How to monitor ssl certificates with Datadog?

Viewed 1348

I have an nginx-pod which redirects traffic into Kubernetes services and stores related certificates insides its volume. I want to monitor these certificates - mainly their expiration.

I found out that there is a TLS integration in Datadog (we use Datadog in our cluster): https://docs.datadoghq.com/integrations/tls/?tab=host.

They provide sample file, which can be found here: https://github.com/DataDog/integrations-core/blob/master/tls/datadog_checks/tls/data/conf.yaml.example

To be honest, I am completely lost and do not understand comments of the sample file - such as:

## @param server - string - required
## The hostname or IP address with which to connect.

I want to monitor certificates that are stored in the pod, does it mean this value should be localhost or do I need to somehow iterate over all the certificates that are stored using this value (such as server_names in nginx.conf)? If anyone could help me with setting sample configuration, I would be really grateful - if there are any more details I should provide, that is not a problem at all.

1 Answers

TLS Setup on Host

You can use a host type of instance to track all your certificate expiration dates

1- Install TLS Integration from datadog UI

2- Create instance and install datadog agent in there.

3- Create a /etc/datadog/conf.d/tls.d/conf.yaml

4- Edit following template for your need

init_config:
instances:

    ## @param server - string - required
    ## The hostname or IP address with which to connect.
    #
  - server: https://yourDNS1.com/
    tags:
      - dns:yourDNS.com
  - server: https://yourDNS2.com/
    tags:
      - dns:yourDNS2
  - server: yourDNS3.com
    tags:
      - dns:yourDNS3
  - server: https://yourDNS4.com/
    tags:
      - dns:yourDNS4.com
  - server: https://yourDNS5.com/
    tags:
      - dns:yourDNS5.com
  - server: https://yourDNS6.com/
    tags:
      - dns:yourDNS6.com

5- Restart datadog-agent

systemctl restart datadog-agent

6- Check status if you see the tls is running successfully

watch systemctl status datadog-agent

8- Create a TLS Overview Dashboard

9- Create a Monitor for getting alert on expiration dates


TLS Setup on Kubernetes

1- Create a ConfigMap and attach that as a Volume https://docs.datadoghq.com/agent/kubernetes/integrations/?tab=configmap

Related