Skip to content

ServiceMonitor [monitoring.coreos.com/v1]

Description

The ServiceMonitor custom resource definition (CRD) defines how Prometheus and PrometheusAgent can scrape metrics from a group of services. Among other things, it allows to specify:

  • The services to scrape via label selectors.
  • The container ports to scrape.
  • Authentication credentials to use.
  • Target and metric relabeling.

Prometheus and PrometheusAgent objects select ServiceMonitor objects using label and namespace selectors.

Type
`object`
Required
  • spec

Specification

Property Type Description
apiVersion string APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata ObjectMeta Standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
spec object spec defines the specification of desired Service selection for target discovery by Prometheus.
status object status defines the status subresource. It is under active development and is updated only when the "StatusForConfigurationResources" feature gate is enabled.
Most recent observed status of the ServiceMonitor. Read-only. More info: https://github.com/kubernetes/community/blob/master/contributors/devel/sig-architecture/api-conventions.md#spec-and-status

.spec

Description
spec defines the specification of desired Service selection for target discovery by Prometheus.
Type
`object`
Required
  • endpoints
  • selector
Property Type Description
attachMetadata object attachMetadata defines additional metadata which is added to the discovered targets.
It requires Prometheus >= v2.37.0.
bodySizeLimit string bodySizeLimit when defined, bodySizeLimit specifies a job level limit on the size of uncompressed response body that will be accepted by Prometheus.
It requires Prometheus >= v2.28.0.
convertClassicHistogramsToNHCB boolean convertClassicHistogramsToNHCB defines whether to convert all scraped classic histograms into a native histogram with custom buckets. It requires Prometheus >= v3.0.0.
endpoints array endpoints defines the list of endpoints part of this ServiceMonitor. Defines how to scrape metrics from Kubernetes Endpoints objects. In most cases, an Endpoints object is backed by a Kubernetes Service object with the same name and labels.
endpoints[] object Endpoint defines an endpoint serving Prometheus metrics to be scraped by Prometheus.
fallbackScrapeProtocol string fallbackScrapeProtocol defines the protocol to use if a scrape returns blank, unparseable, or otherwise invalid Content-Type.
It requires Prometheus >= v3.0.0.
jobLabel string jobLabel selects the label from the associated Kubernetes Service object which will be used as the job label for all metrics.
For example if jobLabel is set to foo and the Kubernetes Service object is labeled with foo: bar, then Prometheus adds the job="bar" label to all ingested metrics.
If the value of this field is empty or if the label doesn’t exist for the given Service, the job label of the metrics defaults to the name of the associated Kubernetes Service.
keepDroppedTargets integer keepDroppedTargets defines the per-scrape limit on the number of targets dropped by relabeling that will be kept in memory. 0 means no limit.
It requires Prometheus >= v2.47.0.
labelLimit integer labelLimit defines the per-scrape limit on number of labels that will be accepted for a sample.
It requires Prometheus >= v2.27.0.
labelNameLengthLimit integer labelNameLengthLimit defines the per-scrape limit on length of labels name that will be accepted for a sample.
It requires Prometheus >= v2.27.0.
labelValueLengthLimit integer labelValueLengthLimit defines the per-scrape limit on length of labels value that will be accepted for a sample.
It requires Prometheus >= v2.27.0.
namespaceSelector object namespaceSelector defines in which namespace(s) Prometheus should discover the services. By default, the services are discovered in the same namespace as the ServiceMonitor object but it is possible to select pods across different/all namespaces.
nativeHistogramBucketLimit integer nativeHistogramBucketLimit defines ff there are more than this many buckets in a native histogram, buckets will be merged to stay within the limit. It requires Prometheus >= v2.45.0.
nativeHistogramMinBucketFactor integer-or-string nativeHistogramMinBucketFactor defines if the growth factor of one bucket to the next is smaller than this, buckets will be merged to increase the factor sufficiently. It requires Prometheus >= v2.50.0.
podTargetLabels array (string) podTargetLabels defines the labels which are transferred from the associated Kubernetes Pod object onto the ingested metrics.
sampleLimit integer sampleLimit defines a per-scrape limit on the number of scraped samples that will be accepted.
scrapeClass string scrapeClass defines the scrape class to apply.
scrapeClassicHistograms boolean scrapeClassicHistograms defines whether to scrape a classic histogram that is also exposed as a native histogram. It requires Prometheus >= v2.45.0.
Notice: scrapeClassicHistograms corresponds to the always_scrape_classic_histograms field in the Prometheus configuration.
scrapeNativeHistograms boolean scrapeNativeHistograms defines whether to enable scraping of native histograms. It requires Prometheus >= v3.8.0.
scrapeProtocols array (string) scrapeProtocols defines the protocols to negotiate during a scrape. It tells clients the protocols supported by Prometheus in order of preference (from most to least preferred).
If unset, Prometheus uses its default value.
It requires Prometheus >= v2.49.0.
selector object selector defines the label selector to select the Kubernetes Endpoints objects to scrape metrics from.
selectorMechanism string selectorMechanism defines the mechanism used to select the endpoints to scrape. By default, the selection process relies on relabel configurations to filter the discovered targets. Alternatively, you can opt in for role selectors, which may offer better efficiency in large clusters. Which strategy is best for your use case needs to be carefully evaluated.
It requires Prometheus >= v2.17.0.
serviceDiscoveryRole string serviceDiscoveryRole defines the service discovery role used to discover targets.
If set, the value should be either "Endpoints" or "EndpointSlice". Otherwise it defaults to the value defined in the Prometheus/PrometheusAgent resource.
targetLabels array (string) targetLabels defines the labels which are transferred from the associated Kubernetes Service object onto the ingested metrics.
targetLimit integer targetLimit defines a limit on the number of scraped targets that will be accepted.

