You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过OpenTelemetry Agent暴露ActiveMQ Artemis JMX指标且无需加入白名单?

问题描述

我们正在使用OpenTelemetry Agent导出ActiveMQ Artemis JMX指标,当前的OTel配置规则如下:

rules:
  - beans:
      - org.apache.activemq.artemis:broker="0.0.0.0",component=addresses,address=*,subcomponent=queues,routing-type="anycast",queue=*

为了获取指标,我们在management.xml的白名单中添加了整个org.apache.activemq.artemis域:

<allowlist>
    <entry domain="hawtio"/>
    <!--allow access for org.apache.activemq.artemis for JMX metrics-->
    <entry domain="org.apache.activemq.artemis"/>
</allowlist>

但这种方式会暴露该域下的所有JMX数据,存在安全风险,不适合生产环境。请问如何无需将整个域加入白名单,就能获取所需的指标?


解决方案

精确配置JMX白名单条目

不要将整个org.apache.activemq.artemis域加入白名单,而是针对OpenTelemetry Agent需要采集的具体MBean属性配置精细化规则,既能满足指标采集需求,又能最小化JMX数据暴露范围。

  1. 确认目标MBean的属性
    根据你的OTel配置,目标是采集匹配org.apache.activemq.artemis:broker="0.0.0.0",component=addresses,address=*,subcomponent=queues,routing-type="anycast",queue=*的MBean指标。先明确这些MBean提供的核心属性,比如队列常用的MessageCount、ConsumerCount、EnqueueCount、DequeueCount等。

  2. 替换白名单为精确条目
    修改management.xml中的白名单配置,移除整个域的条目,添加针对目标MBean和属性的授权规则:

    <allowlist>
        <entry domain="hawtio"/>
        <!-- 仅授权OTel需要的Artemis队列MBean属性 -->
        <entry domain="org.apache.activemq.artemis" 
               key="broker=0.0.0.0,component=addresses,address=*,subcomponent=queues,routing-type=anycast,queue=*"
               attributes="MessageCount,ConsumerCount,EnqueueCount,DequeueCount"/>
    </allowlist>
    
    • domain:指定目标域为org.apache.activemq.artemis
    • key:匹配你OTel配置中的MBean模式,支持通配符*
    • attributes:明确列出需要访问的具体属性,只开放实际需要采集的指标
  3. 验证配置效果
    重启ActiveMQ Artemis后,检查OpenTelemetry Agent是否正常采集到目标指标,同时通过JConsole等工具确认未授权的JMX数据无法被访问。

额外建议

  • 按需添加规则:如果后续需要采集其他类型的MBean(如broker节点本身的指标),单独添加对应的白名单条目,避免过度授权。
  • 定期清理配置:生产环境定期审计JMX白名单,移除不再使用的条目,降低安全风险。

内容的提问来源于stack exchange,提问作者Raushan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 02:41:10