You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何借助GCP托管Prometheus获取认证模式下的Cloud Run指标?

对接需认证Cloud Run服务到Prometheus的可行方案

一、排查Sidecar代理方案的问题

如果用OIDC令牌代理作为Sidecar仍无法采集指标,重点检查以下几点:

  • 权限配置:确保代理使用的服务账号被授予roles/run.invoker角色,并且该账号已添加到Cloud Run服务的IAM策略中(允许调用该服务)
  • 令牌有效性:手动调用代理的令牌生成接口,拿到令牌后执行gcloud auth token info <token>,检查aud字段是否完全匹配Cloud Run服务的完整URL(比如https://your-service-abcdef.a.run.app)
  • Prometheus目标配置:确认Prometheus的scrape目标指向Sidecar的地址,而非直接Cloud Run服务。示例配置:
    scrape_configs:
      - job_name: 'cloud-run-service'
        static_configs:
          - targets: ['sidecar-proxy:8080']
        metrics_path: '/metrics'
        params:
          target: ['https://your-service-abcdef.a.run.app/metrics']
    
  • 代理日志:查看Sidecar的运行日志,排查令牌生成失败、请求转发错误等具体异常信息

二、GCP托管Prometheus对接Cloud Run的可行方案

1. 采集Cloud Run系统指标

GCP会自动将Cloud Run的系统指标(请求量、延迟、CPU/内存使用率等)同步到Cloud Monitoring,可通过托管Prometheus的联邦查询获取这些指标:

  • 创建具有roles/monitoring.viewer权限的服务账号
  • 在托管Prometheus中添加联邦配置,目标指向Cloud Monitoring的Prometheus API:
    scrape_configs:
      - job_name: 'gcp-cloud-run-federation'
        scrape_interval: 1m
        metrics_path: '/v1/projects/[PROJECT_ID]/locations/global/workspaces/[WORKSPACE_ID]/prometheus/api/v1/query'
        params:
          query: ['{job="cloud_run_revision"}']
        scheme: 'https'
        static_configs:
          - targets: ['monitoring.googleapis.com']
        authorization:
          credentials_file: '/var/run/secrets/google.com/service-account.json'
    

2. 采集Cloud Run自定义指标

如果需要采集服务自身暴露的自定义metrics,可通过OpenTelemetry Collector实现:

  • 为Collector创建服务账号,授予roles/run.invoker权限,并将该账号添加到Cloud Run服务的IAM策略
  • 部署Collector,配置Prometheus接收器(对接Cloud Run的metrics端点)和OAuth2令牌自动获取,同时配置Google Cloud exporter发送到托管Prometheus:
    receivers:
      prometheus:
        config:
          scrape_configs:
            - job_name: 'cloud-run-custom-metrics'
              scrape_interval: 1m
              static_configs:
                - targets: ['your-service-abcdef.a.run.app']
              scheme: https
              authorization:
                type: OAuth2
                credentials_file: '/var/run/secrets/google.com/service-account.json'
                scopes: ['https://www.googleapis.com/auth/cloud-platform']
    exporters:
      googlecloud:
        project: '[PROJECT_ID]'
        metric:
          prefix: 'custom.googleapis.com/'
    service:
      pipelines:
        metrics:
          receivers: [prometheus]
          exporters: [googlecloud]
    

内容的提问来源于stack exchange,提问作者Aditya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 16:06:25