Prometheus ServiceMonitor抓取Confluent Cloud Kafka指标配置方法
配置异常根因
ServiceMonitor的端点配置强制要求关联对应Service上定义的命名端口,即使用户使用ExternalName类型的Service对接外部服务,也不能省略端口定义与端口名匹配逻辑。Confluent Cloud指标接口默认使用HTTPS 443端口,原有配置既没有在Service上声明端口,也没有在ServiceMonitor端点中关联对应端口名,Prometheus无法生成合法的抓取目标地址,因此出现目标状态异常。
正确配置方案
1. 补全ExternalName Service的端口定义
在原有Service配置中增加443端口的命名声明,端口名可自定义,但需要和后续ServiceMonitor中的引用保持完全一致:
kind: Service apiVersion: v1 metadata: name: kafka-metric-api-service namespace: monitoring labels: app: kafka-metric-api spec: type: ExternalName externalName: api.telemetry.confluent.cloud ports: - name: https-metrics port: 443 protocol: TCP targetPort: 443
2. 修正ServiceMonitor配置
在端点配置中增加port字段关联Service上定义的端口名,同时建议显式声明命名空间选择器,避免跨命名空间匹配失效:
apiVersion: monitoring.coreos.com/v1 kind: ServiceMonitor metadata: name: kafka-metric-api namespace: monitoring labels: app: kafka-metric-api spec: endpoints: - port: https-metrics basicAuth: password: name: kafka-basic-auth key: password username: name: kafka-basic-auth key: username path: /v2/metrics/cloud/export interval: 60s scheme: https tlsConfig: insecureSkipVerify: true params: resource.kafka.id: - lkc-xxxx # 替换为实际的Confluent Kafka集群ID selector: matchLabels: app: kafka-metric-api namespaceSelector: matchNames: - monitoring
排错验证要点
- 配置应用后等待1-2分钟,再到Prometheus Targets页面查看目标状态,正常情况下状态应为UP
- 若仍有异常,先在集群内执行curl命令验证基础连通性与鉴权有效性:
curl -v -u <你的Confluent API Key>:<对应Secret> "https://api.telemetry.confluent.cloud/v2/metrics/cloud/export?resource.kafka.id=lkc-xxxx",先排除网络策略、密钥错误这类基础问题 - 注意ServiceMonitor的port字段仅支持填写Service中定义的端口名称,直接填写端口数字不会生效
内容的提问来源于stack exchange,提问作者santosh.a
相关产品推荐
相关产品推荐

