Enable data-plane monitoring for your service mesh so that gateways and sidecar proxies can generate operational status metrics. By collecting these metrics in Managed Service for Prometheus, you gain comprehensive observability across gateways, the entire mesh, services, and workloads. This allows you to identify potential issues and optimize your configuration.
Prerequisites
-
Managed Service for Prometheus is activated on your Alibaba Cloud account. For more information, see Activate ARMS.
-
The ack-arms-prometheus component is installed on the data-plane cluster. For more information, see Connect to and configure Alibaba Cloud Prometheus monitoring.
Procedure
For ASM instances earlier than v1.17.2.35
-
Log on to the ASM console. In the left-side navigation pane, choose .
-
On the Mesh Management page, click the name of the ASM instance. In the left-side navigation pane, choose .
-
On the Monitoring metrics page, select Use Managed Service for Prometheus to Collect Metrics, and then click Collect Metrics to Managed Service for Prometheus. In the Confirm dialog box, click OK.
After you enable metric collection, the Monitoring metrics page automatically switches to a dashboard view. Monitoring metrics provides multiple dashboards, such as Cloud ASM Istio Gateway Status, Cloud ASM Istio Http Gateway, and Cloud ASM Istio Mesh, that you can view as needed.
NoteIf you no longer need this feature, click Disable metrics generation and collection in the upper-right corner of the Monitoring metrics page. In the Confirm dialog box, click OK.
After you stop metric collection, the gateway and sidecar proxies continue to expose their last-collected metric values, which are not updated. To clear these stale metrics, restart the workloads. For more information, see Redeploy workloads.
For ASM instances v1.17.2.35 and later
-
Log on to the ASM console. In the left-side navigation pane, choose .
-
On the Mesh Management page, click the name of the ASM instance. In the left-side navigation pane, choose .
-
On the Monitoring metrics page, click Collect Metrics to Managed Service for Prometheus. In the Confirm dialog box, click OK.
After you enable metric collection, the Monitoring metrics page automatically switches to a dashboard view. The Monitoring metrics page provides multiple dashboards, such as Cloud ASM Istio Gateway Status, Cloud ASM Istio Http Gateway, and Cloud ASM Istio Mesh. You can view these dashboards as needed.
After you stop metric collection, the gateway and sidecar proxies continue to expose their last-collected metric values, which are not updated. To clear these stale metrics, restart the workloads. For more information, see Redeploy workloads.
If you no longer need this feature, click Disable the Collection of Metrics to Managed Service for Prometheus in the upper-right corner of the Monitoring metrics page. In the Confirm dialog box, click OK.
Related documents
-
After you collect metrics to Managed Service for Prometheus, you can view monitoring reports in the ASM console or the Grafana console. For more information, see Integrate Managed Service for Prometheus to monitor the mesh.
-
If you use a self-managed Prometheus instance and want to implement mesh monitoring, see Integrate a self-managed Prometheus instance for mesh monitoring.
-
If you need to customize metrics or log formats, see Customize monitoring metrics in ASM and Observability configurations.
-
ASM reduces the attack surface in cloud-native environments and provides the foundation for a zero-trust application network. By managing service-to-service security with ASM, you can ensure end-to-end encryption, service-level authentication, and fine-grained authorization policies. For more information, see Overview of zero trust security.
-
You can enable the mesh audit feature to track daily user operations. You can also configure audit alerts for mesh resources to notify alert contacts when critical resources are modified. For more information, see Use KubeAPI operation audit and Configure audit alerts for operations on mesh resources.