PodMonitor

com.coreos.monitoring.v1.PodMonitor

The `PodMonitor` custom resource definition (CRD) defines how `Prometheus` and `PrometheusAgent` can scrape metrics from a group of pods. Among other things, it allows to specify:

`Prometheus` and `PrometheusAgent` objects select `PodMonitor` objects using label and namespace selectors.

apiVersionstring = "monitoring.coreos.com/v1"APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values.More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kindstring = "PodMonitor"Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to.Cannot be updated. In CamelCase.More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadataobject
specobject requiredspec defines the specification of desired Pod selection for target discovery by Prometheus.
attachMetadataobjectattachMetadata defines additional metadata which is added to the discovered targets.It requires Prometheus >= v2.35.0.
nodebooleannode when set to true, Prometheus attaches node metadata to the discovered targets.The Prometheus service account must have the `list` and `watch` permissions on the `Nodes` objects.
bodySizeLimitstringbodySizeLimit when defined specifies a job level limit on the size of uncompressed response body that will be accepted by Prometheus.It requires Prometheus >= v2.28.0.
convertClassicHistogramsToNHCBbooleanconvertClassicHistogramsToNHCB defines whether to convert all scraped classic histograms into a native histogram with custom buckets. It requires Prometheus >= v3.0.0.
fallbackScrapeProtocolstringfallbackScrapeProtocol defines the protocol to use if a scrape returns blank, unparseable, or otherwise invalid Content-Type.It requires Prometheus >= v3.0.0.
jobLabelstringjobLabel defines the label to use to retrieve the job name from. `jobLabel` selects the label from the associated Kubernetes `Pod` object which will be used as the `job` label for all metrics.For example if `jobLabel` is set to `foo` and the Kubernetes `Pod` object is labeled with `foo: bar`, then Prometheus adds the `job="bar"` label to all ingested metrics.If the value of this field is empty, the `job` label of the metrics defaults to the namespace and name of the PodMonitor object (e.g. `<namespace>/<name>`).
keepDroppedTargetsinteger (int64)keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling that will be kept in memory. 0 means no limit.It requires Prometheus >= v2.47.0.
labelLimitinteger (int64)labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.It requires Prometheus >= v2.27.0.
labelNameLengthLimitinteger (int64)labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.It requires Prometheus >= v2.27.0.
labelValueLengthLimitinteger (int64)labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.It requires Prometheus >= v2.27.0.
namespaceSelectorobjectnamespaceSelector defines in which namespace(s) Prometheus should discover the pods. By default, the pods are discovered in the same namespace as the `PodMonitor` object but it is possible to select pods across different/all namespaces.
anybooleanany defines the boolean describing whether all namespaces are selected in contrast to a list restricting them.
matchNames[]stringmatchNames defines the list of namespace names to select from.
nativeHistogramBucketLimitinteger (int64)nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram, buckets will be merged to stay within the limit. It requires Prometheus >= v2.45.0.
nativeHistogramMinBucketFactorobjectnativeHistogramMinBucketFactor defines if the growth factor of one bucket to the next is smaller than this, buckets will be merged to increase the factor sufficiently. It requires Prometheus >= v2.50.0.
podMetricsEndpoints[]objectpodMetricsEndpoints defines how to scrape metrics from the selected pods.
authorizationobjectauthorization configures the Authorization header credentials used by the client.Cannot be set at the same time as `basicAuth`, `bearerTokenSecret` or `oauth2`.
credentialsobjectcredentials defines a key of a Secret in the namespace that contains the credentials for authentication.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
typestringtype defines the authentication type. The value is case-insensitive."Basic" is not a supported value.Default: "Bearer"
basicAuthobjectbasicAuth defines the Basic Authentication credentials used by the client.Cannot be set at the same time as `authorization`, `bearerTokenSecret` or `oauth2`.
passwordobjectpassword defines a key of a Secret containing the password for authentication.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
usernameobjectusername defines a key of a Secret containing the username for authentication.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
bearerTokenSecretobjectbearerTokenSecret defines a key of a Secret containing the bearer token used by the client for authentication. The secret needs to be in the same namespace as the custom resource and readable by the Prometheus Operator.Cannot be set at the same time as `authorization`, `basicAuth` or `oauth2`.Deprecated: use `authorization` instead.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
enableHttp2booleanenableHttp2 can be used to disable HTTP2.
