• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
El Blog de Jorge de la Cruz

El Blog de Jorge de la Cruz

El Blog de Jorge de la Cruz - Todas las novedades sobre VMware, Veeam, InfluxData, Grafana, Zimbra, etc.

  • Home
  • VMware
    • VMworld
    • VMware vSphere 6.7
    • VMware vSphere 6.5
  • Veeam
    • Resumen Contenido 2021
    • Veeam v11
      • Continuous Data Protection (CDP
      • Ransomware Protection
      • Archive Tier
      • Mejoras en Instant Recovery
      • Veeam Agent for Mac
      • Veeam Backup for AHV v2.1
    • Veeam Backup for Microsoft Office 365
      • 1 – Razones para proteger nuestra información en Microsoft Office 365
      • 2 – Componentes lógicos de Veeam Backup for Microsoft Office 365 2.0
      • 3 – Instalación paso a paso de Veeam Backup for Microsoft Office 365 v2.0
      • 4 – Configuración inicial de Veeam Backup for Microsoft Office 365 v2.0
      • 5 – Creando trabajos de copia en Veeam Backup for Microsoft Office 365 v2.0
      • 6 – Restaurando elementos en Veeam Backup for Microsoft Office 365 v2.0
    • Veeam Backup for AWS
      • Veeam: Veeam anuncia Veeam Backup for AWS Free Edition
      • Veeam: Cómo Desplegar Veeam Backup for AWS – paso a paso
      • Veeam: Vistazo en profundidad al nuevo Veeam Backup for AWS – Creación de Políticas de Backup y Restauración
      • Veeam: Cómo conectar nuestro Veeam Backup & Replication a Veeam Backup for AWS
    • Veaam ONE
      • En busca del Dashboard perfecto: Veeam ONE – Parte I – Introducción a Veeam ONE
      • En busca del Dashboard perfecto: Veeam ONE – Parte II – Descarga e Instalación de Veeam ONE
      • En busca del Dashboard perfecto: Veeam ONE – Parte III – Añadir una Infraestructura de VMware vSphere a Veeam ONE
      • En busca del Dashboard perfecto: Veeam ONE – Parte IV – Añadir una Infraestructura de Veeam Backup and Replication a Veeam ONE
      • En busca del Dashboard perfecto: Veeam ONE – Parte V – Realizando troubleshooting de vSphere usando Veeam ONE Monitor
      • En busca del Dashboard perfecto: Veeam ONE – Parte VI – Realizando troubleshooting de Veeam Backup and Replication usando Veeam ONE Monitor
      • En busca del Dashboard perfecto: Veeam ONE – Parte VII – Vistazo profundo a los Dashboards en Veeam ONE Reporter
      • En busca del Dashboard perfecto: Veeam ONE – Parte VIII – Vistazo profundo a Reportes en Veeam ONE Reporter
      • En busca del Dashboard perfecto: Veeam ONE – Parte IX – Chargeback para crear reportes de coste de nuestra Infraestructura
    • Veeam Availability Console
      • 1 – Teoría e información útil sobre el producto
      • 2 – Instalación de Veeam Availability Console
      • 3 – Configuración y conexión con VBR Server
      • 4 – Administración centralizada de Veeam Backup Agents
      • 5 – Backup de Agentes a diferentes destinos, SMB, Repositorio Veeam o Cloud Connect
      • 6 – Reportes de Backup de Veeam Agent y Veeam Backup and Replication
      • 7 – Manejando la Facturación de Veeam Agents, Backup and Replication y Cloud Connect
    • Backup y restore de cargas de trabajo a Microsoft Azure
      • 1 – Introducción
      • 2 – Conectividad entre nuestro Datacenter y Microsoft Azure
      • 3 – Desplegar Veeam Backup and Replication en Microsoft Azure
      • 4 – Configuración en nuestro Datacenter para backup a Microsoft Azure
      • 5 – Restaurando a Microsoft Azure, desde Microsoft Azure
      • 6 – Migrar cargas de trabajo desde Microsoft Azure hacía nuestro Datacenter
    • Veeam v9.5 Update 4
