流烟默头像
关注

Spring Boot 应用对接 Prometheus 监控指南

Spring Boot 应用对接 Prometheus 监控指南

本文档介绍如何将 Spring Boot 应用接入 Prometheus 监控体系,分无认证Basic Auth 认证两种情况说明。


一、技术栈

组件用途
Micrometer指标采集门面
Spring Boot Actuator暴露监控端点
Prometheus指标采集 + 时序数据库
Grafana指标可视化

二、通用步骤(两种场景都需要)

2.1 引入依赖

<!-- Spring Boot Actuator -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-actuator</artifactId>
</dependency>

<!-- Prometheus Registry -->
<dependency>
    <groupId>io.micrometer</groupId>
    <artifactId>micrometer-registry-prometheus</artifactId>
</dependency>

2.2 配置 application.yml

server:
  port: 8086                                  # 业务端口

spring:
  application:
    name: janus-service1


management:
  server:
    port: 18086                                # 管理端口,与应用端口隔离
  endpoints:
    web:
      exposure:
        include: health,info,prometheus        # 暴露 Prometheus 端点
  endpoint:
    prometheus:
      enabled: true                            # 启用 Prometheus 端点
  metrics:
    tags:
      application: ${spring.application.name}  # 给指标打标签,便于区分

2.3 K8s Deployment 配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: janus-service1
  namespace: gateway-default
spec:
  template:
    metadata:
      annotations:
        # ============================================================
        # 场景一:无认证(直接抓取)
        # ============================================================
        prometheus.io/scrape: "true"
        prometheus.io/kind: "janus-service1"
        prometheus.io/port: "18086"
        prometheus.io/path: "/actuator/prometheus"

        # ============================================================
        # 场景二:Basic Auth 认证(额外添加)
        # ============================================================
        # prometheus.io/auth: "basic"          # ← 有认证时取消注释
    spec:
      containers:
        - name: janus-service1
          image: your-registry/janus-service1:latest
          ports:
            - name: http
              containerPort: 8086
              protocol: TCP
            - name: management
              containerPort: 18086               # 管理端口
              protocol: TCP

三、场景一:无认证(内网/测试环境)

3.1 场景说明

  • Prometheus 直接抓取 /actuator/prometheus 端点
  • 无需用户名密码验证
  • 适用于内网环境或测试环境

3.2 配置清单

配置项说明
prometheus.io/scrape"true"允许 Prometheus 抓取
prometheus.io/port"18086"抓取端口
prometheus.io/path"/actuator/prometheus"抓取路径
prometheus.io/auth不配置无需认证

3.3 验证命令

# 1. Pod 内验证
curl http://localhost:18086/actuator/prometheus | head -10

# 2. 集群内验证
curl http://<pod-ip>:18086/actuator/prometheus | head -10

# 3. 查看 Prometheus Targets
http://<prometheus-host>:9090/targets
# 预期: State = UP ✅

四、场景二:Basic Auth 认证(生产环境)

4.1 场景说明

  • Prometheus 抓取时需要携带 Basic Auth 凭证
  • 应用需要验证请求中的用户名密码
  • 适用于生产环境,安全性更高

4.2 新增依赖

<!-- 仅场景二需要 -->
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

4.3 配置 application.yml

spring:
  security:
    user:
      # ⚠️ 必须与 Prometheus 配置中的 basic_auth 一致
      name: username
      password: axxxxxxxxxxxxxxxxxxxxxxx

management:
  # ... 与场景一相同,保持不变

需要注意的是security6.X版本下,password应该如下:

password: '{noop}你的密码'

4.4 配置 Security(只保护 /actuator 路径)


import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.core.annotation.Order;
import org.springframework.security.config.Customizer;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
@EnableWebSecurity
public class ManagementSecurityConfig {

    /**
     * 只保护 /actuator/** 路径,使用 Basic Auth
     */
    @Bean
    @Order(1)
    public SecurityFilterChain managementSecurityFilterChain(HttpSecurity http) throws Exception {
        http.securityMatcher("/actuator/**")
            .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
            .httpBasic(Customizer.withDefaults())
            .csrf(csrf -> csrf.disable());
        return http.build();
    }

    /**
     * 其他所有请求放行(不影响业务接口)
     */
    @Bean
    @Order(2)
    public SecurityFilterChain defaultSecurityFilterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(auth -> auth.anyRequest().permitAll())
            .csrf(csrf -> csrf.disable());
        return http.build();
    }
}

4.5 K8s 注解(添加 auth 标记)

annotations:
  prometheus.io/scrape: "true"
  prometheus.io/kind: "janus-service1"
  prometheus.io/port: "18086"
  prometheus.io/path: "/actuator/prometheus"
  prometheus.io/auth: "basic"   # ← 告诉 Prometheus 需要认证

4.6 Prometheus 配置(运维侧)

scrape_configs:
  - job_name: 'janus-service1'
    kubernetes_sd_configs:
      - role: pod
    relabel_configs:
      # 只抓取 scrape=true 的 Pod
      - source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_scrape]
        action: keep
        regex: true
      # 只抓取 auth=basic 的 Pod
      - source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_auth]
        action: keep
        regex: basic
      # 使用自定义路径
      - source_labels: [__meta_kubernetes_pod_annotation_prometheus_io_path]
        action: replace
        target_label: __metrics_path__
      # 使用自定义端口
      - source_labels: [__address__, __meta_kubernetes_pod_annotation_prometheus_io_port]
        action: replace
        regex: ([^:]+)(?::\d+)?;(\d+)
        replacement: $1:$2
        target_label: __address__
    # Basic Auth 认证配置
    basic_auth:
      username: username
      password: a48xxxxxxxxxxxxxxxxxxxxxxxxxx391

转载自 CSDN-专业IT技术社区

原文链接:https://blog.csdn.net/J080624/article/details/163342323

文章来源crawl

评论

赞0

评论列表

微信小程序
QQ小程序

关于作者

点赞数:0
关注数:0
粉丝:0
文章:0
关注标签:0
加入于:--