Prometheus: monitorimi i HTTP përmes eksportuesit Blackbox

Të gjithë përshëndetje. Në maj OTUS do të nisë praktikumin mbi monitorimin dhe regjistrimin, si të infrastrukturës ashtu edhe të aplikacioneve duke përdorur Zabbix, Prometheus, Grafana dhe ELK. Në lidhje me këtë, tradicionalisht ndajmë materiale të dobishme mbi temën.

Eksportuesi Blackbox për Prometheus lejon realizimin e monitorimit të shërbimeve të jashtme përmes HTTP, HTTPS, DNS, TCP, ICMP. Në këtë artikull do t'ju tregoj se si të konfiguroni monitorimin HTTP/HTTPS duke përdorur eksportuesin Blackbox. Do ta ekzekutojmë eksportuesin Blackbox në Kubernetes.

Mjedisi

Na nevojitet gjithçka:

  • Kubernetes
  • Prometheus Operator

Konfigurimi i eksportuesit blackbox

Konfigurojmë Blackbox përmes ConfigMap për konfigurimin e http modulit të monitorimit të shërbimeve në ueb.

apiVersion: v1
kind: ConfigMap
metadata:
  name: prometheus-blackbox-exporter
  labels:
    app: prometheus-blackbox-exporter
data:
  blackbox.yaml: |
    modules:
      http_2xx:
        http:
          no_follow_redirects: false
          preferred_ip_protocol: ip4
          valid_http_versions:
          - HTTP/1.1
          - HTTP/2
          valid_status_codes: []
        prober: http
        timeout: 5s

Moduli http_2xx përdoret për të kontrolluar nëse shërbimi në ueb kthen kodin e statusit HTTP 2xx. Më shumë detaje mbi konfigurimin e eksportuesit blackbox janë përshkruar në dokumentacionin.

Shkëputja e eksportuesit blackbox në Kubernetes cluster

Përshkruani Zhvillimi dhe Shërbimi për implementimin në Kubernetes.

---
kind: Service
apiVersion: v1
metadata:
  name: prometheus-blackbox-exporter
  labels:
    app: prometheus-blackbox-exporter
spec:
  type: ClusterIP
  ports:
    - name: http
      port: 9115
      protocol: TCP
  selector:
    app: prometheus-blackbox-exporter

---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: prometheus-blackbox-exporter
  labels:
    app: prometheus-blackbox-exporter
spec:
  replicas: 1
  selector:
    matchLabels:
      app: prometheus-blackbox-exporter
  template:
    metadata:
      labels:
        app: prometheus-blackbox-exporter
    spec:
      restartPolicy: Always
      containers:
        - name: blackbox-exporter
          image: "prom/blackbox-exporter:v0.15.1"
          imagePullPolicy: IfNotPresent
          securityContext:
            readOnlyRootFilesystem: true
            runAsNonRoot: true
            runAsUser: 1000
          args:
            - "--config.file=/config/blackbox.yaml"
          resources:
            {}
          ports:
            - containerPort: 9115
              name: http
          livenessProbe:
            httpGet:
              path: /health
              port: http
          readinessProbe:
            httpGet:
              path: /health
              port: http
          volumeMounts:
            - mountPath: /config
              name: config
        - name: configmap-reload
          image: "jimmidyson/configmap-reload:v0.2.2"
          imagePullPolicy: "IfNotPresent"
          securityContext:
            runAsNonRoot: true
            runAsUser: 65534
          args:
            - --volume-dir=/etc/config
            - --webhook-url=http://localhost:9115/-/reload
          resources:
            {}
          volumeMounts:
            - mountPath: /etc/config
              name: config
              readOnly: true
      volumes:
        - name: config
          configMap:
            name: prometheus-blackbox-exporter

Eksportuesi Blackbox mund të zbatohet me komandën në vijim. Hapësira e emrave monitorimi i referohet Prometheus Operator.

kubectl --namespace=monitoring apply -f blackbox-exporter.yaml

Sigurohuni që të gjitha shërbimet janë aktive duke përdorur komandën e mëposhtme:

kubectl --namespace=monitoring get all --selector=app=prometheus-blackbox-exporter

Kontrollimi i Blackbox

Mund të qaseni në ndërfaqen e uebit të eksportuesit Blackbox përmes port-forward:

kubectl --namespace=monitoring port-forward svc/prometheus-blackbox-exporter 9115:9115

Lidhu me ndërfaqen e uebit të eksportuesit Blackbox përmes shfletuesit të internetit në adresën localhost:9115.

