如何通过Blackbox Exporter监控TCP端点的SSL证书过期状态
解决TCP端点SSL证书过期监控问题
你当前的核心问题是TCP探测模块未启用TLS握手——现有的tcp_connect模块设置了tls: false,导致Blackbox Exporter不会和目标TCP端点建立SSL连接,自然无法获取证书过期相关指标。下面是具体的修正步骤:
1. 修改Blackbox Exporter模块配置
新增一个支持TLS的TCP探测模块(推荐保留原tcp_connect模块,用于纯TCP连通性探测):
modules: # 保留你已有的http_2xx、http_OpenAPI_2xx、tcp_connect等所有模块... tcp_tls_connect: prober: tcp timeout: 10s tcp: tls: true # 关键:启用TLS握手 tls_config: insecure_skip_verify: false # 若目标是自签名证书,可设为true跳过验证;监控过期建议保持false,确保证书本身有效
2. 更新Prometheus抓取配置
将blackbox-tcp任务的探测模块替换为新定义的tcp_tls_connect:
- job_name: 'blackbox-tcp' metrics_path: /probe params: module: [tcp_tls_connect] # 替换为启用TLS的新模块 scrape_interval: 30s scrape_timeout: 20s static_configs: - targets: - tcp://171.17.25.12:38205 - tcp://171.17.25.12:5071 relabel_configs: - source_labels: [__address__] target_label: __param_target - source_labels: [__param_target] target_label: instance - target_label: __address__ replacement: 171.12.30.12:9115 # Blackbox exporter.
3. 验证证书监控指标
配置生效后,在Prometheus中可查询以下核心指标:
probe_ssl_earliest_cert_expiry:证书链中最早过期证书的Unix时间戳probe_ssl_cert_expiry_time_seconds:证书剩余有效时长(单位:秒)
若想直观查看剩余天数,可使用PromQL表达式:
probe_ssl_cert_expiry_time_seconds / 86400
可选:特殊TLS场景配置
如果目标TCP端点有特殊TLS要求(比如自定义CA证书、限制TLS版本),可扩展tls_config参数:
tls_config: insecure_skip_verify: false ca_file: /etc/blackbox_exporter/custom_ca.crt # 自定义CA证书路径 min_version: TLS12 # 强制使用TLS 1.2及以上版本
内容的提问来源于stack exchange,提问作者Priyotosh deb
相关产品推荐
相关产品推荐

