You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Blackbox Exporter监控TCP端点的SSL证书过期状态

解决TCP端点SSL证书过期监控问题

你当前的核心问题是TCP探测模块未启用TLS握手——现有的tcp_connect模块设置了tls: false,导致Blackbox Exporter不会和目标TCP端点建立SSL连接,自然无法获取证书过期相关指标。下面是具体的修正步骤:

1. 修改Blackbox Exporter模块配置

新增一个支持TLS的TCP探测模块(推荐保留原tcp_connect模块,用于纯TCP连通性探测):

modules:
  # 保留你已有的http_2xx、http_OpenAPI_2xx、tcp_connect等所有模块...
  tcp_tls_connect:
    prober: tcp
    timeout: 10s
    tcp:
      tls: true  # 关键:启用TLS握手
      tls_config:
        insecure_skip_verify: false  # 若目标是自签名证书,可设为true跳过验证;监控过期建议保持false,确保证书本身有效

2. 更新Prometheus抓取配置

将blackbox-tcp任务的探测模块替换为新定义的tcp_tls_connect:

- job_name: 'blackbox-tcp'
  metrics_path: /probe
  params:
    module: [tcp_tls_connect]  # 替换为启用TLS的新模块
  scrape_interval: 30s
  scrape_timeout: 20s
  static_configs:
    - targets:
      - tcp://171.17.25.12:38205
      - tcp://171.17.25.12:5071
  relabel_configs:
    - source_labels: [__address__]
      target_label: __param_target
    - source_labels: [__param_target]
      target_label: instance
    - target_label: __address__
      replacement: 171.12.30.12:9115 # Blackbox exporter.

3. 验证证书监控指标

配置生效后,在Prometheus中可查询以下核心指标:

  • probe_ssl_earliest_cert_expiry:证书链中最早过期证书的Unix时间戳
  • probe_ssl_cert_expiry_time_seconds:证书剩余有效时长(单位:秒)

若想直观查看剩余天数,可使用PromQL表达式:

probe_ssl_cert_expiry_time_seconds / 86400

可选:特殊TLS场景配置

如果目标TCP端点有特殊TLS要求(比如自定义CA证书、限制TLS版本),可扩展tls_config参数:

tls_config:
  insecure_skip_verify: false
  ca_file: /etc/blackbox_exporter/custom_ca.crt  # 自定义CA证书路径
  min_version: TLS12  # 强制使用TLS 1.2及以上版本

内容的提问来源于stack exchange,提问作者Priyotosh deb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:50:01