Prometheus: monitorimi i HTTP përmes eksportuesit Blackbox

Nëse shkoni në adresën http://localhost:9115/probe?module=http_2xx&target=https://www.google.com, do të shihni rezultatin e kontrollit të URL-së së dhënë (https://www.google.com).

Prometheus: monitorimi i HTTP përmes eksportuesit Blackbox

Vlera e metrikës probe_success e barabartë me 1 tregon një kontroll të suksesshëm. Vlera 0 tregon një gabim.

Konfigurimi i Prometheus

Pas vendosjes së eksportuesit BlackBox, konfigurojmë Prometheus në prometheus-additional.yaml.

- job_name: 'kube-api-blackbox'
  scrape_interval: 1w
  metrics_path: /probe
  params:
    module: [http_2xx]
  static_configs:
   - targets:
      - https://www.google.com
      - http://www.example.com
      - https://prometheus.io
  relabel_configs:
   - source_labels: [__address__]
     target_label: __param_target
   - source_labels: [__param_target]
     target_label: instance
   - target_label: __address__
     replacement: prometheus-blackbox-exporter:9115 # Eksportuesi blackbox.

Duke gjeneruar Sekreti, duke përdorur komandën e mëposhtme.

PROMETHEUS_ADD_CONFIG=$(cat prometheus-additional.yaml | base64)
cat << EOF | kubectl --namespace=monitoring apply -f -
apiVersion: v1
kind: Secret
metadata:
  name: additional-scrape-configs
type: Opaque
data:
  prometheus-additional.yaml: $PROMETHEUS_ADD_CONFIG
EOF

Specifikoni additional-scrape-configs për Prometheus Operator, duke përdorur additionalScrapeConfigs.

kubectl --namespace=monitoring edit prometheuses k8s
...
spec:
  additionalScrapeConfigs:
    key: prometheus-additional.yaml
    name: additional-scrape-configs

Hyn në ndërfaqen e uebit të Prometheus, kontrollon metrikat dhe objektivat.

kubectl --namespace=monitoring port-forward svc/prometheus-k8s 9090:9090

Prometheus: monitorimi i HTTP përmes eksportuesit Blackbox

Prometheus: monitorimi i HTTP përmes eksportuesit Blackbox

Shihni metrikat dhe objektivat Blackbox.

Shtimi i rregullave për njoftime (alert)

Për të marrë njoftime nga eksportuesi Blackbox, do të shtojmë rregulla në Prometheus Operator.

