You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Prometheus监控Web服务遇x509证书未知签发机构错误求助

解决Prometheus Blackbox Exporter监控端点的x509证书错误问题

首先明确核心问题:你当前Prometheus配置里的tls_config是用于Prometheus与Blackbox Exporter之间的TLS通信,而非Blackbox Exporter和目标服务之间的证书验证。所以这个配置不会影响Blackbox对目标端点的证书检查,这就是部分端点仍报错的原因。

以下是具体解决方法:

方法1:修改Blackbox Exporter的模块配置(推荐)

找到Blackbox Exporter的配置文件(通常为blackbox.yml),定位你使用的http_2xx_example模块,在http节点下添加TLS配置,可选择跳过验证或指定信任的CA证书:

跳过证书验证(快速临时解决)

modules:
  http_2xx_example:
    prober: http
    http:
      method: GET
      tls_config:
        insecure_skip_verify: true  # 跳过目标服务的证书合法性检查

信任自定义CA证书(生产环境推荐)

如果公司使用内部自签名CA,将CA证书路径添加到配置中:

modules:
  http_2xx_example:
    prober: http
    http:
      method: GET
      tls_config:
        ca_file: /opt/blackbox/company-internal-ca.crt  # 替换为实际CA证书路径

修改完成后重启Blackbox Exporter服务即可生效。

方法2:针对特定目标单独配置模块

若不想修改全局模块,可复制新模块专门处理有证书问题的目标,再在Prometheus配置中拆分job:

  1. 在Blackbox配置中新增模块:
modules:
  http_2xx_example:
    prober: http
    http:
      method: GET
  http_2xx_insecure:  # 新增跳过证书验证的模块
    prober: http
    http:
      method: GET
      tls_config:
        insecure_skip_verify: true
  1. 在Prometheus配置中拆分两个job:
# 处理正常证书的端点
- job_name: 'blackbox'
  metrics_path: /probe
  params:
    module: [http_2xx_example]
  static_configs:
    - targets:
      - https://test-services1.ffe.yy.com/
      - https://test-services2.ffe.yy.com/
  tls_config:
    insecure_skip_verify: true
  relabel_configs:
    - source_labels: [__address__]
      target_label: __param_target
    - source_labels: [__param_target]
      target_label: instance
    - target_label: __address__
      replacement: xx:xx:xx:xx:9115

# 处理证书异常的端点
- job_name: 'blackbox_insecure'
  metrics_path: /probe
  params:
    module: [http_2xx_insecure]
  static_configs:
    - targets:
      - https://test-services.xxxxx.com/
      - http://test-services3.xxxxx.com/
  tls_config:
    insecure_skip_verify: true
  relabel_configs:
    - source_labels: [__address__]
      target_label: __param_target
    - source_labels: [__param_target]
      target_label: instance
    - target_label: __address__
      replacement: xx:xx:xx:xx:9115

补充:HTTP端点报错的原因

http://test-services3.xxxxx.com/是HTTP协议却触发证书错误,大概率是该服务会自动重定向到HTTPS(如301/302跳转),Blackbox Exporter默认会跟随重定向,实际请求的是HTTPS地址,因此触发证书验证。上述方法同样适用。

内容的提问来源于stack exchange,提问作者CaglarAyhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 19:52:57