Prometheus : Enable authentication and HTTPS2024/09/06 |
Enable basic authentication and HTTPS for Prometheus endpoint. |
|
[1] |
Get SSL Certificate, or
Create self-signed Certificate. |
[2] | Configure Prometheus. |
root@dlp:~ #
pkg install -y apache24 # generate password with bcrypt hash # set any username you like root@dlp:~ # htpasswd -nB admin New password: Re-type new password: admin:$2y$05$.Ne.2SccDPsUYWquhSu3OOebB85g3pde/7nnrWmrIOnVw8x2KJDyS
root@dlp:~ #
cp /usr/local/etc/ssl/server.crt /usr/local/etc/ssl/server.key /usr/local/etc/ root@dlp:~ # chown prometheus:prometheus /usr/local/etc/server.crt /usr/local/etc/server.key
root@dlp:~ #
vi /usr/local/etc/prometheus-web.yml # create new # specify your certificate tls_server_config: cert_file: /usr/local/etc/server.crt key_file: /usr/local/etc/server.key # specify username and password generated above basic_auth_users: admin: $2y$05$.Ne.2SccDPsUYWquhSu3OOebB85g3pde/7nnrWmrIOnVw8x2KJDyS
root@dlp:~ #
vi /usr/local/etc/prometheus.yml ..... ..... scrape_configs: # The job name is added as a label `job=<job_name>` to any timeseries scraped from this config. - job_name: "prometheus" # metrics_path defaults to '/metrics' # scheme defaults to 'http'. # add settings for certificate and authentication scheme: https tls_config: cert_file: /usr/local/etc/server.crt key_file: /usr/local/etc/server.key # if using self-signed certificate, set [true] insecure_skip_verify: true basic_auth: username: 'admin' password: 'password' static_configs: # if using valid certificate, set the same hostname in certificate - targets: ["localhost:9090"]root@dlp:~ # sysrc prometheus_args="--web.config.file=/usr/local/etc/prometheus-web.yml" prometheus_args: -> --web.config.file=/usr/local/etc/prometheus-web.yml root@dlp:~ # service prometheus restart
|
[3] | Access to Prometheus endpoint via HTTPS, then that's OK if you can successfully authenticate with the username and password you set. |
Sponsored Link |