如何让node-exporter与cadvisor仅对Prometheus容器开放访问?
How to Restrict Node-Exporter and cAdvisor Access to Only Prometheus Container
Got it, let's lock this down properly so only your Prometheus container can reach node-exporter and cAdvisor, while blocking all public access to those two services. The fix relies on Docker's internal networking and removing unnecessary port mappings that expose them to the outside world. Here's your step-by-step solution:
1. Use a Custom Internal Docker Network
First, define a dedicated private network in your docker-compose.yml. This lets all your monitoring services communicate with each other using container names as hostnames, without opening them up to the public internet.
2. Adjust Service Configurations
- Remove port mappings from node-exporter and cAdvisor: Those
portslines are what make the services accessible via your host's IP + port. Ditching them means the services will only be reachable within the Docker network. - Update Prometheus scrape targets: Since all services are on the same network, you can reference node-exporter and cAdvisor directly by their container names (instead of localhost or your host IP) in Prometheus' config.
Example docker-compose.yml
version: '3.8' networks: monitoring-net: driver: bridge internal: true # Optional: Makes the network fully isolated from external traffic services: prometheus: image: prom/prometheus:latest volumes: - ./prometheus.yml:/etc/prometheus/prometheus.yml - prometheus-storage:/prometheus networks: - monitoring-net ports: - "9090:9090" # Keep this if you need public access to Prometheus UI restart: unless-stopped node-exporter: image: quay.io/prometheus/node-exporter:latest volumes: - /proc:/host/proc:ro - /sys:/host/sys:ro - /:/rootfs:ro command: - '--path.procfs=/host/proc' - '--path.sysfs=/host/sys' - '--path.rootfs=/rootfs' - '--collector.filesystem.mount-points-exclude=^/(sys|proc|dev|host|etc)($$|/)' networks: - monitoring-net # REMOVE the ports line here to block public access restart: unless-stopped cadvisor: image: gcr.io/cadvisor/cadvisor:latest volumes: - /:/rootfs:ro - /var/run:/var/run:rw - /sys:/sys:ro - /var/lib/docker:/var/lib/docker:ro networks: - monitoring-net # REMOVE the ports line here to block public access restart: unless-stopped volumes: prometheus-storage:
Example Prometheus Scrape Config (prometheus.yml)
Update your targets to use container names instead of host IPs:
global: scrape_interval: 15s scrape_configs: - job_name: 'prometheus' static_configs: - targets: ['localhost:9090'] - job_name: 'node-exporter' static_configs: - targets: ['node-exporter:9100'] # Use container name for internal DNS resolution - job_name: 'cadvisor' static_configs: - targets: ['cadvisor:8080'] # Use container name for internal DNS resolution
3. Verify the Setup
- Check public access: Try hitting
http://your-host-ip:9100orhttp://your-host-ip:8080from a browser or curl command. You should get a connection refused error—this confirms public access is blocked. - Check Prometheus connectivity: Exec into the Prometheus container and test access to the exporters:
You should see raw metric data returned, which means Prometheus can reach the services as intended.docker exec -it <your-prometheus-container-name> curl node-exporter:9100/metrics docker exec -it <your-prometheus-container-name> curl cadvisor:8080/metrics
Why This Works
- Custom Network: Docker's bridge network provides automatic DNS resolution for container names, so Prometheus can easily locate node-exporter and cAdvisor without relying on host IP addresses.
- No Port Mappings: Without
portsentries, Docker doesn't bind the container ports to your host's network interface. This cuts off all external access, leaving only containers on the same internal network able to communicate with the exporters.
内容的提问来源于stack exchange,提问作者Tara Prasad Gurung
相关产品推荐
相关产品推荐

