Installation of NGINX Prometheus Exporter in production environment consists from following high level steps:
-
Install exporter;
-
Configure authentication;
-
Configure firewall;
-
Configure service for autostart and restart;
-
Check access to exporter from I&B monitoring platform.
1. Install NGINX Prometheus Exporter.
-
Check latest version, available platforms of NGINX Prometheus Exporter GitHub page and make necessary changes in variables on next step.
-
Prepare environment variables to simplify installation and configuration process.
export EXPORTER_VERSION=1.5.0
export EXPORTER_PLATFORM=linux_amd64
-
Download exporter
wget https://github.com/nginx/nginx-prometheus-exporter/releases/\
download/v$EXPORTER_VERSION/nginx-prometheus-exporter_"$EXPORTER_VERSION"_"$EXPORTER_PLATFORM".tar.gz
-
Create directory /usr/local/bin/nginx_exporter and untar exporter into it.
sudo mkdir -p /usr/local/bin/nginx_exporter
sudo tar xvfz nginx-prometheus-exporter_"$EXPORTER_VERSION"_"$EXPORTER_PLATFORM".tar.gz -C /usr/local/bin/nginx_exporter
-
Create prometheus user. If it already exist - go to step 6.
Fedora (RHEL, CentOS)
sudo useradd -M -s /sbin/nologin prometheus
-
-M(or--no-create-home): This option prevents the creation of a home directory for the new user; -
-s /sbin/nologin: This option sets the user's login shell to/sbin/nologin. This effectively prevents the user from interactively logging into the system. While the user won't have a password set, this further ensures they cannot log in.
Debian (Ubuntu)
sudo useradd -s /sbin/nologin prometheus --no-create-home
-
Make prometheus user owner of nginx_exporter directory
sudo chown -hR prometheus:prometheus /usr/local/bin/nginx_exporter
2. Configure firewall
Configure firewall on resource
-
NGINX Prometheus Exporter uses default port 9113, so allow it in firewall on resource.
Fedora (RHEL, CentOS)
sudo firewall-cmd --zone=public --add-port=9113/tcp --permanent
sudo systemctl reload firewalld
Check firewall configuration
sudo firewall-cmd --list-all
You should see in output:
ports: 9113/tcp
Debian (Ubuntu)
sudo ufw allow 9113
You should see in output:
Rules updated
Rules updated (v6)
Check firewall configuration
sudo ufw status
You should see in output:
To Action From
-- ------ ----
9113 ALLOW Anywhere
3. Configure authentication for exporter
Do the steps described in Exporters configuration → Authentication section.
4. Check configuration
-
To enable metrics expose you need to enable the stub status, you need to configure it in your NGINX configuration file. Below is an example:
location /stub_status {
stub_status;
allow 127.0.0.1; # Allow access only from localhost or your exporter host IP
deny all; # Deny access from other hosts
}
-
Run nginx_exporter
/usr/local/bin/nginx_exporter/nginx-prometheus-exporter --nginx.scrape-uri=https://127.0.0.1:443/stub_status \
--web.config.file=/usr/local/bin/nginx_exporter/web-config.yml
In this string --nginx.scrape-uri=https://127.0.0.1:443/stub_status, 127.0.0.1:443 this is ip:port of your nginx, --web.config.file=/usr/local/bin/nginx_exporter/web-config.yml sets path to your web-config file,
In output you should see:
... msg="TLS is enabled." ...
Check with browser if it is accessible at:
https://resource-hostname-or-ip:9113/metrics
After entering exporter’s user name and password you should see page like this:
# HELP go_gc_duration_seconds A summary of the wall-time pause (stop-the-world) duration in garbage collection cycles.
# TYPE go_gc_duration_seconds summary
go_gc_duration_seconds{quantile="0"} 0
...
Stop nginx exporter with Ctrl-c in terminal where you run it.
Make nginx_exporter service for autostart and restart.
Create file with your preferred text editor, for example nano …
sudo nano /etc/systemd/system/nginx_exporter.service
… and paste following text into it.
[Unit]
Description=nginx Exporter
[Service]
User=prometheus
ExecStart=/usr/local/bin/nginx_exporter/nginx-prometheus-exporter --nginx.scrape-uri=https://127.0.0.1:443/stub_status --web.config.file=/usr/local/bin/nginx_exporter/web-config.yml
[Install]
WantedBy=multi-user.target
Save file and exit editor.
Start service …
sudo systemctl daemon-reload
sudo systemctl start nginx_exporter
sudo systemctl enable nginx_exporter
… and check
sudo systemctl status nginx_exporter
You should see following output similar to:
In case of any problem, you should view log entries for service:
journalctl -u nginx_exporter.service -e
Now NGINX Prometheus Exporter is ready to accept data and then expose it to Prometheus.