Uptime Monitoring
Overview
KubeSense can monitor the availability of internal and external endpoints from the Kubernetes cluster where the Sensor is installed. Uptime monitoring uses the Prometheus Blackbox Exporter through the OpenTelemetry (OTEL) Agent and forwards probe metrics to KubeSense.
Supported probe types are:
- HTTP/HTTPS - Check web endpoints
- TCP - Check TCP service reachability
- ICMP - Check whether an IP address responds to ping
- gRPC - Check gRPC endpoints
Each probe produces metrics such as probe_success and probe_duration_seconds. Targets can be grouped so one label set is applied to many URLs.
Prerequisites
Before configuring uptime monitoring, ensure that:
- KubeSense Sensor is installed in the target Kubernetes cluster.
- The OTEL Agent and uptime-monitor components are enabled.
- The Sensor namespace can resolve and reach every target.
- You can update the Sensor Helm values file.
Enable Uptime Monitoring
Add this configuration to the Sensor values file:
uptime-monitor:
enabled: true
otel-agent:
enabled: true
uptime-monitor:
enabled: true
httpProbe:
enabled: true
targetGroups:
- targets:
- "https://api.example.com/health"
- "https://web.example.com/health"
labels:
service: public-services
env: production
platform: externalThe top-level uptime-monitor section configures the Blackbox Exporter. The otel-agent.uptime-monitor section configures the OTEL Agent to scrape it and forward probe metrics.
Apply the configuration:
helm upgrade -i kubesensor kubesense/kubesensor \
--namespace kubesense \
--create-namespace \
-f values.yamlConfigure Targets and Labels
HTTP and HTTPS
Use targetGroups when several URLs share labels:
otel-agent:
uptime-monitor:
httpProbe:
enabled: true
targetGroups:
- targets:
- "https://service-01.example.com/health"
- "https://service-02.example.com/health"
- "https://service-03.example.com/health"
labels:
service: customer-services
env: production
platform: external
- targets:
- "https://service-04.example.com/health"
- "https://service-05.example.com/health"
labels:
service: customer-services
env: staging
platform: externalThe original string format remains supported:
otel-agent:
uptime-monitor:
httpProbe:
enabled: true
targets:
- "https://example.com"
- "https://api.example.com/health"For different labels on individual targets, use:
targets:
- target: "https://api.example.com/health"
labels:
service: api
env: production
platform: externaltargets and targetGroups may be used together. targetGroups is recommended for large target lists.
TCP
otel-agent:
uptime-monitor:
tcpProbe:
enabled: true
targetGroups:
- targets:
- "database.example.com:5432"
- "cache.example.com:6379"
labels:
service: data-services
env: production
platform: externalICMP
otel-agent:
uptime-monitor:
icmpProbe:
enabled: true
targetGroups:
- targets:
- "8.8.8.8"
- "1.1.1.1"
labels:
service: dns
env: external
platform: externalICMP probing may require cluster and pod security settings that permit ICMP packets.
gRPC
otel-agent:
uptime-monitor:
grpcProbe:
enabled: true
targetGroups:
- targets:
- "grpc-01.example.com:443"
- "grpc-02.example.com:443"
labels:
service: grpc-services
env: production
platform: externalAuthenticated HTTP Probes
Authenticated targets are configured in two parts:
- Define a Blackbox Exporter module under
uptime-monitor.config.modules. - Reference that module from an
otel-agent.uptime-monitor.httpProbeAuthgroup.
Targets in the same group use the same module and credentials. Create separate groups when credentials differ.
Bearer Token
uptime-monitor:
enabled: true
secretConfig: true
config:
modules:
http_2xx_bearer_services:
prober: http
timeout: 5s
http:
valid_http_versions: ["HTTP/1.1", "HTTP/2.0"]
follow_redirects: true
preferred_ip_protocol: "ip4"
headers:
Authorization: "Bearer <bearer-token>"
otel-agent:
uptime-monitor:
enabled: true
httpProbeAuth:
- module: http_2xx_bearer_services
targets:
- "https://private-api-01.example.com/health"
- "https://private-api-02.example.com/health"
labels:
auth_type: bearer
service: private-api
env: production
platform: externalOAuth 2.0 Client Credentials
uptime-monitor:
enabled: true
secretConfig: true
config:
modules:
http_2xx_oauth_services:
prober: http
timeout: 5s
http:
valid_http_versions: ["HTTP/1.1", "HTTP/2.0"]
follow_redirects: true
preferred_ip_protocol: "ip4"
oauth2:
client_id: "<client-id>"
client_secret: "<client-secret>"
token_url: "https://<tenant>.auth0.com/oauth/token"
endpoint_params:
audience: "<api-audience>"
otel-agent:
uptime-monitor:
enabled: true
httpProbeAuth:
- module: http_2xx_oauth_services
targets:
- "https://oauth-api-01.example.com/health"
- "https://oauth-api-02.example.com/health"
labels:
auth_type: oauth2
service: oauth-api
env: production
platform: externalSet secretConfig: true so the Blackbox Exporter configuration is stored in a Kubernetes Secret. Do not commit real tokens or client secrets to source control.
For ten bearer URLs and ten OAuth URLs, use one group for each authentication configuration when credentials are shared. If every URL has different credentials, define a module and group for each credential set.
Metrics and Labels
Labels in a target group are applied to every target in that group. The OTEL Agent also sets instance to the target URL:
labels:
service: payments
env: production
platform: externalUse stable, low-cardinality labels such as service, environment, region, and platform. Do not use sensitive data or rapidly changing values as labels.
Scaling Guidance
The configuration supports 100 or more targets. Each target is probed once per scrape interval, so resource usage depends on the number of targets, probe timeout, and scrape interval.
- Group targets that share labels and authentication settings.
- Keep different bearer tokens and OAuth client credentials in separate groups.
- Start with a 60-second scrape interval for approximately 100 targets and tune it for the required detection time.
- Keep probe timeouts shorter than the scrape interval.
- Provide sufficient CPU, memory, and network capacity to the OTEL Agent and Blackbox Exporter.
- Avoid duplicate targets across authenticated and unauthenticated groups unless both probes are intentional.
Troubleshooting
Targets are not appearing
-
Confirm
uptime-monitor.enabledandotel-agent.uptime-monitor.enabledaretrue. -
Confirm the relevant probe type is enabled.
-
Inspect the rendered configuration:
helm template kubesensor kubesense/kubesense -f values.yaml -
Check the OTEL Agent and uptime-monitor pod logs:
kubectl logs -n kubesense deploy/kubesensor-otel-agent kubectl logs -n kubesense deploy/kubesensor-uptime-monitor
Probes are failing
- Verify DNS resolution, network policies, target ports, and protocols.
- For HTTP, check redirects, TLS certificates, and authentication.
- For bearer authentication, check the token and
Authorizationheader. - For OAuth2, check the client credentials, token URL, audience, and endpoint parameters.
- For ICMP, verify that pod and cluster security settings permit ICMP probing.
Labels are missing
- Put
labelsbesidetargetsinside the sametargetGroupsentry. - For authenticated probes, put
labelsbesidemoduleandtargetsin thehttpProbeAuthentry. - Check that label names and values are valid Prometheus labels.
Summary
Use uptime monitoring to collect endpoint availability metrics from the Sensor cluster. Use targetGroups to manage large target lists, define labels once for related URLs, and isolate authenticated targets by Blackbox Exporter module and credential set.