为 VictoriaMetrics 搭建跨区域双写与查询切换

监测系统需要在一个区域不可用时继续查询指标、显示仪表盘并触发告警。VictoriaMetrics 的这份跨区域专用监测指南把业务工作负载与监测存储分开:每个业务区域运行本地 vmagent,向两个专用监测区域发送同一份指标。这样可以形成两份逻辑上的完整副本,并对外提供统一的查询入口。

代价也很直接:相同数据需要发送和保存两次,存储、计算和跨区域传输成本都会增加。本文按原文完整说明配置思路;文中的主机名与路径均为示例,安全边界和实际部署前提单独标出,没有执行服务或故障演练。

业务区域的vmagent双写两个监测区域;查询可选择vmauth单区路由或顶层vmselect合并;告警经Alertmanager去重。
原创示意图:两个监测区域各保存一份指标;下方展示可选的读取方式,不表示必须同时部署两种全局入口。

把业务区域与监测区域分开

原文使用 Earth、Mars、Venus 表示三个业务区域;它们可以对应应用或基础设施所在的不同机房或云区域。另有 Ground Control 1 和 Ground Control 2 两个专用监测区域,各自运行一套 VictoriaMetrics。业务区域的 vmagent 把相同样本发往两个 Ground Control。

Ground Control 可以使用 VictoriaMetrics 单节点,也可以使用集群模式。这里的“两个副本”指跨监测区域的两套数据,不等于已经定义了每个区域内部的节点数量、磁盘冗余或复制策略。选择架构时,仍需分别考虑区域内和区域间的故障。

向两个监测区域写入

在每个业务区域运行一个或多个 vmagent,为每个目的地重复指定 -remoteWrite.url。写入单节点实例的原文配置如下:

/path/to/vmagent-prod \
  -remoteWrite.url=https://ground-control-1:8428/api/v1/write \
  -remoteWrite.url=https://ground-control-2:8428/api/v1/write

集群模式应指向各区域的 vminsert。下面使用租户 accountID=0,路径中的租户号需要与实际部署一致:

/path/to/vmagent-prod \
  -remoteWrite.url=https://ground-control-1-vminsert:8480/insert/0/prometheus/api/v1/write \
  -remoteWrite.url=https://ground-control-2-vminsert:8480/insert/0/prometheus/api/v1/write

vmagent 为每个 -remoteWrite.url 维护独立的持久队列。某个区域暂时不可用时,另一目的地仍可继续接收数据;发送失败的样本保存在该目标的文件队列中,待区域恢复后重新投递。这能帮助两边重新达到一致,但队列受可用磁盘空间约束。

编者补充:“持久队列”需要真正可持久化的存储。容器重建时丢失的临时目录不能提供相同保障;队列容量、磁盘余量、发送错误和积压量都应监测。队列超过容量、采集端整体故障或根本未采到的样本,不会因为配置两个写入 URL 自动恢复。上面两段命令只展示目的地,不包含指标抓取配置、TLS 材料或身份验证。可继续参照官方 vmagent 文档和项目提供的告警规则与仪表盘来配置采集和队列监测。

选择读取方式:一次查询读一个区域,还是合并多个区域

两种方案都可以给仪表盘提供稳定入口,但行为不同。负载均衡器将每次请求转发给某个可用区域,适合控制复杂度和查询开销;顶层 vmselect 向两个区域发出查询并合并结果,适合需要跨区域合并数据的情况。原文还指向 VictoriaMetrics 拓扑指南,帮助结合运维复杂度选择方案。

方案一:用 vmauth 选择一个可用区域

把 vmauth 放在两套 Ground Control 前面,仪表盘只连接它提供的一个 URL。单节点部署的示例:

unauthorized_user:
  url_prefix:
    - "http://ground-control-1:8428"
    - "http://ground-control-2:8428"
  load_balancing_policy: first_available