filterRunningbooleanfilterRunning when true, the pods which are not running (e.g. either in Failed or Succeeded state) are dropped during the target discovery.If unset, the filtering is enabled.More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase
followRedirectsbooleanfollowRedirects defines whether the client should follow HTTP 3xx redirects.
honorLabelsbooleanhonorLabels when true preserves the metric's labels when they collide with the target's labels.
honorTimestampsbooleanhonorTimestamps defines whether Prometheus preserves the timestamps when exposed by the target.
intervalstringinterval at which Prometheus scrapes the metrics from the target.If empty, Prometheus uses the global scrape interval.
metricRelabelings[]objectmetricRelabelings defines the relabeling rules to apply to the samples before ingestion.
actionstringaction to perform based on the regex matching.`Uppercase` and `Lowercase` actions require Prometheus >= v2.36.0. `DropEqual` and `KeepEqual` actions require Prometheus >= v2.41.0.Default: "Replace"
modulusinteger (int64)modulus to take of the hash of the source label values.Only applicable when the action is `HashMod`.
regexstringregex defines the regular expression against which the extracted value is matched.
replacementstringreplacement value against which a Replace action is performed if the regular expression matches.Regex capture groups are available.
separatorstringseparator defines the string between concatenated SourceLabels.
sourceLabels[]stringsourceLabels defines the source labels select values from existing labels. Their content is concatenated using the configured Separator and matched against the configured regular expression.
targetLabelstringtargetLabel defines the label to which the resulting string is written in a replacement.It is mandatory for `Replace`, `HashMod`, `Lowercase`, `Uppercase`, `KeepEqual` and `DropEqual` actions.Regex capture groups are available.
noProxystringnoProxy defines a comma-separated string that can contain IPs, CIDR notation, domain names that should be excluded from proxying. IP and domain names can contain port numbers.It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
oauth2objectoauth2 defines the OAuth2 settings used by the client.It requires Prometheus >= 2.27.0.Cannot be set at the same time as `authorization`, `basicAuth` or `bearerTokenSecret`.
clientIdobject requiredclientId defines a key of a Secret or ConfigMap containing the OAuth2 client's ID.
configMapobjectconfigMap defines the ConfigMap containing data to use for the targets.
keystring requiredThe key to select.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the ConfigMap or its key must be defined
secretobjectsecret defines the Secret containing data to use for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
clientSecretobject requiredclientSecret defines a key of a Secret containing the OAuth2 client's secret.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
endpointParamsmap[string]stringendpointParams configures the HTTP parameters to append to the token URL.
noProxystringnoProxy defines a comma-separated string that can contain IPs, CIDR notation, domain names that should be excluded from proxying. IP and domain names can contain port numbers.It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyConnectHeadermap[string][]objectproxyConnectHeader optionally specifies headers to send to proxies during CONNECT requests.It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyFromEnvironmentbooleanproxyFromEnvironment defines whether to use the proxy configuration defined by environment variables (HTTP_PROXY, HTTPS_PROXY, and NO_PROXY).It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyUrlstringproxyUrl defines the HTTP proxy server to use.
scopes[]stringscopes defines the OAuth2 scopes used for the token request.
tlsConfigobjecttlsConfig defines the TLS configuration to use when connecting to the OAuth2 server. It requires Prometheus >= v2.43.0.
caobjectca defines the Certificate authority used when verifying server certificates.
configMapobjectconfigMap defines the ConfigMap containing data to use for the targets.
keystring requiredThe key to select.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the ConfigMap or its key must be defined
secretobjectsecret defines the Secret containing data to use for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
certobjectcert defines the Client certificate to present when doing client-authentication.
configMapobjectconfigMap defines the ConfigMap containing data to use for the targets.
keystring requiredThe key to select.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the ConfigMap or its key must be defined
secretobjectsecret defines the Secret containing data to use for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
insecureSkipVerifybooleaninsecureSkipVerify defines how to disable target certificate validation.