kubectl --namespace=monitoring edit prometheusrules prometheus-k8s-rules
...
  - name: blackbox-exporter
    rules:
    - alert: ProbeFailed
      expr: probe_success == 0
      for: 5m
      labels:
        severity: error
      annotations:
        summary: "Probe failed (instance {{ $labels.instance }})"
        description: "Probe failedn  VALUE = {{ $value }}n  LABELS: {{ $labels }}"
    - alert: SlowProbe
      expr: avg_over_time(probe_duration_seconds[1m]) > 1
      for: 5m
      labels:
        severity: warning
      annotations:
        summary: "Slow probe (instance {{ $labels.instance }})"
        description: "Blackbox probe took more than 1s to completen  VALUE = {{ $value }}n  LABELS: {{ $labels }}"
    - alert: HttpStatusCode
      expr: probe_http_status_code = 400
      for: 5m
      labels:
        severity: error
      annotations:
        summary: "HTTP Status Code (instance {{ $labels.instance }})"
        description: "HTTP status code is not 200-399n  VALUE = {{ $value }}n  LABELS: {{ $labels }}"
    - alert: SslCertificateWillExpireSoon
      expr: probe_ssl_earliest_cert_expiry - time() < 86400 * 30
      for: 5m
      labels:
        severity: warning
      annotations:
        summary: "SSL certificate will expire soon (instance {{ $labels.instance }})"
        description: "SSL certificate expires in 30 daysn  VALUE = {{ $value }}n  LABELS: {{ $labels }}"
    - alert: SslCertificateHasExpired
      expr: probe_ssl_earliest_cert_expiry - time()   1
      for: 5m
      labels:
        severity: warning
      annotations:
        summary: "HTTP slow requests (instance {{ $labels.instance }})"
        description: "HTTP request took more than 1sn  VALUE = {{ $value }}n  LABELS: {{ $labels }}"
    - alert: SlowPing
      expr: avg_over_time(probe_icmp_duration_seconds[1m]) > 1
      for: 5m
      labels:
        severity: warning
      annotations:
        summary: "Slow ping (instance {{ $labels.instance }})"
        description: "Blackbox ping took more than 1sn  VALUE = {{ $value }}n  LABELS: {{ $labels }}"

Në ndërfaqen e internetit të Prometheus, shkoni në Seksionin Status => Rules dhe gjeni rregullat e njoftimit për blackbox-exporter.

Prometheus: monitorimi i HTTP përmes eksportuesit Blackbox

Konfigurimi i njoftimeve për skadimin e certifikatave SSL në Kubernetes API Server

Le të vendosim monitorimin për skadimin e certifikatave SSL në Kubernetes API Server. Ai do të dërgojë njoftime një herë në javë.

Shtimi i modulit Blackbox eksportues për Kubernetes API Server Authentication.

kubectl --namespace=monitoring edit configmap prometheus-blackbox-exporter
...
      kube-api:
        http:
          method: GET
          no_follow_redirects: false
          preferred_ip_protocol: ip4
          tls_config:
            insecure_skip_verify: false
            ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
          bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
          valid_http_versions:
          - HTTP/1.1
          - HTTP/2
          valid_status_codes: []
        prober: http
        timeout: 5s

Shtimi i konfiguracionit të scrape për Prometheus

- job_name: 'kube-api-blackbox'
  metrics_path: /probe
  params:
    module: [kube-api]
  static_configs:
   - targets:
      - https://kubernetes.default.svc/api
  relabel_configs:
   - source_labels: [__address__]
     target_label: __param_target
   - source_labels: [__param_target]
     target_label: instance
   - target_label: __address__
     replacement: prometheus-blackbox-exporter:9115 # The blackbox exporter.

Aplikojmë Prometheus Secret

PROMETHEUS_ADD_CONFIG=$(cat prometheus-additional.yaml | base64)
cat << EOF | kubectl --namespace=monitoring apply -f -
apiVersion: v1
kind: Secret
metadata:
  name: additional-scrape-configs
type: Opaque
data:
  prometheus-additional.yaml: $PROMETHEUS_ADD_CONFIG
EOF

Shtojmë rregulla njoftimi

kubectl --namespace=monitoring edit prometheusrules prometheus-k8s-rules
...
  - name: k8s-api-server-cert-expiry
    rules:
    - alert: K8sAPIServerSSLCertExpiringAfterThreeMonths
      expr: probe_ssl_earliest_cert_expiry{job="kube-api-blackbox"} - time() < 86400 * 90 
      for: 1w
      labels:
        severity: warning
      annotations:
        summary: "Kubernetes API Server SSL certificate do të skadojë pas tre muajsh (instance {{ $labels.instance }})"
        description: "Kubernetes API Server SSL certificate skadon në 90 ditën  Vlera = {{ $value }}n  Etiketat: {{ $labels }}"

Useful links

Monitorimi dhe regjistrimi në Docker

Burimi: habr.com

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster