作为前端负责认证和过期控制,配置示例:

server {
    listen 80;
    server_name your-prometheus-domain.com;

    # 开启 Basic Auth 并指定认证文件
    auth_basic "Prometheus 访问验证";
    auth_basic_user_file /etc/nginx/.htpasswd;

    # 设置会话 Cookie 控制过期时间(此处设为 1 小时,即 3600 秒)
    auth_request_set $auth_cookie $upstream_http_set_cookie;
    add_header Set-Cookie $auth_cookie;
    proxy_set_header Cookie $http_cookie;

    # 统一设置各类超时时间为 3600 秒
    proxy_connect_timeout 3600;
    proxy_send_timeout 3600;
    proxy_read_timeout 3600;
    send_timeout 3600;

    # 将请求转发到本地 Prometheus 实例
    location / {
        proxy_pass http://localhost:9090;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
}

2. 生成认证文件

使用 htpasswd 工具生成包含用户名和密码的认证文件:

# Debian/Ubuntu 系统先安装工具
apt-get install apache2-utils

# 生成认证文件并添加用户(示例用户名为 admin)
htpasswd -c /etc/nginx/.htpasswd admin

3. 限制 Prometheus 直接访问

修改 Prometheus 配置文件 prometheus.yml,让其仅监听本地地址,避免绕过反向代理:

web:
  listen-address: 127.0.0.1:9090

4. 重启服务生效

# 重启 Nginx
systemctl restart nginx

# 重启 Prometheus
systemctl restart prometheus

配置完成后,用户通过 Nginx 访问 Prometheus 时,认证状态会由 Cookie 控制,到达设置的超时时间后需重新登录。

内容的提问来源于stack exchange,提问作者lubrum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 01:20:14