对于 VictoriaMetrics 集群,后端 URL 应指向各区域的 vmselect,而不是写入节点:

unauthorized_user:
  url_prefix:
    - "http://ground-control-1-vmselect:8481"
    - "http://ground-control-2-vmselect:8481"
  load_balancing_policy: first_available

first_available 按配置的可用后端策略路由,优先区域失效时可切到另一区域。每次只向一个区域查询,避免了跨区域合并开销。原文把它描述为相较“两边读取再合并”通常更快,并给出延迟大约减半的说法;这不是普适保证,更不是本文测试结果,实际耗时取决于网络、查询、数据量和后端负载。

更重要的限制是:vmauth 不知道恢复的区域是否已完成 vmagent 队列回放。刚恢复就把请求送回去,近期数据可能仍不完整。健康检查证明服务可达,并不能证明它已经追平。原文建议等待恢复区域补齐积压后,再恢复该区域的读取流量。

原例是无认证示例。unauthorized_user 允许未经身份验证的请求,且后端使用 HTTP。不能把这段 YAML 直接当作公开网关配置;对外提供服务时,需要配置适当的认证、TLS 和网络访问控制。官方 vmauth 文档说明了相应认证方式。

以配置文件启动 vmauth:

/path/to/vmauth-prod -auth.config=/path/to/auth.yaml

原文给出两种查询检查命令。它们只是待在目标环境验证的例子,本文未执行验证:

# single node
curl http://vmauth-node:8427/api/v1/query?query=up

# cluster
curl http://vmauth-node:8427/select/0/prometheus/api/v1/query?query=up

使用 shell 时可给完整 URL 加引号,避免特殊字符被 shell 解释;实际访问还应通过已经设置好认证和 TLS 的入口。Kubernetes 用户可进一步参考官方 VMDistributed 资源示例。这个方案每次读取一个区域,不会自动拿另一区域的数据来填补查询结果中的缺口。

方案二:用顶层 vmselect 合并结果

该方案要求 Ground Control 使用 VictoriaMetrics 集群,或启用了多租户支持的单节点实例。单节点需要通过 -vmselectAddr=:8401 启用相应的 vmselect RPC 服务。

集群方式下,每个区域有本地 vmselect。顶层 vmselect 连接这些区域查询节点,而不是直接访问区域内的 vmstorage。当存储节点不适合被上层直接访问时,这种分层很有用,例如 Kubernetes 中的存储服务默认不提供 HTTP 查询端点。

区域 vmselect 使用 -clusternativeListenAddr 接收上层请求;顶层使用 -storageNode 指向区域节点,并配置去重间隔。原例完整展示如下:

# Ground Control 1 cluster vmselect
/path/to/vmselect-prod \
  -storageNode=ground-control-1-vmstorage-1:8401,ground-control-1-vmstorage-2:8401 \
  -clusternativeListenAddr=:8401

# Ground Control 2 cluster vmselect
/path/to/vmselect-prod \
  -storageNode=ground-control-2-vmstorage-1:8401,ground-control-2-vmstorage-2:8401 \
  -clusternativeListenAddr=:8401

# Top-level vmselect
/path/to/vmselect-prod \
  -storageNode=ground-control-1-vmselect:8401,ground-control-2-vmselect:8401 \
  -dedup.minScrapeInterval=1ms \
  -replicationFactor=2

顶层对两个区域提供统一查询入口。一个区域不可用时,它仍能查询健康区域;恢复期间,也可以合并两边的数据。跨两个查询层的代价是额外的请求与合并开销,因此通常比直接查询某个区域或通过负载均衡择一读取更慢。

编者补充:原例的 -dedup.minScrapeInterval=1ms 与 -replicationFactor=2 必须结合“两个区域保存相同数据”的前提理解,不能脱离实际拓扑照抄。需要核对抓取间隔、标签一致性、每个区域的完整性、目标版本的去重和复制语义,并限制原生 RPC 端口的可达范围。它们不会自动解决缺失采集数据,也不替代区域内部的存储可靠性设计。

在每个区域独立求值,再对告警去重

在每个 Ground Control 区域部署 vmalert,让它查询本区域的 VictoriaMetrics。因为两边保存同样的指标,可以部署相同的告警规则和记录规则,使一个区域失效时另一个区域继续求值。把告警发送给 Alertmanager 集群,由它处理重复告警。

