You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让node-exporter与cadvisor仅对Prometheus容器开放访问?

How to Restrict Node-Exporter and cAdvisor Access to Only Prometheus Container

Got it, let's lock this down properly so only your Prometheus container can reach node-exporter and cAdvisor, while blocking all public access to those two services. The fix relies on Docker's internal networking and removing unnecessary port mappings that expose them to the outside world. Here's your step-by-step solution:

1. Use a Custom Internal Docker Network

First, define a dedicated private network in your docker-compose.yml. This lets all your monitoring services communicate with each other using container names as hostnames, without opening them up to the public internet.

2. Adjust Service Configurations

  • Remove port mappings from node-exporter and cAdvisor: Those ports lines are what make the services accessible via your host's IP + port. Ditching them means the services will only be reachable within the Docker network.
  • Update Prometheus scrape targets: Since all services are on the same network, you can reference node-exporter and cAdvisor directly by their container names (instead of localhost or your host IP) in Prometheus' config.

Example docker-compose.yml

version: '3.8'

networks:
  monitoring-net:
    driver: bridge
    internal: true  # Optional: Makes the network fully isolated from external traffic

services:
  prometheus:
    image: prom/prometheus:latest
    volumes:
      - ./prometheus.yml:/etc/prometheus/prometheus.yml
      - prometheus-storage:/prometheus
    networks:
      - monitoring-net
    ports:
      - "9090:9090"  # Keep this if you need public access to Prometheus UI
    restart: unless-stopped

  node-exporter:
    image: quay.io/prometheus/node-exporter:latest
    volumes:
      - /proc:/host/proc:ro
      - /sys:/host/sys:ro
      - /:/rootfs:ro
    command:
      - '--path.procfs=/host/proc'
      - '--path.sysfs=/host/sys'
      - '--path.rootfs=/rootfs'
      - '--collector.filesystem.mount-points-exclude=^/(sys|proc|dev|host|etc)($$|/)'
    networks:
      - monitoring-net
    # REMOVE the ports line here to block public access
    restart: unless-stopped

  cadvisor:
    image: gcr.io/cadvisor/cadvisor:latest
    volumes:
      - /:/rootfs:ro
      - /var/run:/var/run:rw
      - /sys:/sys:ro
      - /var/lib/docker:/var/lib/docker:ro
    networks:
      - monitoring-net
    # REMOVE the ports line here to block public access
    restart: unless-stopped

volumes:
  prometheus-storage:

Example Prometheus Scrape Config (prometheus.yml)

Update your targets to use container names instead of host IPs:

global:
  scrape_interval: 15s

scrape_configs:
  - job_name: 'prometheus'
    static_configs:
      - targets: ['localhost:9090']

  - job_name: 'node-exporter'
    static_configs:
      - targets: ['node-exporter:9100']  # Use container name for internal DNS resolution

  - job_name: 'cadvisor'
    static_configs:
      - targets: ['cadvisor:8080']  # Use container name for internal DNS resolution

3. Verify the Setup

  • Check public access: Try hitting http://your-host-ip:9100 or http://your-host-ip:8080 from a browser or curl command. You should get a connection refused error—this confirms public access is blocked.
  • Check Prometheus connectivity: Exec into the Prometheus container and test access to the exporters:
    docker exec -it <your-prometheus-container-name> curl node-exporter:9100/metrics
    docker exec -it <your-prometheus-container-name> curl cadvisor:8080/metrics
    
    You should see raw metric data returned, which means Prometheus can reach the services as intended.

Why This Works

  • Custom Network: Docker's bridge network provides automatic DNS resolution for container names, so Prometheus can easily locate node-exporter and cAdvisor without relying on host IP addresses.
  • No Port Mappings: Without ports entries, Docker doesn't bind the container ports to your host's network interface. This cuts off all external access, leaving only containers on the same internal network able to communicate with the exporters.

内容的提问来源于stack exchange,提问作者Tara Prasad Gurung

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:41:11