      • Veeam Cloud Tier
        • Cómo controlar el ancho de banda en Veeam Cloud Tier
      • Secure Restore y Staged Restore
      • Mejoras en Veeam Agent Management
      • Veeam Community Edition
      • Actualizar Veeam Enterprise Manager y Veeam Backup and Replication a la última versión
      • VeeamONE con Intelligent Diagnostics, Remediation actions, Business View 2.0 y Application Monitoring
    • VeeamON 2022
      • Novedades en Veeam ONE v12
    • VeeamON 2021
      • VBO v6 – Self-Service y Backup Copy Glacier-Azure Archive
    • VeeamON 2020
      • Veeam Backup for AWS v2.0
    • VeeamON 2019
      • Veeam Availability Orchestrator v2.0 – ¡novedades!
    • VeeamON 2017
      • Sesiones recomendadas
      • Día I – Veeam Availability Suite v10 – ¡novedades!
      • Día II – Veeam Azure PN (Powered Network), Scale-out Archive Tier y mucho más
    • VeeamON 2015
      • VeeamON 2015 volverá a Las Vegas en el único Evento sobre Disponibilidad en el Data Center
      • Completo resumen, keynotes e imágenes
      • vBrownBag – Jorge de la Cruz – Stop sending postcards to your customers
  • Zextras
  • PRTG
  • Office 365
    • Microsoft – Añadiendo nuestro dominio a Office 365, configuración de DNS y migración de actual Mailbox
    • Veeam: Usando Microsoft Office 365 para nuestras notificaciones por correo electrónico
    • PRTG: Usando Microsoft Office 365 para nuestras notificaciones por correo electrónico
  • Zimbra
    • Instalación
      • Instalando Zimbra 8.7.6 sobre Ubuntu 14.04 LTS – ¡con Chat y Drive!
      • Amazon Lightsail para instalar Zimbra Collaboration 8.7.1, Parte II
      • Amazon Lightsail para instalar Zimbra Collaboration 8.7.1, Parte I
      • Instalando Zimbra 8.7.x con un solo comando, incluye Chat y Drive
  • Linux
    • InfluxDB, Grafana y Telegraf
      • 1 – Instalación y configuración de los components
      • 2 – Instalar agente en Linux
      • 3 – Integración con PRTG
      • 4 – Instalar agente Telegraf en Nodos remotos Windows
      • 5 – Activar inputs específicos, Red, MySQL/MariaDB, Nginx
      • 6 – Monitorizando Veeam
    • Ansible y Zabbix
      • 1 – Inicio
      • 2 – Instalación de Ansible e integración con Active Directory
      • 3 – Configuración de AutoDiscovery en Zabbix
      • 4 – Instalación del agente de Zabbix en Windows
      • 5 – Instalación del agente de Zabbix en Linux y Auto Remove en Zabbix
    • Jenkins
      • 1 – Inicio
      • 2 – Instalación de Jenkins en Ubuntu
      • 3 – Instalando nuestro primer plugin
      • 4 – Sincronización NTP de Linux
      • 5 – Añadir un Slave Windows a Jenkins
      • 6 – Ejecutar tareas en Linux
      • 7 – Ejecutar tareas en Windows
    • Kubernetes
      • 1 – Introducción a Kubernetes
      • 2 – Instalación paso a paso
      • 3 – RollingUpdate con Kubernetes
      • 4 – Dashboard
      • 5 – Volúmenes NFS
      • 6 – Registry
      • 7 – Traefik
      • 8 – Systemd con Traefik y Proxy de Kubernetes
      • 9 – Heapster Influx Grafana
      • 10 – Labels de Kubernetes
      • 11 – API: Swagger
      • 12 – API: Creando nuestro primer POD
  • Contribuidores
    • Acerca de Jorge
    • Acerca de Oscar Mas
      • Clúster SQL
        • 1 – Introducción
        • 2 – Preparación de los equipos virtuales
        • 3 – Instalación del Clúster de Microsoft
        • 4 – Instalación de SQL Server para Clúster de Microsoft
        • 5 – Configuración de nuestro Clúster de SQL
        • 6 – Monitorización de Clúster de SQL con Zabbix
        • 7 – Actualizando clúster de SQL

