Configure Prometheus with TLS
Note
For basic Prometheus setup without TLS, see Setup Prometheus. This page covers advanced TLS configuration with cert-manager.This page shows how to configure Kueue to use Prometheus metrics with TLS encryption.
The page is intended for a batch administrator.
Before you begin
Make sure the following conditions are met:
- A Kubernetes cluster is running.
- The kubectl command-line tool has communication with your cluster.
- Kueue is installed.
- Prometheus is installed
- Cert Manager can be optionally installed
Kueue supports either Kustomize or installation via a Helm chart.
Kustomize Installation
- Enable
prometheusinconfig/default/kustomization.yamland uncomment all sections with ‘PROMETHEUS’.
Kustomize Prometheus with certificates
If you want to enable TLS verification for the metrics endpoint, follow the directions below.
- Set
internalCertManagement.enabletofalsein the kueue configuration. - Comment out the
internalcertfolder inconfig/default/kustomization.yaml. - Enable
cert-managerinconfig/default/kustomization.yamland uncomment all sections with ‘CERTMANAGER’. - To enable secure metrics with TLS protection, uncomment all sections with ‘PROMETHEUS-WITH-CERTS’.
Helm Installation
Prometheus installation
Kueue can also supports helm deployment for Prometheus.
- Set
enablePrometheusin your values.yaml file to true.
Helm Prometheus with certificates
If you want to secure the metrics endpoints with external certificates:
- Set both
enableCertManagerandenablePrometheusto true. SettingenableCertManageralso disables internal cert management, unless you setinternalCertManagementexplicitly inmanagerConfig. - The chart configures the ServiceMonitor to verify the metrics certificate issued by cert-manager, so no
tlsConfigis needed.
To customize it, set metrics.serviceMonitor.tlsConfig. It replaces the generated configuration, so set serverName and ca yourself. Certificate verification stays disabled unless you set insecureSkipVerify: false. For example:
...
metrics:
prometheusNamespace: monitoring
# tls configs for serviceMonitor
serviceMonitor:
tlsConfig:
serverName: kueue-controller-manager-metrics-service.kueue-system.svc
insecureSkipVerify: false
ca:
secret:
name: kueue-metrics-server-cert
key: ca.crt
cert:
secret:
name: kueue-metrics-server-cert
key: tls.crt
keySecret:
name: kueue-metrics-server-cert
key: tls.key
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.