如何通过OpenTelemetry Agent暴露ActiveMQ Artemis JMX指标且无需加入白名单?
我们正在使用OpenTelemetry Agent导出ActiveMQ Artemis JMX指标,当前的OTel配置规则如下:
rules: - beans: - org.apache.activemq.artemis:broker="0.0.0.0",component=addresses,address=*,subcomponent=queues,routing-type="anycast",queue=*
为了获取指标,我们在management.xml的白名单中添加了整个org.apache.activemq.artemis域:
<allowlist> <entry domain="hawtio"/> <!--allow access for org.apache.activemq.artemis for JMX metrics--> <entry domain="org.apache.activemq.artemis"/> </allowlist>
但这种方式会暴露该域下的所有JMX数据,存在安全风险,不适合生产环境。请问如何无需将整个域加入白名单,就能获取所需的指标?
精确配置JMX白名单条目
不要将整个org.apache.activemq.artemis域加入白名单,而是针对OpenTelemetry Agent需要采集的具体MBean属性配置精细化规则,既能满足指标采集需求,又能最小化JMX数据暴露范围。
确认目标MBean的属性
根据你的OTel配置,目标是采集匹配org.apache.activemq.artemis:broker="0.0.0.0",component=addresses,address=*,subcomponent=queues,routing-type="anycast",queue=*的MBean指标。先明确这些MBean提供的核心属性,比如队列常用的MessageCount、ConsumerCount、EnqueueCount、DequeueCount等。替换白名单为精确条目
修改management.xml中的白名单配置,移除整个域的条目,添加针对目标MBean和属性的授权规则:<allowlist> <entry domain="hawtio"/> <!-- 仅授权OTel需要的Artemis队列MBean属性 --> <entry domain="org.apache.activemq.artemis" key="broker=0.0.0.0,component=addresses,address=*,subcomponent=queues,routing-type=anycast,queue=*" attributes="MessageCount,ConsumerCount,EnqueueCount,DequeueCount"/> </allowlist>domain:指定目标域为org.apache.activemq.artemiskey:匹配你OTel配置中的MBean模式,支持通配符*attributes:明确列出需要访问的具体属性,只开放实际需要采集的指标
验证配置效果
重启ActiveMQ Artemis后,检查OpenTelemetry Agent是否正常采集到目标指标,同时通过JConsole等工具确认未授权的JMX数据无法被访问。
额外建议
- 按需添加规则:如果后续需要采集其他类型的MBean(如broker节点本身的指标),单独添加对应的白名单条目,避免过度授权。
- 定期清理配置:生产环境定期审计JMX白名单,移除不再使用的条目,降低安全风险。
内容的提问来源于stack exchange,提问作者Raushan

