Grafana Monitoring – Proxmox

Proxmox-Monitoring mit Prometheus & Grafana

Diese Anleitung beschreibt die Einrichtung des Proxmox-Monitorings mittels pve-exporter, Prometheus und Grafana.


Auf dem Hypervisor

Zunächst wird der SNMP-Daemon installiert:

apt install snmpd

Konfigurationsdatei bearbeiten:

nano /etc/snmp/snmpd.conf
rouser prometheus priv
rocommunity public
agentAddress udp:161
sysLocation     Proxmox-Cluster
sysContact      admin@localhost
includeAllDisks 10%

Anschließend wird ein dedizierter Benutzer für Prometheus angelegt:

!!! Achtung: Token unbedingt speichern !!!

pveum user add prometheus@pve
pveum aclmod / -user prometheus@pve -role PVEAuditor
pveum user token add prometheus@pve monitoring -privsep 0

Auf dem Monitoring-Server

Prometheus installieren

apt install prometheus
systemctl enable prometheus

pve-exporter installieren

wget https://github.com/bigtcze/pve-exporter/releases/latest/download/pve-exporter-linux-amd64
chmod +x pve-exporter-linux-amd64

sudo useradd --system --no-create-home --shell /usr/sbin/nologin pve-exporter
sudo wget -O /usr/local/bin/pve-exporter \
  https://github.com/bigtcze/pve-exporter/releases/latest/download/pve-exporter-linux-amd64
sudo chmod +x /usr/local/bin/pve-exporter

Konfigurationsdatei bearbeiten:

sudo mkdir -p /etc/pve-exporter

nano /etc/pve-exporter/config.yml
proxmox:
  host: "192.168.3.129"
  port: 8006

  # Option A: Password authentication
  #user: "prometheus@pve"
  #password: "your-password"

  # Option B: API Token authentication (recommended, comment out user/password above)
  token_id: "prometheus@pve!monitoring"
  token_secret: "xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxx"

  insecure_skip_verify: true

server:
  listen_address: ":9221"
  metrics_path: "/metrics"

Berechtigungen der Konfigurationsdatei setzen:

sudo chown root:pve-exporter /etc/pve-exporter/config.yml
sudo chmod 640 /etc/pve-exporter/config.yml

Dienst-Installation (systemd)

sudo cat > /etc/systemd/system/pve-exporter.service << 'EOF'
[Unit]
Description=Proxmox VE Exporter for Prometheus
Documentation=https://github.com/bigtcze/pve-exporter
After=network-online.target
Wants=network-online.target

[Service]
Type=simple
User=pve-exporter
Group=pve-exporter
ExecStart=/usr/local/bin/pve-exporter -config /etc/pve-exporter/config.yml
Restart=on-failure
RestartSec=5

# Security hardening
ProtectSystem=strict
ProtectHome=yes
PrivateTmp=yes
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
ReadOnlyPaths=/
ReadWritePaths=

[Install]
WantedBy=multi-user.target
EOF

Grafana

apt install -y apt-transport-https software-properties-common wget
mkdir -p /etc/apt/keyrings/
wget -q -O - https://apt.grafana.com/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/grafana.gpg
echo "deb [signed-by=/etc/apt/keyrings/grafana.gpg] https://apt.grafana.com stable main" | sudo tee /etc/apt/sources.list.d/grafana.list

Empfohlene Dashboards (Import über die Dashboard-ID):

  • 24550
  • 1860

Prometheus-Konfiguration ergänzen

Konfigurationsdatei bearbeiten:

nano /etc/prometheus/prometheus.yml
scrape_configs:
  - job_name: 'proxmox-pve'
    static_configs:
      - targets:
           - localhost:9221
    metrics_path: /metrics