Prometheus JMX Exporter 1.6.0

Published Prometheus JMX Exporter 1.6.0 — a release of an exporter designed to collect values JMX MBean from Java applications and output them as Prometheus metrics. With the right configuration, the JMX Exporter can also send data via OpenTelemetry. The project code is distributed under the license Apache-2.0.

JMX Exporter can be run in several modes: as a Java agent within the target JVM, as a standalone exporter for polling remote JMX/RMI, and as an isolator Java agent for multiple isolated exporters in one JVM. The documentation recommends using the Java agent as the preferred option for most users, as it avoids the need for remote JMX/RMI configuration.

What’s Changed

  • Configurable metrics path.
    Added the ability to specify a custom HTTP path for the exporter to deliver metrics. This is useful in environments where the endpoint /metrics is already occupied, where routing is tied to unified ingress/service mesh rules, or where multiple exporters are published via a single proxy.

  • Protection against timing attacks during password verification.
    Added enhancement to defend against timing-based password attacks. This involves reducing the risk where an attacker tries to guess a password by analyzing the differences in response time when verifying different options.

  • Fixed PBKDF2 authentication methods.
    Developers corrected the bit length calculation for PBKDF2 authentication methods. The error could affect the accuracy of password verification when using the corresponding hashing schemes. In the changelog, it was listed as PKDF2, but in context and meaning related to authentication, it refers to PBKDF2.

  • Fixed LRU caching for authentication.
    An adjustment was made to the caching mechanism for authentication results. For an exporter that can be polled frequently and in parallel by Prometheus, the proper functioning of such a cache is essential for both performance and predictable authorization behavior.

  • Documentation updated.
    Documentation 1.6.0 describes the purpose of the JMX Exporter, deployment modes, quick start, YAML configuration, HTTP settings, authentication, SSL, OpenTelemetry, and examples. The artifacts for version 1.6.0 are also listed separately.

  • Dependencies updated.
    The release includes multiple dependency updates. For the monitoring infrastructure component, this is an important part of maintenance: such updates typically close accumulated fixes, enhance compatibility, and reduce the risk of supply chain issues.

  • A general cleanup of the project has been conducted.
    The developers have improved the Javadoc, increased test coverage, expanded the set of unit tests, and refined the integration tests. Additionally, more containers and distributions have been added for integration testing.

Overall JMX Exporter 1.6.0 appears to be an operational release: without major architectural overhauls, but with useful changes for production environments — flexible configuration of metric endpoints, enhanced authentication, caching fixes, and a significant update to the test suite.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster