blackbox exporter 是 prometheus 官方提供的轻量级黑盒监控工具,支持 http、tcp、icmp、dns 等协议主动探测,通过模拟用户行为判断服务连通性、响应延迟及证书有效期等核心健康状态。

直接部署 Blackbox Exporter 并接入 Prometheus,就能实现对 HTTP、TCP、ICMP、DNS 等协议的主动探测监控。它不依赖目标服务内部状态,只模拟真实用户行为,快速回答“服务通不通”“响应快不快”“证书有没有过期”这类关键问题。
一、部署 Blackbox Exporter 服务
Blackbox Exporter 是单二进制文件,轻量且无依赖:
- 从 Prometheus 官方 GitHub 发布页 下载最新稳定版(如 v0.25.0),解压后得到
blackbox_exporter可执行文件 - 准备配置文件
config.yml,定义常用探测模块(HTTP、TCP、ICMP 等),例如:
modules:
http_2xx:
prober: http
timeout: 5s
http:
valid_status_codes: [200, 204]
method: GET
headers:
User-Agent: "monitoring/blackbox"
tcp_connect:
prober: tcp
timeout: 3s
icmp:
prober: icmp
timeout: 2s- 启动服务:
./blackbox_exporter --config.file=config.yml --web.listen-address=:9115 - 验证是否运行:访问
http://localhost:9115查看状态页;调用探测接口测试,如:curl "http://localhost:9115/probe?module=http_2xx&target=https%3A%2F%2Fexample.com",应返回 Prometheus 格式指标
二、在 Prometheus 中配置抓取任务
编辑 Prometheus 的 prometheus.yml,添加 scrape job 指向 Blackbox Exporter 的 /probe 接口:
- 确保
static_configs或服务发现机制能列出待监控的目标(如域名、IP、端口) - 每个 target 需通过 URL 参数指定
module和target,例如:
scrape_configs:
- job_name: 'blackbox-http'
metrics_path: /probe
params:
module: [http_2xx]
static_configs:
- targets:
- https://api.example.com/health
- https://www.company.com
relabel_configs:
- source_labels: [__address__]
target_label: __param_target
- source_labels: [__param_target]
target_label: instance
- target_label: __address__
replacement: 127.0.0.1:9115- 重启 Prometheus 后,在 Web UI 的 Status → Targets 页面确认 job 状态为 UP
- 在 Graph 页面输入
probe_success{job="blackbox-http"},可查看各目标最近一次探测是否成功(1=成功,0=失败)
三、配置实用监控指标与告警
Blackbox 返回的核心指标已覆盖多数场景,无需二次开发:
-
probe_success:判断连通性,建议设置连续 3 次失败才触发告警 -
probe_duration_seconds:响应耗时,可用于识别慢响应或超时(如 >2s 告警) -
probe_http_status_code:检查状态码是否符合预期(如非 200/204 即异常) -
probe_ssl_last_expired_at:配合 PromQL 计算剩余天数,提前 15 天预警证书过期 -
probe_dns_lookup_time_seconds:DNS 解析延迟突增可能预示解析服务异常或污染
在 Alertmanager 中配置示例规则(写入 alert.rules.yml):
groups:
- name: blackbox-alerts
rules:
- alert: HttpProbeFailed
expr: probe_success{job="blackbox-http"} == 0
for: 3m
labels:
severity: critical
annotations:
summary: "HTTP probe failed for {{ $labels.instance }}"
- alert: SSLCertExpiresSoon
expr: probe_ssl_last_expired_at{job="blackbox-http"} - time() 四、典型实战场景配置要点
不同协议探测需关注各自关键配置项:
-
HTTP 探测:启用
no_follow_redirects: false跟踪跳转链;用fail_if_matches_regexp检查响应体是否含错误关键词;加Host请求头适配虚拟主机 -
TCP 探测:适用于数据库端口(如 3306)、Redis(6379)等;可开启
tls_config验证 TLS 握手是否成功 -
ICMP 探测:适合主机存活检查;注意 Linux 需赋予
cap_net_raw权限:sudo setcap cap_net_raw+ep blackbox_exporter -
DNS 探测:指定
dns_query_name和dns_query_type(如 A、AAAA、TXT),验证记录准确性与响应时间