.spec.attachMetadata

Description

attachMetadata defines additional metadata which is added to the discovered targets.

It requires Prometheus >= v2.37.0.

Type
`object`
Property Type Description
node boolean node when set to true, Prometheus attaches node metadata to the discovered targets.
The Prometheus service account must have the list and watch permissions on the Nodes objects.

.spec.endpoints

Description
endpoints defines the list of endpoints part of this ServiceMonitor. Defines how to scrape metrics from Kubernetes Endpoints objects. In most cases, an Endpoints object is backed by a Kubernetes Service object with the same name and labels.
Type
`array`

.spec.endpoints[]

Description
Endpoint defines an endpoint serving Prometheus metrics to be scraped by Prometheus.
Type
`object`
Property Type Description
authorization object authorization configures the Authorization header credentials used by the client.
Cannot be set at the same time as basicAuth, bearerTokenSecret or oauth2.
basicAuth object basicAuth defines the Basic Authentication credentials used by the client.
Cannot be set at the same time as authorization, bearerTokenSecret or oauth2.
bearerTokenFile string bearerTokenFile defines the file to read bearer token for scraping the target.
Deprecated: use authorization instead.
bearerTokenSecret object bearerTokenSecret defines a key of a Secret containing the bearer token used by the client for authentication. The secret needs to be in the same namespace as the custom resource and readable by the Prometheus Operator.
Cannot be set at the same time as authorization, basicAuth or oauth2.
Deprecated: use authorization instead.
enableHttp2 boolean enableHttp2 can be used to disable HTTP2.
filterRunning boolean filterRunning when true, the pods which are not running (e.g. either in Failed or Succeeded state) are dropped during the target discovery.
If unset, the filtering is enabled.
More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase
followRedirects boolean followRedirects defines whether the client should follow HTTP 3xx redirects.
honorLabels boolean honorLabels defines when true the metric’s labels when they collide with the target’s labels.
honorTimestamps boolean honorTimestamps defines whether Prometheus preserves the timestamps when exposed by the target.
interval string interval at which Prometheus scrapes the metrics from the target.
If empty, Prometheus uses the global scrape interval.
metricRelabelings array metricRelabelings defines the relabeling rules to apply to the samples before ingestion.
metricRelabelings[] object RelabelConfig allows dynamic rewriting of the label set for targets, alerts, scraped samples and remote write samples.
More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
noProxy string noProxy defines a comma-separated string that can contain IPs, CIDR notation, domain names that should be excluded from proxying. IP and domain names can contain port numbers.
It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
oauth2 object oauth2 defines the OAuth2 settings used by the client.
It requires Prometheus >= 2.27.0.
Cannot be set at the same time as authorization, basicAuth or bearerTokenSecret.
params object params define optional HTTP URL parameters.
params{} array (string)
path string path defines the HTTP path from which to scrape for metrics.
If empty, Prometheus uses the default value (e.g. /metrics).
port string port defines the name of the Service port which this endpoint refers to.
It takes precedence over targetPort.
proxyConnectHeader object proxyConnectHeader optionally specifies headers to send to proxies during CONNECT requests.
It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyConnectHeader{} array
proxyConnectHeader{}[] object SecretKeySelector selects a key of a Secret.
