I&B Monitoring Platform documentation

Pushgateway

Installation of Prometheus Pushgateway in production environment consists from following high level steps:

  1. Install exporter;

  2. Configure authentication;

  3. Configure firewall;

  4. Configure service for autostart and restart;

  5. Check access to exporter from I&B monitoring platform.

1. Install Prometheus Pushgateway.

  1. Check latest version, available platforms on Pushgateway GitHub page and make necessary changes in variables on next step.

  2. Prepare environment variables to simplify installation and configuration process.

Bash
export EXPORTER_VERSION=1.11.1
export EXPORTER_PLATFORM=linux-amd64
  1. Download exporter

Bash
wget https://github.com/prometheus/pushgateway/releases/download/v$EXPORTER_VERSION/pushgateway-$EXPORTER_VERSION.$EXPORTER_PLATFORM.tar.gz
  1. Create directory /usr/local/bin/pushgateway and untar exporter into it.

Bash
sudo mkdir -p /usr/local/bin/pushgateway
sudo tar xvfz pushgateway-$EXPORTER_VERSION.$EXPORTER_PLATFORM.tar.gz -C /usr/local/bin/pushgateway --strip-components=1
  1. Create prometheus user. If it already exist - go to step 6.

Fedora (RHEL, CentOS)

Bash
sudo useradd -M -s /sbin/nologin prometheus
  • -M (or --no-create-home): This option prevents the creation of a home directory for the new user;

  • -s /sbin/nologin: This option sets the user's login shell to /sbin/nologin. This effectively prevents the user from interactively logging into the system. While the user won't have a password set, this further ensures they cannot log in.

Debian (Ubuntu)

Bash
sudo useradd -s /sbin/nologin prometheus --no-create-home
  1. Make prometheus user owner of pushgateway directory

Bash
sudo chown -hR prometheus:prometheus /usr/local/bin/pushgateway

2. Configure firewall

Configure firewall on resource

  1. Pushgateway uses default port 9091, so allow it in firewall on resource.

Fedora (RHEL, CentOS)

Bash
sudo firewall-cmd --zone=public --add-port=9091/tcp --permanent
sudo systemctl reload firewalld

Check firewall configuration

Bash
sudo firewall-cmd --list-all

You should see in output:

Bash
ports: 9091/tcp

Debian (Ubuntu)

Bash
sudo iptables -A INPUT -p tcp --dport 9091 -j ACCEPT

You see nothing in output, its normal, to see state of firewal you need run:

Bash
sudo iptables -L | grep 9091

You should see output like this:

Bash
sudo iptables -L | grep 9091
ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:9091

3. Configure authentication for exporter

Do the steps described in Exporters configuration → Authentication section.

4. Check configuration

  1. Run pushgateway

Bash
/usr/local/bin/pushgateway/pushgateway --web.config.file=/usr/local/bin/pushgateway/web-config.yml

In output you should see:

... msg="TLS is enabled." ...

Check with browser if it is accessible at:

https://resource-hostname-or-ip:9091/metrics

After entering exporter’s user name and password you should see page like this:

# HELP go_gc_duration_seconds A summary of the wall-time pause (stop-the-world) duration in garbage collection cycles.
# TYPE go_gc_duration_seconds summary
go_gc_duration_seconds{quantile="0"} 2.2622e-05
...

Stop pushgateway with Ctrl-c in terminal where you run it.

Make pushgateway service for autostart and restart.

Create file with your preferred text editor, for example nano …

Bash
sudo nano /etc/systemd/system/pushgateway.service

… and paste following text into it.

Bash
[Unit]
Description=pushgateway
After=network-online.target

[Service]
User=prometheus
Group=prometheus
Type=simple
ExecStart=/usr/local/bin/pushgateway/pushgateway --web.config.file=/usr/local/bin/pushgateway/pushgateway/web-config.yml
Restart=always

[Install]
WantedBy=multi-user.target

Save file and exit editor.

Start service …

Bash
sudo systemctl daemon-reload
sudo systemctl start pushgateway
sudo systemctl enable pushgateway

… and check

Bash
sudo systemctl status pushgateway

You should see following output similar to:

image-20250915-130812.png

In case of any problem, you should view log entries for service:

Bash
journalctl -u myservice.service -e

Now Pushgateway is ready to accept data and then expose it to Prometheus.

info To configure Pushgateway to collect Top N CPU and MEM usage processes see section here.