深色模式
Synthetic 拨测
摘要:RUM 是等用户来了才被动采集,拨测则是主动模拟用户去访问。它能覆盖"凌晨三点没人访问但服务已挂"这类盲区,也能做发布后的快速冒烟。本文给出四类拨测的配置方法与告警接入。
适用环境
bash
# 黑盒拨测工具(Prometheus 生态)
which blackbox_exporter || echo "需安装 blackbox_exporter"
# 命令行拨测(快速验证)
curl --version | head -1
# 浏览器拨测需 Node 环境
node --version1
2
3
4
5
6
7
8
2
3
4
5
6
7
8
操作步骤
1. 明确四类拨测
| 类型 | 适用场景 | 成本 |
|---|---|---|
| ICMP/TCP | 主机与端口存活 | 低 |
| HTTP | 单接口可用性与状态码 | 低 |
| 多步 API | 完整业务流程(登录->下单->支付) | 中 |
| 浏览器 | 真实渲染与前端交互 | 高 |
2. 部署 blackbox_exporter
bash
# 到 Releases 页核对版本后下载
VERSION=0.25.0
curl -LO https://github.com/prometheus/blackbox_exporter/releases/download/v${VERSION}/blackbox_exporter-${VERSION}.linux-amd64.tar.gz
tar xzf blackbox_exporter-${VERSION}.linux-amd64.tar.gz
sudo install -m 0755 blackbox_exporter-${VERSION}.linux-amd64/blackbox_exporter /usr/local/bin/1
2
3
4
5
2
3
4
5
3. 配置拨测模块
yaml
# /etc/blackbox_exporter/blackbox.yml
modules:
http_2xx:
prober: http
timeout: 5s
http:
valid_status_codes: [200]
method: GET
http_post_login:
prober: http
timeout: 10s
http:
method: POST
headers:
Content-Type: application/json
body: '{"username":"probe_user","password":"xxxx"}'
fail_if_body_not_matches_regexp:
- '"token":'1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
4. 让 Prometheus 触发拨测
yaml
scrape_configs:
- job_name: blackbox-http
metrics_path: /probe
params:
module: [http_2xx]
static_configs:
- targets:
- https://your-site.example.com/healthz
- https://your-site.example.com/api/order
relabel_configs:
- source_labels: [__address__]
target_label: __param_target
- source_labels: [__param_target]
target_label: instance
- target_label: __address__
replacement: 127.0.0.1:9115 # blackbox_exporter 地址1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
5. 配置告警
yaml
groups:
- name: synthetic
rules:
- alert: ProbeFailed
expr: probe_success == 0
for: 2m
labels: {severity: critical}
annotations: {summary: "拨测失败:{{ $labels.instance }}"}
- alert: ProbeSlow
expr: probe_duration_seconds > 1
for: 5m
labels: {severity: warning}
annotations: {summary: "响应超过 1s:{{ $labels.instance }}"}
- alert: SSLCertExpiring
expr: probe_ssl_earliest_cert_expiry - time() < 86400 * 14
labels: {severity: warning}
annotations: {summary: "证书 14 天内到期"}1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
6. 多步 API 拨测脚本(blackbox 不适用时自己写)
bash
cat > /usr/local/bin/probe_order_flow.sh <<'EOF'
#!/usr/bin/env bash
set -uo pipefail
BASE=https://your-site.example.com
TOKEN=$(curl -s -X POST "$BASE/api/login" -H 'Content-Type: application/json' \
-d '{"username":"probe_user","password":"'"$PROBE_PASS"'"}' \
| python3 -c 'import sys,json;print(json.load(sys.stdin).get("token",""))')
[ -z "$TOKEN" ] && echo "LOGIN FAILED" && exit 1
CODE=$(curl -s -o /dev/null -w '%{http_code}' -X POST "$BASE/api/order" \
-H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
-d '{"sku":"TEST-001","qty":1}')
echo "order_code=$CODE"
[ "$CODE" = "200" ] || exit 1
EOF
chmod +x /usr/local/bin/probe_order_flow.sh1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
2
3
4
5
6
7
8
9
10
11
12
13
14
15
7. 浏览器拨测(覆盖前端渲染与交互,可用 Playwright 脚本定时执行)
javascript
const { chromium } = require('playwright'); // npm install playwright
(async () => {
const browser = await chromium.launch();
const page = await browser.newPage();
const t0 = Date.now();
await page.goto('https://your-site.example.com', { waitUntil: 'networkidle' });
await page.click('#login');
await page.waitForSelector('.dashboard', { timeout: 10000 });
console.log('flow ok, ms =', Date.now() - t0);
await browser.close();
})();1
2
3
4
5
6
7
8
9
10
11
2
3
4
5
6
7
8
9
10
11
DANGER
拨测账号必须使用独立的只读/测试账号,且拨测产生的数据要能被识别并定期清理(如下单测试单)。不要用生产真实账号做拨测,避免污染业务数据与统计口径。
验证
bash
# 1) blackbox 本身可用
curl -s 'http://127.0.0.1:9115/probe?target=https://example.com&module=http_2xx' | grep probe_success
# 2) Prometheus 里能查到拨测结果
curl -s 'http://127.0.0.1:9090/api/v1/query' --data-urlencode 'query=probe_success' | head -c 300
# 3) 把目标改成不存在的路径,确认 probe_success 变 0 且告警触发
# 4) 拨测脚本返回码
/usr/local/bin/probe_order_flow.sh; echo "exit=$?"1
2
3
4
5
6
7
8
9
10
2
3
4
5
6
7
8
9
10
常见坑
WARNING
拨测点与被拨测对象在同一机房内,网络问题、DNS 问题、CDN 问题全都测不出来。请至少部署 2-3 个不同地域/运营商的拨测点。
WARNING
拨测频率过高(如每 5 秒一次)会被 WAF 或限流策略判定为攻击并封禁 IP。请设置合理间隔(30s-1min)并与安全团队确认白名单。
DANGER
拨测脚本里硬编码生产账号密码是重大安全隐患。请使用独立的测试账号,凭据从密钥管理系统注入,且脚本文件权限设为仅属主可读。