单节点模式的例子:

/path/to/vmalert \
  -rule=/path/to/rules.yaml \
  -datasource.url=http://ground-control-1:8428 \
  -notifier.url=http://alertmanager-1:9093 \
  -notifier.url=http://alertmanager-2:9093

集群模式中,-datasource.url 指向本地 vmselect 的租户查询端点:

/path/to/vmalert \
  -rule=/path/to/rules.yaml \
  -datasource.url=http://ground-control-1-vmselect:8481/select/0/prometheus \
  -notifier.url=http://alertmanager-1:9093,http://alertmanager-2:9093

若要在重启后保留告警状态和记录规则结果,还需配置 -remoteWrite.url 和 -remoteRead.url。集群示例如下:

/path/to/vmalert \
  -rule=/path/to/rules.yaml \
  -datasource.url=http://ground-control-1-vmselect:8481/select/0/prometheus \
  -remoteRead.url=http://ground-control-1-vmselect:8481/select/0/prometheus \
  -remoteWrite.url=http://ground-control-1-vminsert:8480/insert/0/prometheus \
  -notifier.url=http://alertmanager-1:9093,http://alertmanager-2:9093

原文推荐参考 VictoriaMetrics 提供的告警规则。需要注意,“各区域使用相同数据”不等于规则文件会自动同步。部署工具仍要保证 rules.yaml 和求值相关配置的版本一致。Alertmanager 的网络可达性、集群状态及用于去重的标签也必须一致核查;把告警简单发送到两个地址,不是全部高可用工作。

监测系统也要被监测

每个 Ground Control 区域可以使用独立的监测路径抓取自身 VictoriaMetrics 各组件的指标。还可以把这些自监测指标复制给相邻区域:即使整个 Ground Control 区域掉线,仍能从另一边查看它故障前的遥测,帮助定位问题和恢复服务。

单节点与集群的自身监测项不完全相同,应分别参考官方部署监测文档。这里保留原文的核心原则:不要让监测系统自身的故障同时切断唯一的诊断证据。

在存储区域前再增加一层接收代理

还可以在每个 Ground Control 部署额外的 vmagent,作为区域内的指标接收代理。这样写入入口离存储更近,存储暂时不可用时还能多一层磁盘缓冲。它也适合在本地做重新标记,并区分跨区域流量和区域内写入。

面向 Ground Control 1 的单节点写入端点:

# vmagent next to Ground Control 1
/path/to/vmagent-prod \
  -remoteWrite.url=http://ground-control-1:8428/api/v1/write

集群模式则使用该区域 vminsert 的写入路径:

# vmagent next to Ground Control 1 for cluster mode
/path/to/vmagent-prod \
  -remoteWrite.url=http://ground-control-1-vminsert:8480/insert/0/prometheus/api/v1/write

这些命令展示的是代理的输出端;业务区域的发送端还需要改为指向代理实际配置的接收入口,并为代理设置接收、认证、队列和监测。增加缓冲层会增加需要管理的状态,不能只计算正常路径。

静态审查与部署边界

本稿完整核对了源文的 12 段配置和命令,没有发现实际写入的私密凭证,但这不表示它们构成完整安全配置。所有跨区域地址、证书、鉴权、持久磁盘容量及恢复读流量的条件都需要按环境确定;未认证的 vmauth、HTTP 后端和原生查询 RPC 端口尤其不能直接暴露给不可信网络。

跨区域双写还涉及网络费用和数据驻留,应在选区前明确要求。本文未进行开通资源、写入指标、切断区域、发送告警或测量性能;两份数据、可达的端点和同步的规则是三项不同的条件,应分别验证。

来源、作者与许可

原文为 VictoriaMetrics Multi-Regional Setup: Dedicated Monitoring。原作者/维护者:VictoriaMetrics 文档贡献者。核对日期:2026-10-05。技术审读与示意图:未完纪编辑整理。原文未标个人作者时,不补造个人署名。

本稿保留 VictoriaMetrics 归属及其项目 Apache License 2.0 许可正文。修改内容为中文翻译、段落整理与明确标记的静态审查补充;不暗示上游对部署或配图背书。

随文保留的原始许可证全文
 Apache License
                           Version 2.0, January 2004
                        http://www.apache.org/licenses/

   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION

   1. Definitions.

      "License" shall mean the terms and conditions for use, reproduction,
      and distribution as defined by Sections 1 through 9 of this document.

