You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Prometheus使用Google服务账户对抓取目标进行身份验证

更新 感谢@levi-harrison,我编写了一个解决方案 gcp-oidc-token-proxy

我需要抓取要求Google身份验证的Cloud Run服务,该方案也可普遍适用于所有受Google身份认证保护的端点。

我可以通过如下方式实现访问:

curl \
--request GET
--header "Authorization: Bearer $(gcloud auth print-identity-token)" \
https://my-server-blahblah-wl.a.run.app/metrics

Prometheus目前仅支持TLS或OAuth2两种身份验证方式,其中oauth2配置要求提供Client ID和secret。

我使用配置了对应IAM权限的Google服务账号,参照Google服务端间应用OAuth2文档,可以获取Prometheus配置所需的client_id(但我不清楚该值是服务账户密钥的client_id还是client_email),不过我不确定Prometheus配置中的client_secret(或client_secret_file)以及token_url该填什么。

我尝试过以下几种配置方案:

  • 将服务账户密钥作为client_secret_file的值
  • 通过oauth2l生成JWT,将其作为client_secret的值,对应命令如下:
    oauth2l fetch \
    --type=jwt \
    --scope cloud-platform \
    --credentials ${PWD}/${KEY}.json
    
  • 使用gcloud auth application-default生成的${HOME}/.config/gcloud/application_default_credentials.json凭证,该凭证文件包含client_id和client_secret,搭配的token_url为https://oauth2.googleapis.com/token
  • 搭配JWT使用的token_url为https://sts.googleapis.com/v1beta/token

以上所有配置方式都返回400错误。

我还尝试过将JWT与https://securetoken.googleapis.com/v1/token?key=${API_KEY}搭配使用,返回了携带INVALID_GRANT_TYPE的400错误,原因是我无法修改请求体,按照Token Service要求添加grant_type=authorization-code参数。

我使用的完整prometheus.yml配置示例如下:

global:
  ...

scrape_configs:
  - job_name: "foo"
    scheme: https
    oauth2:
      # 从服务账号密钥中获取
      client_id: ""
      # 从`oauth2l`生成的ID令牌(JWT)
      client_secret: ""
      scopes:
      - "https://www.googleapis.com/auth/cloud-platform"
      token_url: "https://securetoken.googleapis.com/v1/token?key=${API_KEY}"
    static_configs:
      - targets:
          - "my-server-blahblah-wl.a.run.app"

内容的提问来源于stack exchange,提问作者DazWilkin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 20:18:02