keySecretobjectkeySecret defines the Secret containing the client key file for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
maxVersionstringmaxVersion defines the maximum acceptable TLS version.It requires Prometheus >= v2.41.0 or Thanos >= v0.31.0.
minVersionstringminVersion defines the minimum acceptable TLS version.It requires Prometheus >= v2.35.0 or Thanos >= v0.28.0.
serverNamestringserverName is used to verify the hostname for the targets.
tokenUrlstring requiredtokenUrl defines the URL to fetch the token from.
paramsmap[string][]stringparams define optional HTTP URL parameters.
pathstringpath defines the HTTP path from which to scrape for metrics.If empty, Prometheus uses the default value (e.g. `/metrics`).
portstringport defines the `Pod` port name which exposes the endpoint.If the pod doesn't expose a port with the same name, it will result in no targets being discovered.If a `Pod` has multiple `Port`s with the same name (which is not recommended), one target instance per unique port number will be generated.It takes precedence over the `portNumber` and `targetPort` fields.
portNumberinteger (int32)portNumber defines the `Pod` port number which exposes the endpoint.The `Pod` must declare the specified `Port` in its spec or the target will be dropped by Prometheus.This cannot be used to enable scraping of an undeclared port. To scrape targets on a port which isn't exposed, you need to use relabeling to override the `__address__` label (but beware of duplicate targets if the `Pod` has other declared ports).In practice Prometheus will select targets for which the matches the target's __meta_kubernetes_pod_container_port_number.
proxyConnectHeadermap[string][]objectproxyConnectHeader optionally specifies headers to send to proxies during CONNECT requests.It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyFromEnvironmentbooleanproxyFromEnvironment defines whether to use the proxy configuration defined by environment variables (HTTP_PROXY, HTTPS_PROXY, and NO_PROXY).It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyUrlstringproxyUrl defines the HTTP proxy server to use.
relabelings[]objectrelabelings defines the relabeling rules to apply the target's metadata labels.The Operator automatically adds relabelings for a few standard Kubernetes fields.The original scrape job's name is available via the `__tmp_prometheus_job_name` label.More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
actionstringaction to perform based on the regex matching.`Uppercase` and `Lowercase` actions require Prometheus >= v2.36.0. `DropEqual` and `KeepEqual` actions require Prometheus >= v2.41.0.Default: "Replace"
modulusinteger (int64)modulus to take of the hash of the source label values.Only applicable when the action is `HashMod`.
regexstringregex defines the regular expression against which the extracted value is matched.
replacementstringreplacement value against which a Replace action is performed if the regular expression matches.Regex capture groups are available.
separatorstringseparator defines the string between concatenated SourceLabels.
sourceLabels[]stringsourceLabels defines the source labels select values from existing labels. Their content is concatenated using the configured Separator and matched against the configured regular expression.
targetLabelstringtargetLabel defines the label to which the resulting string is written in a replacement.It is mandatory for `Replace`, `HashMod`, `Lowercase`, `Uppercase`, `KeepEqual` and `DropEqual` actions.Regex capture groups are available.
schemestringscheme defines the HTTP scheme to use for scraping.
scrapeTimeoutstringscrapeTimeout defines the timeout after which Prometheus considers the scrape to be failed.If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used. The value cannot be greater than the scrape interval otherwise the operator will reject the resource.
targetPortobjecttargetPort defines the name or number of the target port of the `Pod` object behind the Service, the port must be specified with container port property.Deprecated: use 'port' or 'portNumber' instead.
tlsConfigobjecttlsConfig defines the TLS configuration used by the client.
caobjectca defines the Certificate authority used when verifying server certificates.
configMapobjectconfigMap defines the ConfigMap containing data to use for the targets.
keystring requiredThe key to select.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the ConfigMap or its key must be defined
secretobjectsecret defines the Secret containing data to use for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
certobjectcert defines the Client certificate to present when doing client-authentication.
configMapobjectconfigMap defines the ConfigMap containing data to use for the targets.
keystring requiredThe key to select.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the ConfigMap or its key must be defined
secretobjectsecret defines the Secret containing data to use for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
insecureSkipVerifybooleaninsecureSkipVerify defines how to disable target certificate validation.