proxyFromEnvironment boolean proxyFromEnvironment defines whether to use the proxy configuration defined by environment variables (HTTP_PROXY, HTTPS_PROXY, and NO_PROXY).
It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyUrl string proxyUrl defines the HTTP proxy server to use.
relabelings array relabelings defines the relabeling rules to apply the target’s metadata labels.
The Operator automatically adds relabelings for a few standard Kubernetes fields.
The original scrape job’s name is available via the \__tmp_prometheus_job_name label.
More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
relabelings[] object RelabelConfig allows dynamic rewriting of the label set for targets, alerts, scraped samples and remote write samples.
More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
scheme string scheme defines the HTTP scheme to use when scraping the metrics.
scrapeTimeout string scrapeTimeout defines the timeout after which Prometheus considers the scrape to be failed.
If empty, Prometheus uses the global scrape timeout unless it is less than the target’s scrape interval value in which the latter is used. The value cannot be greater than the scrape interval otherwise the operator will reject the resource.
targetPort integer-or-string targetPort defines the name or number of the target port of the Pod object behind the Service. The port must be specified with the container’s port property.
tlsConfig object tlsConfig defines TLS configuration used by the client.
trackTimestampsStaleness boolean trackTimestampsStaleness defines whether Prometheus tracks staleness of the metrics that have an explicit timestamp present in scraped data. Has no effect if honorTimestamps is false.
It requires Prometheus >= v2.48.0.

.spec.endpoints[].authorization

Description

authorization configures the Authorization header credentials used by the client.

Cannot be set at the same time as basicAuth, bearerTokenSecret or oauth2.

Type
`object`
Property Type Description
credentials object credentials defines a key of a Secret in the namespace that contains the credentials for authentication.
type string type defines the authentication type. The value is case-insensitive.
"Basic" is not a supported value.
Default: "Bearer"

.spec.endpoints[].authorization.credentials

Description
credentials defines a key of a Secret in the namespace that contains the credentials for authentication.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].basicAuth

Description

basicAuth defines the Basic Authentication credentials used by the client.

Cannot be set at the same time as authorization, bearerTokenSecret or oauth2.

Type
`object`
Property Type Description
password object password defines a key of a Secret containing the password for authentication.
username object username defines a key of a Secret containing the username for authentication.

.spec.endpoints[].basicAuth.password

Description
password defines a key of a Secret containing the password for authentication.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].basicAuth.username

Description
username defines a key of a Secret containing the username for authentication.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].bearerTokenSecret

Description

bearerTokenSecret defines a key of a Secret containing the bearer token used by the client for authentication. The secret needs to be in the same namespace as the custom resource and readable by the Prometheus Operator.

Cannot be set at the same time as authorization, basicAuth or oauth2.

Deprecated: use authorization instead.

Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].metricRelabelings

Description
metricRelabelings defines the relabeling rules to apply to the samples before ingestion.
Type
`array`

.spec.endpoints[].metricRelabelings[]

Description

RelabelConfig allows dynamic rewriting of the label set for targets, alerts, scraped samples and remote write samples.

