必须部署thanos以实现prometheus长期存储,支持docker compose+minio、原生二进制、helm chart(k8s)及remote write四种部署方式。

如果您在Linux系统上需要为Prometheus配置长期存储能力,则必须部署Thanos以突破本地TSDB的时间限制。以下是多种可行的安装与部署方式,适用于不同运维场景和基础设施成熟度。
一、基于Docker Compose的快速二进制+MinIO对象存储部署
该方法适合测试环境或轻量级生产部署,所有组件通过Docker容器化运行,MinIO作为本地对象存储后端,无需依赖云厂商服务。
1、确保系统已安装Docker及docker-compose。若未安装,执行:sudo apt update && sudo apt install -y docker.io docker-compose(Ubuntu)或sudo yum install -y docker docker-compose(CentOS)。
2、创建项目目录并初始化数据路径:mkdir -p ~/thanos-test/data/{minio,prometheus},然后进入:cd ~/thanos-test。
3、编写minio-compose.yml,定义MinIO服务,暴露9000(S3 API)和9001(Web控制台)端口,并设置初始账号密码为minioadmin。
4、启动MinIO:docker-compose -f minio-compose.yml up -d,随后访问http://$(hostname -I | awk '{print $1}'):9001,登录并创建名为thanos的存储桶。
5、下载Thanos v0.34.0与Prometheus v2.50.0二进制包,解压后将thanos和prometheus可执行文件分别复制至/usr/local/bin/并赋予执行权限。
二、原生二进制方式部署(无容器依赖)
该方式适用于对系统精简性要求高、禁止运行Docker的合规环境,所有组件以systemd服务形式常驻运行,便于审计与资源隔离。
1、创建专用用户与目录结构:sudo useradd --no-create-home --shell /bin/false thanos;sudo mkdir -p /etc/thanos /var/lib/thanos。
2、下载Thanos二进制并安装:wget https://github.com/thanos-io/thanos/releases/download/v0.34.0/thanos-0.34.0.linux-amd64.tar.gz && tar -xzf thanos-0.34.0.linux-amd64.tar.gz && sudo cp thanos-0.34.0.linux-amd64/thanos /usr/local/bin/。
3、配置Prometheus启用Sidecar模式:在prometheus.yml中添加external_labels: {monitor: "prod"} ,启动时附加参数--web.enable-lifecycle --storage.tsdb.max-block-duration=2h。
4、编写/etc/thanos/objstore.yml,明确指定MinIO endpoint、bucket、access_key与secret_key,并设置insecure: true以跳过TLS验证(仅限内网)。
5、为Sidecar、Store Gateway、Query组件分别创建独立systemd unit文件,均以thanos用户运行,并配置Restart=always保障高可用。
三、Helm Chart方式部署(Kubernetes集群适用)
该方式面向已运行Kubernetes集群的用户,利用Helm统一管理Thanos各组件生命周期,支持自动证书注入、RBAC策略绑定与ServiceMonitor集成。
1、添加官方Helm仓库:helm repo add bitnami https://charts.bitnami.com/bitnami && helm repo update。
2、准备对象存储密钥:将objstore.yml内容编码为Base64,使用kubectl create secret generic thanos-objstore-config --from-file=objstore.yml -n monitoring注入命名空间。
3、覆盖默认values.yaml,重点配置objstoreConfig指向Secret、query.dnsDiscovery.sidecars启用DNS服务发现、storegateway.serviceMonitor.enabled开启指标采集。
4、执行安装命令:helm install thanos bitnami/thanos --namespace monitoring --create-namespace -f values.yaml。
5、验证Pod状态:kubectl get pods -n monitoring -l app.kubernetes.io/instance=thanos,确认sidecar、store-gateway、querier等组件处于Running状态。
四、Prometheus Remote Write直连Thanos Receive部署
该方式绕过Sidecar,由Prometheus主动推送指标至Receive组件,适用于无法修改Prometheus部署形态(如托管服务)、或需集中汇聚多集群指标的场景。
1、部署Receive服务:启动thanos receive进程,指定--receive.local-endpoint为本机监听地址,--receive.hashrings配置分片环(JSON格式),并挂载对象存储配置。
2、配置Prometheus远程写入:在prometheus.yml中添加remote_write区块,目标地址设为Receive服务的/api/v1/receive端点,启用队列与重试策略。
3、为Receive组件启用TSDB压缩:添加--tsdb.retention.time=365d参数,确保本地暂存块按周期上传至对象存储并清理。
4、部署配套Store Gateway与Query:Store Gateway需配置相同对象存储凭证,并通过--objstore.config-file加载;Query组件通过--store参数显式发现Receive和Store Gateway的gRPC地址。










