You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Compose Prometheus对接HTTPS的ASP.NET Core Web API:X509证书无效

解决ASP.NET Core Web API与Docker Prometheus HTTPS对接的证书问题

错误信息:

Get "https://host.docker.internal:443/metrics": x509: certificate is valid for localhost, not host.docker.internal

这个错误是因为ASP.NET Core默认HTTPS证书仅包含localhost域名,Prometheus通过host.docker.internal访问时,证书域名不匹配导致验证失败。以下是两种解决方案,优先推荐第一种(合规安全)。

方案一:生成包含host.docker.internal的有效证书并配置Web API

1. 生成多域名开发证书

使用dotnet dev-certs命令生成同时覆盖localhost和host.docker.internal的证书:

dotnet dev-certs https -ep $HOME/.aspnet/https/MyWebApi.pfx -p MyStrongPassword123! --trust --hostname localhost --hostname host.docker.internal

参数说明:

  • -ep:指定证书导出路径
  • -p:设置证书保护密码
  • --trust:让本地操作系统信任该证书
  • --hostname:添加需要纳入证书的域名,可多次添加

2. 配置ASP.NET Core使用新证书

三种配置方式选其一即可:

方式1:环境变量启动

ASPNETCORE_Kestrel__Certificates__Default__Path=$HOME/.aspnet/https/MyWebApi.pfx ASPNETCORE_Kestrel__Certificates__Default__Password=MyStrongPassword123! dotnet run

方式2:appsettings.json配置

{
  "Kestrel": {
    "Certificates": {
      "Default": {
        "Path": "~/../.aspnet/https/MyWebApi.pfx",
        "Password": "MyStrongPassword123!"
      }
    }
  }
}

注意:路径需根据实际文件位置调整,建议使用绝对路径避免歧义。

方式3:代码配置Kestrel

var builder = WebApplication.CreateBuilder(args);

builder.WebHost.ConfigureKestrel(serverOptions =>
{
    // 配置HTTPS端口使用自定义证书
    serverOptions.ListenAnyIP(443, listenOptions =>
    {
        listenOptions.UseHttps("MyWebApi.pfx", "MyStrongPassword123!");
    });
    // 配置HTTP端口
    serverOptions.ListenAnyIP(80);
});

// 原有服务配置
services.AddPrometheusCounters();
services.AddPrometheusAspNetCoreMetrics();
services.AddPrometheusHttpClientMetrics();
services.AddPrometheusSqlClientMetrics();

var app = builder.Build();
app.UseHttpsRedirection();
app.MapMetrics();
app.Run();

3. 若Web API部署在Docker容器中

如果Web API需要和Prometheus同属Docker网络,需将证书集成到镜像或挂载到容器:

Dockerfile示例

FROM mcr.microsoft.com/dotnet/aspnet:7.0 AS base
WORKDIR /app
EXPOSE 80
EXPOSE 443

# 将本地证书复制到容器内指定路径
COPY ./MyWebApi.pfx /https/MyWebApi.pfx

# 设置环境变量指定证书路径和密码
ENV ASPNETCORE_Kestrel__Certificates__Default__Path=/https/MyWebApi.pfx
ENV ASPNETCORE_Kestrel__Certificates__Default__Password=MyStrongPassword123!

FROM mcr.microsoft.com/dotnet/sdk:7.0 AS build
WORKDIR /src
COPY ["MyWebApi.csproj", "."]
RUN dotnet restore "./MyWebApi.csproj"
COPY . .
RUN dotnet build "MyWebApi.csproj" -c Release -o /app/build

FROM build AS publish
RUN dotnet publish "MyWebApi.csproj" -c Release -o /app/publish /p:UseAppHost=false

FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .
ENTRYPOINT ["dotnet", "MyWebApi.dll"]

更新docker-compose.yml

添加Web API服务并加入qs网络:

services:
  # 原有grafana、prometheus服务...
  webapi:
    build: .
    ports:
      - "443:443"
      - "80:80"
    networks:
      - qs

此时Prometheus的scrape配置可改为直接访问容器名:

- job_name: qs
  metrics_path: /metrics
  scheme: https
  static_configs:
    - targets: ['webapi:443']

方案二:开发环境临时跳过证书验证(仅测试用,禁止生产)

修改prometheus.yml的qs任务配置,添加tls_config跳过证书校验:

- job_name: qs
  metrics_path: /metrics
  scheme: https
  static_configs:
    - targets: ['host.docker.internal:443']
  tls_config:
    insecure_skip_verify: true

此方式会绕过HTTPS证书校验,存在安全风险,仅用于本地开发测试场景。


内容的提问来源于stack exchange,提问作者nop

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 16:30:46