提问者:小点点

如何为prometheus作业添加不记名代币


我已经开始为我的微服务开发Prometheus。我最初能够实现它。现在,是时候在Spring Security下推动执行器endpoint了。添加安全执行器后,需要来自Prometheus的不记名令牌。那么,如何在Prometheus作业中配置用户名和密码,以便Prometheus从登录中获取不记名令牌,并将其添加为所有请求的标头中的“授权”。

我正在使用以下命令在docker容器中运行Prometheus


 1. $ docker run --name prometheus -p 9090:9090 -v prometheus.yml:/etc/prometheus/prometheus.yml -d prom/prometheus
 2. $ docker run --name grafana -d -p 3000:3000 grafana/grafana

以下是prometheus. yml文件


# my global config
global:
  scrape_interval:     15s # Set the scrape interval to every 15 seconds. Default is every 1 minute.
  evaluation_interval: 15s # Evaluate rules every 15 seconds. The default is every 1 minute.
  # scrape_timeout is set to the global default (10s).

# Load rules once and periodically evaluate them according to the global 'evaluation_interval'.
rule_files:
# - "first_rules.yml"
# - "second_rules.yml"

# A scrape configuration containing exactly one endpoint to scrape:
# Here it's Prometheus itself.
scrape_configs:

  # The job name is added as a label `job=<job_name>` to any time series scraped from this config.
  - job_name: 'prometheus'
    # metrics_path defaults to '/metrics'
    # scheme defaults to 'http'.
    static_configs:
      - targets: ['127.0.0.1:9090']

  - job_name: 'NL-APPLICATION'
    metrics_path: '/actuator/prometheus'
    scrape_interval: 5s
    scheme: http
    static_configs:
      - targets: ['172.17.0.1:8085']

  - job_name: 'NL-ADMIN-API'
    metrics_path: '/actuator/prometheus'
    scrape_interval: 5s
    static_configs:
      - targets: ['172.17.0.1:8083']

如何指示普罗米修斯按照以下操作

  1. API使用用户名和密码调用/login获取承载令牌
  2. 在所有执行器调用中添加作为授权API头的承载令牌

共1个答案

匿名用户

您可以指定为文件或将令牌添加到配置中

- job_name: 'test'
    metrics_path: "/metrics"
    scheme: "http"
    bearer_token_file: /var/run/secrets/    OR   bearer_token: token_here
    static_configs:
- targets: ['host.com']