keySecretobjectkeySecret defines the Secret containing the client key file for the targets.
keystring requiredThe key of the secret to select from. Must be a valid secret key.
namestringName of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong.More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optionalbooleanSpecify whether the Secret or its key must be defined
maxVersionstringmaxVersion defines the maximum acceptable TLS version.It requires Prometheus >= v2.41.0 or Thanos >= v0.31.0.
minVersionstringminVersion defines the minimum acceptable TLS version.It requires Prometheus >= v2.35.0 or Thanos >= v0.28.0.
serverNamestringserverName is used to verify the hostname for the targets.
trackTimestampsStalenessbooleantrackTimestampsStaleness defines whether Prometheus tracks staleness of the metrics that have an explicit timestamp present in scraped data. Has no effect if `honorTimestamps` is false.It requires Prometheus >= v2.48.0.
podTargetLabels[]stringpodTargetLabels defines the labels which are transferred from the associated Kubernetes `Pod` object onto the ingested metrics.
sampleLimitinteger (int64)sampleLimit defines a per-scrape limit on the number of scraped samples that will be accepted.
scrapeClassstringscrapeClass defines the scrape class to apply.
scrapeClassicHistogramsbooleanscrapeClassicHistograms defines whether to scrape a classic histogram that is also exposed as a native histogram. It requires Prometheus >= v2.45.0.Notice: `scrapeClassicHistograms` corresponds to the `always_scrape_classic_histograms` field in the Prometheus configuration.
scrapeNativeHistogramsbooleanscrapeNativeHistograms defines whether to enable scraping of native histograms. It requires Prometheus >= v3.8.0.
scrapeProtocols[]stringscrapeProtocols defines the protocols to negotiate during a scrape. It tells clients the protocols supported by Prometheus in order of preference (from most to least preferred).If unset, Prometheus uses its default value.It requires Prometheus >= v2.49.0.
selectorobject requiredselector defines the label selector to select the Kubernetes `Pod` objects to scrape metrics from.
matchExpressions[]objectmatchExpressions is a list of label selector requirements. The requirements are ANDed.
keystring requiredkey is the label key that the selector applies to.
operatorstring requiredoperator represents a key's relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
values[]stringvalues is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.
matchLabelsmap[string]stringmatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.
selectorMechanismstringselectorMechanism defines the mechanism used to select the endpoints to scrape. By default, the selection process relies on relabel configurations to filter the discovered targets. Alternatively, you can opt in for role selectors, which may offer better efficiency in large clusters. Which strategy is best for your use case needs to be carefully evaluated.It requires Prometheus >= v2.17.0.
targetLimitinteger (int64)targetLimit defines a limit on the number of scraped targets that will be accepted.
statusobject read-onlystatus defines the status subresource. It is under active development and is updated only when the "StatusForConfigurationResources" feature gate is enabled.Most recent observed status of the PodMonitor.Read-only. More info: https://github.com/kubernetes/community/blob/master/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
bindings[]object read-onlybindings defines the list of workload resources (Prometheus, PrometheusAgent, ThanosRuler or Alertmanager) which select the configuration resource.
conditions[]object read-onlyconditions defines the current state of the configuration resource when bound to the referenced Workload object.
lastTransitionTimestring (date-time) required read-onlylastTransitionTime defines the time of the last update to the current status property.
messagestring read-onlymessage defines the human-readable message indicating details for the condition's last transition.
observedGenerationinteger (int64) read-onlyobservedGeneration defines the .metadata.generation that the condition was set based upon. For instance, if `.metadata.generation` is currently 12, but the `.status.conditions[].observedGeneration` is 9, the condition is out of date with respect to the current state of the object.
reasonstring read-onlyreason for the condition's last transition.
statusstring required read-onlystatus of the condition.
typestring required read-onlytype of the condition being reported. Currently, only "Accepted" is supported.
groupstring required read-onlygroup defines the group of the referenced resource.
namestring required read-onlyname defines the name of the referenced object.
namespacestring required read-onlynamespace defines the namespace of the referenced object.
resourcestring required read-onlyresource defines the type of resource being referenced (e.g. Prometheus, PrometheusAgent, ThanosRuler or Alertmanager).