prometheus-operator通过https监控etcd

要求:

  • prometheus-operator的prometheus的生产环境要持久化

1、把相关的证书拷贝到prometheus中的prometheus目录下

kubectl cp /etc/etcd/ssl/etcd.pem -n monitoring prometheus-prometheus-kube-prometheus-prometheus-0:/prometheus/ -c prometheus
kubectl cp /etc/etcd/ssl/etcd-key.pem -n monitoring prometheus-prometheus-kube-prometheus-prometheus-0:/prometheus/ -c prometheus
kubectl cp /etc/kubernetes/ssl/ca.pem -n monitoring prometheus-prometheus-kube-prometheus-prometheus-0:/prometheus/ -c prometheus

2、修改servicemonitor的配置,增加证书配置

apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
  labels:
    app: kube-prometheus-stack-kube-etcd
    app.kubernetes.io/instance: prometheus
    app.kubernetes.io/part-of: kube-prometheus-stack
    release: prometheus
  name: prometheus-kube-prometheus-kube-etcd
  namespace: monitoring

spec:
  endpoints:
  - bearerTokenFile: /var/run/secrets/kubernetes.io/serviceaccount/token
    port: http-metrics
    scheme: https      #使用https协议
    tlsConfig:
      caFile: /prometheus/ca.pem             #使用上边的证书
      certFile: /prometheus/etcd.pem         #使用上边的证书
      keyFile: /prometheus/etcd-key.pem      #使用上边的证书
      insecureSkipVerify: true               #忽略验证证书
  jobLabel: jobLabel
  namespaceSelector:
    matchNames:
    - kube-system
  selector:
    matchLabels:
      app: kube-prometheus-stack-kube-etcd
      release: prometheus
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值