如何仅从本地工作站访问EKS集群中的Grafana/Prometheus?
仅本地访问EKS中的Prometheus和Grafana的方法
你可以通过以下几种类似kubectl proxy的方式,在保持服务为ClusterIP类型的前提下,仅让本地工作站访问Prometheus和Grafana:
方法1:kubectl port-forward(推荐)
这是最直接的本地端口转发方式,直接将本地端口映射到集群内的服务端口:
访问Prometheus:
# 替换为你的Prometheus服务名和命名空间,示例中服务名为prometheus-server,命名空间为monitoring kubectl port-forward svc/prometheus-server 9090:9090 -n monitoring执行后,在本地浏览器访问
http://localhost:9090即可访问Prometheus。访问Grafana:
# 替换为你的Grafana服务名和命名空间,示例中服务名为grafana,命名空间为monitoring kubectl port-forward svc/grafana 3000:3000 -n monitoring执行后,在本地浏览器访问
http://localhost:3000即可访问Grafana。
方法2:kubectl proxy 结合API路径转发
和访问Kubernetes Dashboard的方式类似,先启动API代理:
kubectl proxy
然后通过Kubernetes API的代理路径访问服务:
- Prometheus访问地址:
http://localhost:8001/api/v1/namespaces/monitoring/services/prometheus-server:9090/proxy/ - Grafana访问地址:
http://localhost:8001/api/v1/namespaces/monitoring/services/grafana:3000/proxy/
注意事项
- 如果你不确定服务名称或命名空间,可执行
kubectl get svc -A查看所有集群内的服务信息。 - 这两种方式都不会将服务暴露到公网,仅本地工作站能通过建立的通道访问,安全性更高。
内容的提问来源于stack exchange,提问作者user20208419
相关产品推荐
相关产品推荐