More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config

Type
`object`
Property Type Description
action string action to perform based on the regex matching.
Uppercase and Lowercase actions require Prometheus >= v2.36.0. DropEqual and KeepEqual actions require Prometheus >= v2.41.0.
Default: "Replace"
modulus integer modulus to take of the hash of the source label values.
Only applicable when the action is HashMod.
regex string regex defines the regular expression against which the extracted value is matched.
replacement string replacement value against which a Replace action is performed if the regular expression matches.
Regex capture groups are available.
separator string separator defines the string between concatenated SourceLabels.
sourceLabels array (string) sourceLabels defines the source labels select values from existing labels. Their content is concatenated using the configured Separator and matched against the configured regular expression.
targetLabel string targetLabel defines the label to which the resulting string is written in a replacement.
It is mandatory for Replace, HashMod, Lowercase, Uppercase, KeepEqual and DropEqual actions.
Regex capture groups are available.

.spec.endpoints[].oauth2

Description

oauth2 defines the OAuth2 settings used by the client.

It requires Prometheus >= 2.27.0.

Cannot be set at the same time as authorization, basicAuth or bearerTokenSecret.

Type
`object`
Required
  • clientId
  • clientSecret
  • tokenUrl
Property Type Description
clientId object clientId defines a key of a Secret or ConfigMap containing the OAuth2 client’s ID.
clientSecret object clientSecret defines a key of a Secret containing the OAuth2 client’s secret.
endpointParams object (string) endpointParams configures the HTTP parameters to append to the token URL.
noProxy string noProxy defines a comma-separated string that can contain IPs, CIDR notation, domain names that should be excluded from proxying. IP and domain names can contain port numbers.
It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyConnectHeader object proxyConnectHeader optionally specifies headers to send to proxies during CONNECT requests.
It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyConnectHeader{} array
proxyConnectHeader{}[] object SecretKeySelector selects a key of a Secret.
proxyFromEnvironment boolean proxyFromEnvironment defines whether to use the proxy configuration defined by environment variables (HTTP_PROXY, HTTPS_PROXY, and NO_PROXY).
It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.
proxyUrl string proxyUrl defines the HTTP proxy server to use.
scopes array (string) scopes defines the OAuth2 scopes used for the token request.
tlsConfig object tlsConfig defines the TLS configuration to use when connecting to the OAuth2 server. It requires Prometheus >= v2.43.0.
tokenUrl string tokenUrl defines the URL to fetch the token from.

.spec.endpoints[].oauth2.clientId

Description
clientId defines a key of a Secret or ConfigMap containing the OAuth2 client’s ID.
Type
`object`
Property Type Description
configMap object configMap defines the ConfigMap containing data to use for the targets.
secret object secret defines the Secret containing data to use for the targets.

.spec.endpoints[].oauth2.clientId.configMap

Description
configMap defines the ConfigMap containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key to select.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the ConfigMap or its key must be defined

.spec.endpoints[].oauth2.clientId.secret

Description
secret defines the Secret containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].oauth2.clientSecret

Description
clientSecret defines a key of a Secret containing the OAuth2 client’s secret.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].oauth2.proxyConnectHeader

Description

proxyConnectHeader optionally specifies headers to send to proxies during CONNECT requests.

It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.

Type
`object`

.spec.endpoints[].oauth2.proxyConnectHeader{}

Description

Type
`array`

.spec.endpoints[].oauth2.proxyConnectHeader{}[]

Description
SecretKeySelector selects a key of a Secret.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].oauth2.tlsConfig

Description
tlsConfig defines the TLS configuration to use when connecting to the OAuth2 server. It requires Prometheus >= v2.43.0.
Type
`object`
Property Type Description
ca object ca defines the Certificate authority used when verifying server certificates.
cert object cert defines the Client certificate to present when doing client-authentication.
insecureSkipVerify boolean insecureSkipVerify defines how to disable target certificate validation.
keySecret object keySecret defines the Secret containing the client key file for the targets.
maxVersion string maxVersion defines the maximum acceptable TLS version.
It requires Prometheus >= v2.41.0 or Thanos >= v0.31.0.
minVersion string minVersion defines the minimum acceptable TLS version.
It requires Prometheus >= v2.35.0 or Thanos >= v0.28.0.
serverName string serverName is used to verify the hostname for the targets.