      "Licensor" shall mean the copyright owner or entity authorized by
      the copyright owner that is granting the License.

      "Legal Entity" shall mean the union of the acting entity and all
      other entities that control, are controlled by, or are under common
      control with that entity. For the purposes of this definition,
      "control" means (i) the power, direct or indirect, to cause the
      direction or management of such entity, whether by contract or
      otherwise, or (ii) ownership of fifty percent (50%) or more of the
      outstanding shares, or (iii) beneficial ownership of such entity.

      "You" (or "Your") shall mean an individual or Legal Entity
      exercising permissions granted by this License.

      "Source" form shall mean the preferred form for making modifications,
      including but not limited to software source code, documentation
      source, and configuration files.

      "Object" form shall mean any form resulting from mechanical
      transformation or translation of a Source form, including but
      not limited to compiled object code, generated documentation,
      and conversions to other media types.

      "Work" shall mean the work of authorship, whether in Source or
      Object form, made available under the License, as indicated by a
      copyright notice that is included in or attached to the work
      (an example is provided in the Appendix below).

      "Derivative Works" shall mean any work, whether in Source or Object
      form, that is based on (or derived from) the Work and for which the
      editorial revisions, annotations, elaborations, or other modifications
      represent, as a whole, an original work of authorship. For the purposes
      of this License, Derivative Works shall not include works that remain
      separable from, or merely link (or bind by name) to the interfaces of,
      the Work and Derivative Works thereof.

      "Contribution" shall mean any work of authorship, including
      the original version of the Work and any modifications or additions
      to that Work or Derivative Works thereof, that is intentionally
      submitted to Licensor for inclusion in the Work by the copyright owner
      or by an individual or Legal Entity authorized to submit on behalf of
      the copyright owner. For the purposes of this definition, "submitted"
      means any form of electronic, verbal, or written communication sent
      to the Licensor or its representatives, including but not limited to
      communication on electronic mailing lists, source code control systems,
      and issue tracking systems that are managed by, or on behalf of, the
      Licensor for the purpose of discussing and improving the Work, but
      excluding communication that is conspicuously marked or otherwise
      designated in writing by the copyright owner as "Not a Contribution."

      "Contributor" shall mean Licensor and any individual or Legal Entity
      on behalf of whom a Contribution has been received by Licensor and
      subsequently incorporated within the Work.

   2. Grant of Copyright License. Subject to the terms and conditions of
      this License, each Contributor hereby grants to You a perpetual,
      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
      copyright license to reproduce, prepare Derivative Works of,
      publicly display, publicly perform, sublicense, and distribute the
      Work and such Derivative Works in Source or Object form.

   3. Grant of Patent License. Subject to the terms and conditions of
      this License, each Contributor hereby grants to You a perpetual,
      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
      (except as stated in this section) patent license to make, have made,
      use, offer to sell, sell, import, and otherwise transfer the Work,
      where such license applies only to those patent claims licensable
      by such Contributor that are necessarily infringed by their
      Contribution(s) alone or by combination of their Contribution(s)
      with the Work to which such Contribution(s) was submitted. If You
      institute patent litigation against any entity (including a
      cross-claim or counterclaim in a lawsuit) alleging that the Work
      or a Contribution incorporated within the Work constitutes direct
      or contributory patent infringement, then any patent licenses
      granted to You under this License for that Work shall terminate
      as of the date such litigation is filed.

