Prometheus Pushgateway
Prometheus Pushgateway Source
The Prometheus Pushgateway source enables the platform to receive metrics pushed by Prometheus clients using the Pushgateway model. This source exposes an HTTP endpoint that accepts metrics in Prometheus exposition format and converts them into internal metric events.
It is primarily used for short-lived jobs, batch workloads, and sidecar-based deployments where pull-based scraping is not feasible. The source operates in stateless mode and supports at-least-once delivery semantics, with acknowledgements managed globally or at the sink level.
Connection Settings
address (required, string)
Defines the socket address on which the Pushgateway endpoint listens for incoming metric pushes.
- Must include a valid port number.
- Determines network accessibility of the source.
Operational note: Binding to all interfaces allows external systems to push metrics. For restricted environments, bind to a specific interface or loopback address.
Metric Handling
aggregate_metrics (optional, bool)
Controls whether metric values received across multiple push requests are aggregated.
- Applies only to counters and histograms.
- Gauges and summaries are excluded, as they cannot be safely aggregated.
Default behavior: Disabled.
Operational note: Enable this option when multiple producers push incremental metrics that must be combined into a single logical time series. Disable it when each push represents an independent execution or job result.
Acknowledgement Settings (Deprecated)
acknowledgements (optional, object)
This configuration is deprecated and retained for backward compatibility.
- Source-level acknowledgement settings no longer influence delivery guarantees.
- Acknowledgements must be configured globally or at the sink level.
Important: Modifying acknowledgement options in this source has no functional effect.
Authentication
auth (optional, object)
Defines the authentication mechanism for incoming HTTP requests.
Authentication credentials are transmitted via HTTP headers and rely solely on transport-level encryption.
Security recommendation: Authentication should only be enabled when TLS is also enabled.
auth.strategy (required, string enum)
Specifies the authentication strategy.
Supported values:
- basic – Standard HTTP Basic Authentication.
- custom – Custom request validation implemented using VRL expressions.
Basic Authenticationauth.username (required, string)
Username used for client authentication.
auth.password (required, string)
Password associated with the authentication username.
Operational note: Basic authentication is suitable for controlled or internal environments but should not be exposed over unencrypted connections.
Custom Authenticationauth.source (required, string)
A VRL boolean expression used to validate incoming requests.
Operational note: This approach allows advanced access control based on headers, request metadata, or custom logic.
HTTP Keepalive Configuration
keepalive (optional, object)
Controls HTTP connection reuse and lifecycle behavior.
keepalive.max_connection_age_secs (optional, uint)
Defines the maximum lifetime of an HTTP connection before it is closed gracefully.
- A Connection: close header is sent when the limit is reached.
- Applies only to HTTP/0.9, HTTP/1.0, and HTTP/1.1.
Default: 300 seconds.
Operational note: Setting a large value effectively disables forced connection recycling.
keepalive.max_connection_age_jitter_factor (optional, float)
Adds random jitter to connection lifetime to prevent synchronized connection closures.
Default: 0.1
Operational note: Recommended for high-concurrency environments to avoid connection spikes.
TLS Configuration
tls (optional, object)
Configures TLS behavior for secure metric ingestion.
tls.enabled (optional, bool)
Enables TLS for incoming connections.
- When enabled, a valid server certificate must be configured.
tls.crt_file (optional, string)
Path to the server certificate used to identify this source.
Supported formats include PEM, DER, and PKCS#12.
tls.key_file (optional, string)
Path to the private key associated with the server certificate.
Required unless the certificate is provided as a PKCS#12 archive.
tls.key_pass (optional, string)
Passphrase for encrypted private key files.
tls.ca_file (optional, string)
Path to an additional trusted CA certificate.
Used to validate client certificates in mutual TLS deployments.
tls.alpn_protocols (optional, [string])
List of supported ALPN protocols, ordered by preference.
tls.verify_certificate (optional, bool)
Enforces certificate validation.
- Incoming connections must present valid certificates.
- Certificate chains are validated up to a trusted root.
Security warning: Disabling certificate verification significantly reduces transport security and is not recommended.
tls.verify_hostname (optional, bool)
Enables hostname verification for TLS connections.
Relevant only for outgoing connections.
tls.server_name (optional, string)
Specifies the server name used for Server Name Indication (SNI).
Relevant only for outgoing connections.