.spec.endpoints[].oauth2.tlsConfig.ca

Description
ca defines the Certificate authority used when verifying server certificates.
Type
`object`
Property Type Description
configMap object configMap defines the ConfigMap containing data to use for the targets.
secret object secret defines the Secret containing data to use for the targets.

.spec.endpoints[].oauth2.tlsConfig.ca.configMap

Description
configMap defines the ConfigMap containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key to select.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the ConfigMap or its key must be defined

.spec.endpoints[].oauth2.tlsConfig.ca.secret

Description
secret defines the Secret containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].oauth2.tlsConfig.cert

Description
cert defines the Client certificate to present when doing client-authentication.
Type
`object`
Property Type Description
configMap object configMap defines the ConfigMap containing data to use for the targets.
secret object secret defines the Secret containing data to use for the targets.

.spec.endpoints[].oauth2.tlsConfig.cert.configMap

Description
configMap defines the ConfigMap containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key to select.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the ConfigMap or its key must be defined

.spec.endpoints[].oauth2.tlsConfig.cert.secret

Description
secret defines the Secret containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].oauth2.tlsConfig.keySecret

Description
keySecret defines the Secret containing the client key file for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].params

Description
params define optional HTTP URL parameters.
Type
`object`

.spec.endpoints[].proxyConnectHeader

Description

proxyConnectHeader optionally specifies headers to send to proxies during CONNECT requests.

It requires Prometheus >= v2.43.0, Alertmanager >= v0.25.0 or Thanos >= v0.32.0.

Type
`object`

.spec.endpoints[].proxyConnectHeader{}

Description

Type
`array`

.spec.endpoints[].proxyConnectHeader{}[]

Description
SecretKeySelector selects a key of a Secret.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].relabelings

Description

relabelings defines the relabeling rules to apply the target’s metadata labels.

The Operator automatically adds relabelings for a few standard Kubernetes fields.

The original scrape job’s name is available via the \__tmp_prometheus_job_name label.

More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config

Type
`array`

.spec.endpoints[].relabelings[]

Description

RelabelConfig allows dynamic rewriting of the label set for targets, alerts, scraped samples and remote write samples.

More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config

Type
`object`
Property Type Description
action string action to perform based on the regex matching.
Uppercase and Lowercase actions require Prometheus >= v2.36.0. DropEqual and KeepEqual actions require Prometheus >= v2.41.0.
Default: "Replace"
modulus integer modulus to take of the hash of the source label values.
Only applicable when the action is HashMod.
regex string regex defines the regular expression against which the extracted value is matched.
replacement string replacement value against which a Replace action is performed if the regular expression matches.
Regex capture groups are available.
separator string separator defines the string between concatenated SourceLabels.
sourceLabels array (string) sourceLabels defines the source labels select values from existing labels. Their content is concatenated using the configured Separator and matched against the configured regular expression.
targetLabel string targetLabel defines the label to which the resulting string is written in a replacement.
It is mandatory for Replace, HashMod, Lowercase, Uppercase, KeepEqual and DropEqual actions.
Regex capture groups are available.

.spec.endpoints[].tlsConfig

Description
tlsConfig defines TLS configuration used by the client.
Type
`object`
Property Type Description
ca object ca defines the Certificate authority used when verifying server certificates.
caFile string caFile defines the path to the CA cert in the Prometheus container to use for the targets.
cert object cert defines the Client certificate to present when doing client-authentication.
certFile string certFile defines the path to the client cert file in the Prometheus container for the targets.
insecureSkipVerify boolean insecureSkipVerify defines how to disable target certificate validation.
keyFile string keyFile defines the path to the client key file in the Prometheus container for the targets.
keySecret object keySecret defines the Secret containing the client key file for the targets.
maxVersion string maxVersion defines the maximum acceptable TLS version.
It requires Prometheus >= v2.41.0 or Thanos >= v0.31.0.
minVersion string minVersion defines the minimum acceptable TLS version.
It requires Prometheus >= v2.35.0 or Thanos >= v0.28.0.
serverName string serverName is used to verify the hostname for the targets.

