Proxmox-Monitoring mit Prometheus & Grafana
Diese Anleitung beschreibt die Einrichtung des Proxmox-Monitorings mittels pve-exporter, Prometheus und Grafana.
Auf dem Hypervisor
Zunächst wird der SNMP-Daemon installiert:
apt install snmpd
Konfigurationsdatei bearbeiten:
nano /etc/snmp/snmpd.conf
rouser prometheus priv
rocommunity public
agentAddress udp:161
sysLocation Proxmox-Cluster
sysContact admin@localhost
includeAllDisks 10%
Anschließend wird ein dedizierter Benutzer für Prometheus angelegt:
!!! Achtung: Token unbedingt speichern !!!
pveum user add prometheus@pve
pveum aclmod / -user prometheus@pve -role PVEAuditor
pveum user token add prometheus@pve monitoring -privsep 0
Auf dem Monitoring-Server
Prometheus installieren
apt install prometheus
systemctl enable prometheus
pve-exporter installieren
wget https://github.com/bigtcze/pve-exporter/releases/latest/download/pve-exporter-linux-amd64
chmod +x pve-exporter-linux-amd64
sudo useradd --system --no-create-home --shell /usr/sbin/nologin pve-exporter
sudo wget -O /usr/local/bin/pve-exporter \
https://github.com/bigtcze/pve-exporter/releases/latest/download/pve-exporter-linux-amd64
sudo chmod +x /usr/local/bin/pve-exporter
Konfigurationsdatei bearbeiten:
sudo mkdir -p /etc/pve-exporter
nano /etc/pve-exporter/config.yml
proxmox:
host: "192.168.3.129"
port: 8006
# Option A: Password authentication
#user: "prometheus@pve"
#password: "your-password"
# Option B: API Token authentication (recommended, comment out user/password above)
token_id: "prometheus@pve!monitoring"
token_secret: "xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxx"
insecure_skip_verify: true
server:
listen_address: ":9221"
metrics_path: "/metrics"
Berechtigungen der Konfigurationsdatei setzen:
sudo chown root:pve-exporter /etc/pve-exporter/config.yml
sudo chmod 640 /etc/pve-exporter/config.yml
Dienst-Installation (systemd)
sudo cat > /etc/systemd/system/pve-exporter.service << 'EOF'
[Unit]
Description=Proxmox VE Exporter for Prometheus
Documentation=https://github.com/bigtcze/pve-exporter
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=pve-exporter
Group=pve-exporter
ExecStart=/usr/local/bin/pve-exporter -config /etc/pve-exporter/config.yml
Restart=on-failure
RestartSec=5
# Security hardening
ProtectSystem=strict
ProtectHome=yes
PrivateTmp=yes
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
ReadOnlyPaths=/
ReadWritePaths=
[Install]
WantedBy=multi-user.target
EOF
Grafana
apt install -y apt-transport-https software-properties-common wget
mkdir -p /etc/apt/keyrings/
wget -q -O - https://apt.grafana.com/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/grafana.gpg
echo "deb [signed-by=/etc/apt/keyrings/grafana.gpg] https://apt.grafana.com stable main" | sudo tee /etc/apt/sources.list.d/grafana.list
Empfohlene Dashboards (Import über die Dashboard-ID):
- 24550
- 1860
Prometheus-Konfiguration ergänzen
Konfigurationsdatei bearbeiten:
nano /etc/prometheus/prometheus.yml
scrape_configs:
- job_name: 'proxmox-pve'
static_configs:
- targets:
- localhost:9221
metrics_path: /metrics