   4. Redistribution. You may reproduce and distribute copies of the
      Work or Derivative Works thereof in any medium, with or without
      modifications, and in Source or Object form, provided that You
      meet the following conditions:

      (a) You must give any other recipients of the Work or
          Derivative Works a copy of this License; and

      (b) You must cause any modified files to carry prominent notices
          stating that You changed the files; and

      (c) You must retain, in the Source form of any Derivative Works
          that You distribute, all copyright, patent, trademark, and
          attribution notices from the Source form of the Work,
          excluding those notices that do not pertain to any part of
          the Derivative Works; and

      (d) If the Work includes a "NOTICE" text file as part of its
          distribution, then any Derivative Works that You distribute must
          include a readable copy of the attribution notices contained
          within such NOTICE file, excluding those notices that do not
          pertain to any part of the Derivative Works, in at least one
          of the following places: within a NOTICE text file distributed
          as part of the Derivative Works; within the Source form or
          documentation, if provided along with the Derivative Works; or,
          within a display generated by the Derivative Works, if and
          wherever such third-party notices normally appear. The contents
          of the NOTICE file are for informational purposes only and
          do not modify the License. You may add Your own attribution
          notices within Derivative Works that You distribute, alongside
          or as an addendum to the NOTICE text from the Work, provided
          that such additional attribution notices cannot be construed
          as modifying the License.

      You may add Your own copyright statement to Your modifications and
      may provide additional or different license terms and conditions
      for use, reproduction, or distribution of Your modifications, or
      for any such Derivative Works as a whole, provided Your use,
      reproduction, and distribution of the Work otherwise complies with
      the conditions stated in this License.

   5. Submission of Contributions. Unless You explicitly state otherwise,
      any Contribution intentionally submitted for inclusion in the Work
      by You to the Licensor shall be under the terms and conditions of
      this License, without any additional terms or conditions.
      Notwithstanding the above, nothing herein shall supersede or modify
      the terms of any separate license agreement you may have executed
      with Licensor regarding such Contributions.

   6. Trademarks. This License does not grant permission to use the trade
      names, trademarks, service marks, or product names of the Licensor,
      except as required for reasonable and customary use in describing the
      origin of the Work and reproducing the content of the NOTICE file.

   7. Disclaimer of Warranty. Unless required by applicable law or
      agreed to in writing, Licensor provides the Work (and each
      Contributor provides its Contributions) on an "AS IS" BASIS,
      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
      implied, including, without limitation, any warranties or conditions
      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
      PARTICULAR PURPOSE. You are solely responsible for determining the
      appropriateness of using or redistributing the Work and assume any
      risks associated with Your exercise of permissions under this License.

   8. Limitation of Liability. In no event and under no legal theory,
      whether in tort (including negligence), contract, or otherwise,
      unless required by applicable law (such as deliberate and grossly
      negligent acts) or agreed to in writing, shall any Contributor be
      liable to You for damages, including any direct, indirect, special,
      incidental, or consequential damages of any character arising as a
      result of this License or out of the use or inability to use the
      Work (including but not limited to damages for loss of goodwill,
      work stoppage, computer failure or malfunction, or any and all
      other commercial damages or losses), even if such Contributor
      has been advised of the possibility of such damages.

   9. Accepting Warranty or Additional Liability. While redistributing
      the Work or Derivative Works thereof, You may choose to offer,
      and charge a fee for, acceptance of support, warranty, indemnity,
      or other liability obligations and/or rights consistent with this
      License. However, in accepting such obligations, You may act only
      on Your own behalf and on Your sole responsibility, not on behalf
      of any other Contributor, and only if You agree to indemnify,
      defend, and hold each Contributor harmless for any liability
      incurred by, or claims asserted against, such Contributor by reason
      of your accepting any such warranty or additional liability.

   END OF TERMS AND CONDITIONS

   Copyright 2019-2026 VictoriaMetrics, Inc.

   Licensed under the Apache License, Version 2.0 (the "License");
   you may not use this file except in compliance with the License.
   You may obtain a copy of the License at

       http://www.apache.org/licenses/LICENSE-2.0

   Unless required by applicable law or agreed to in writing, software
   distributed under the License is distributed on an "AS IS" BASIS,
   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
   See the License for the specific language governing permissions and
   limitations under the License.
© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容