.spec.endpoints[].tlsConfig.ca

Description
ca defines the Certificate authority used when verifying server certificates.
Type
`object`
Property Type Description
configMap object configMap defines the ConfigMap containing data to use for the targets.
secret object secret defines the Secret containing data to use for the targets.

.spec.endpoints[].tlsConfig.ca.configMap

Description
configMap defines the ConfigMap containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key to select.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the ConfigMap or its key must be defined

.spec.endpoints[].tlsConfig.ca.secret

Description
secret defines the Secret containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].tlsConfig.cert

Description
cert defines the Client certificate to present when doing client-authentication.
Type
`object`
Property Type Description
configMap object configMap defines the ConfigMap containing data to use for the targets.
secret object secret defines the Secret containing data to use for the targets.

.spec.endpoints[].tlsConfig.cert.configMap

Description
configMap defines the ConfigMap containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key to select.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the ConfigMap or its key must be defined

.spec.endpoints[].tlsConfig.cert.secret

Description
secret defines the Secret containing data to use for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.endpoints[].tlsConfig.keySecret

Description
keySecret defines the Secret containing the client key file for the targets.
Type
`object`
Required
  • key
Property Type Description
key string The key of the secret to select from. Must be a valid secret key.
name string Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
optional boolean Specify whether the Secret or its key must be defined

.spec.namespaceSelector

Description
namespaceSelector defines in which namespace(s) Prometheus should discover the services. By default, the services are discovered in the same namespace as the ServiceMonitor object but it is possible to select pods across different/all namespaces.
Type
`object`
Property Type Description
any boolean any defines the boolean describing whether all namespaces are selected in contrast to a list restricting them.
matchNames array (string) matchNames defines the list of namespace names to select from.

.spec.selector

Description
selector defines the label selector to select the Kubernetes Endpoints objects to scrape metrics from.
Type
`object`
Property Type Description
matchExpressions array matchExpressions is a list of label selector requirements. The requirements are ANDed.
matchExpressions[] object A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
matchLabels object (string) matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

.spec.selector.matchExpressions

Description
matchExpressions is a list of label selector requirements. The requirements are ANDed.
Type
`array`

.spec.selector.matchExpressions[]

Description
A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
Type
`object`
Required
  • key
  • operator
Property Type Description
key string key is the label key that the selector applies to.
operator string operator represents a key’s relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
values array (string) values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.

.status

Description

status defines the status subresource. It is under active development and is updated only when the "StatusForConfigurationResources" feature gate is enabled.

Most recent observed status of the ServiceMonitor. Read-only. More info: https://github.com/kubernetes/community/blob/master/contributors/devel/sig-architecture/api-conventions.md#spec-and-status

Type
`object`
Property Type Description
bindings array bindings defines the list of workload resources (Prometheus, PrometheusAgent, ThanosRuler or Alertmanager) which select the configuration resource.
bindings[] object WorkloadBinding is a link between a configuration resource and a workload resource.

.status.bindings

Description
bindings defines the list of workload resources (Prometheus, PrometheusAgent, ThanosRuler or Alertmanager) which select the configuration resource.
Type
`array`

.status.bindings[]

Description
WorkloadBinding is a link between a configuration resource and a workload resource.
Type
`object`
Required
  • group
  • name
  • namespace
  • resource
Property Type Description
conditions array conditions defines the current state of the configuration resource when bound to the referenced Workload object.
conditions[] object ConfigResourceCondition describes the status of configuration resources linked to Prometheus, PrometheusAgent, Alertmanager or ThanosRuler.
group string group defines the group of the referenced resource.
name string name defines the name of the referenced object.
namespace string namespace defines the namespace of the referenced object.
resource string resource defines the type of resource being referenced (e.g. Prometheus, PrometheusAgent, ThanosRuler or Alertmanager).

.status.bindings[].conditions

Description
conditions defines the current state of the configuration resource when bound to the referenced Workload object.
Type
`array`

.status.bindings[].conditions[]

Description
ConfigResourceCondition describes the status of configuration resources linked to Prometheus, PrometheusAgent, Alertmanager or ThanosRuler.
Type
`object`
Required
  • lastTransitionTime
  • status
  • type
Property Type Description
lastTransitionTime string lastTransitionTime defines the time of the last update to the current status property.
message string message defines the human-readable message indicating details for the condition’s last transition.
observedGeneration integer observedGeneration defines the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[].observedGeneration is 9, the condition is out of date with respect to the current state of the object.
reason string reason for the condition’s last transition.
status string status of the condition.
type string type of the condition being reported. Currently, only "Accepted" is supported.

API endpoints

The following API endpoints are available:

  • /apis/monitoring.coreos.com/v1/servicemonitors

    • GET: list objects of kind ServiceMonitor
  • /apis/monitoring.coreos.com/v1/namespaces/{namespace}/servicemonitors

    • DELETE: delete collection of ServiceMonitor
    • GET: list objects of kind ServiceMonitor
    • POST: create a ServiceMonitor
  • /apis/monitoring.coreos.com/v1/namespaces/{namespace}/servicemonitors/{name}

    • DELETE: delete a ServiceMonitor
    • GET: read the specified ServiceMonitor
    • PATCH: partially update the specified ServiceMonitor
    • PUT: replace the specified ServiceMonitor
  • /apis/monitoring.coreos.com/v1/namespaces/{namespace}/servicemonitors/{name}/status

    • GET: read status of the specified ServiceMonitor
    • PATCH: partially update status of the specified ServiceMonitor
    • PUT: replace status of the specified ServiceMonitor

/apis/monitoring.coreos.com/v1/servicemonitors

HTTP method
`GET`
Description
list objects of kind ServiceMonitor

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitorList schema
401 - Unauthorized Empty

/apis/monitoring.coreos.com/v1/namespaces/{namespace}/servicemonitors

HTTP method
`DELETE`
Description
delete collection of ServiceMonitor

HTTP responses

HTTP code Reponse body
200 - OK Status schema
401 - Unauthorized Empty
HTTP method
`GET`
Description
list objects of kind ServiceMonitor

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitorList schema
401 - Unauthorized Empty
HTTP method
`POST`
Description
create a ServiceMonitor

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

Body parameters

Parameter Type Description
body ServiceMonitor schema

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
201 - Created ServiceMonitor schema
202 - Accepted ServiceMonitor schema
401 - Unauthorized Empty

/apis/monitoring.coreos.com/v1/namespaces/{namespace}/servicemonitors/{name}

Global path parameters

Parameter Type Description
name string name of the ServiceMonitor
HTTP method
`DELETE`
Description
delete a ServiceMonitor

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed

HTTP responses

HTTP code Reponse body
200 - OK Status schema
202 - Accepted Status schema
401 - Unauthorized Empty
HTTP method
`GET`
Description
read the specified ServiceMonitor

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
401 - Unauthorized Empty
HTTP method
`PATCH`
Description
partially update the specified ServiceMonitor

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
401 - Unauthorized Empty
HTTP method
`PUT`
Description
replace the specified ServiceMonitor

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

Body parameters

Parameter Type Description
body ServiceMonitor schema

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
201 - Created ServiceMonitor schema
401 - Unauthorized Empty

/apis/monitoring.coreos.com/v1/namespaces/{namespace}/servicemonitors/{name}/status

Global path parameters

Parameter Type Description
name string name of the ServiceMonitor
HTTP method
`GET`
Description
read status of the specified ServiceMonitor

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
401 - Unauthorized Empty
HTTP method
`PATCH`
Description
partially update status of the specified ServiceMonitor

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
401 - Unauthorized Empty
HTTP method
`PUT`
Description
replace status of the specified ServiceMonitor

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

Body parameters

Parameter Type Description
body ServiceMonitor schema

HTTP responses

HTTP code Reponse body
200 - OK ServiceMonitor schema
201 - Created ServiceMonitor schema
401 - Unauthorized Empty