InfluxDB: Securizando nuestros accesos por API a InfluxDB usando HTTPS con Let’s Encrypt de manera gratuita y renovación automatizada

6 September, 2019 - Escrito en: opensource

Saludos amigos, os he contado en numerosas ocasiones cómo desplegar vuestros propios sistemas de monitorización usando Grafana, InfluxDB y Telegraf, pero nunca he abordado el tema de seguridad, al menos lo más básico, servir el API de InfluxDB usando SSL, con lo que en esta entrada vamos a ver cómo configurar InfluxDB para que sea servido usando SSL, además de usar Let’s Encrypt para que no nos cueste ni un céntimo.

Instalar Let’s Encrypt Certbot

Let’s Encrypt es maravilloso, recordar que nos permite solicitar certificados SSL de manera gratuita y válidos por hasta 3 meses, con opciones sencillas de renovación que cubriremos más tarde.

El primero paso será añadir el repositorio de certbot al sistema con el siguiente comando:

sudo add-apt-repository ppa:certbot/certbot

Esto nos mostrará un output similar al siguiente:

 This is the PPA for packages prepared by Debian Let's Encrypt Team and backported for Ubuntu(s).
 More info: https://launchpad.net/~certbot/+archive/ubuntu/certbot
Press [ENTER] to continue or ctrl-c to cancel adding it

gpg: keyring `/tmp/tmp982fvdb1/secring.gpg' created
gpg: keyring `/tmp/tmp982fvdb1/pubring.gpg' created
gpg: requesting key 75BCA694 from hkp server keyserver.ubuntu.com
gpg: /tmp/tmp982fvdb1/trustdb.gpg: trustdb created
gpg: key 75BCA694: public key "Launchpad PPA for certbot" imported
gpg: Total number processed: 1
gpg:               imported: 1  (RSA: 1)
OK

Realizaremos un apt-get update, además de instalar certbot:

sudo apt-get update
sudo apt-get install certbot

Y ya tendremos todo listo para solicitar nuestro SSL, tengo en cuenta que el server tiene acceso a Internet, que el dominio que estáis solicitando responde un DNS público a la IP de salida del server de InfluxDB, y que el puerto 80 está escuchando en el server de InfluxDB para poder completar la petición:

sudo certbot -d veeamtech.ddns.net

Este comando nos mostrará el siguiente menú con preguntas, que tendremos que completar esta única vez:

Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator nginx, Installer nginx
Enter email address (used for urgent renewal and security notices) (Enter 'c' to
cancel): [email protected]
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Please read the Terms of Service at
https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must
agree in order to register with the ACME server at
https://acme-v02.api.letsencrypt.org/directory
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(A)gree/(C)ancel: A

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Would you be willing to share your email address with the Electronic Frontier
Foundation, a founding partner of the Let's Encrypt project and the non-profit
organization that develops Certbot? We'd like to send you email about our work
encrypting the web, EFF news, campaigns, and ways to support digital freedom.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: Y

Ya una vez contestado todo, podremos ver el proceso de petición e instalación del SSL en local:

Starting new HTTPS connection (1): supporters.eff.org
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for veeamtech.ddns.net
Waiting for verification...
Cleaning up challenges
Resetting dropped connection: acme-v02.api.letsencrypt.org
Deploying Certificate to VirtualHost /etc/nginx/sites-enabled/default

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 1

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations! You have successfully enabled https://veeamtech.ddns.net

You should test your configuration at:
https://www.ssllabs.com/ssltest/analyze.html?d=veeamtech.ddns.net
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/veeamtech.ddns.net/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/veeamtech.ddns.net/privkey.pem
   Your cert will expire on 2019-08-30. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot again
   with the "certonly" option. To non-interactively renew *all* of
   your certificates, run "certbot renew"
 - If you like Certbot, please consider supporting our work by:

   Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
   Donating to EFF:                    https://eff.org/donate-le

Como podemos ver, ya tenemos los ficheros necesarios, cert.pem, fullchain.pem y privkey.pem en la ruta /etc/letsencrypt/live/TUDOMINIO/*, vamos a ver los privilegios, tamaño, etc:

ls -la /etc/letsencrypt/live/veeamtech.ddns.net/
total 12
drwxr-xr-x 2 root root 4096 Jun  1 14:12 .
drwx------ 3 root root 4096 Jun  1 14:12 ..
lrwxrwxrwx 1 root root   42 Jun  1 14:12 cert.pem -> ../../archive/veeamtech.ddns.net/cert1.pem
lrwxrwxrwx 1 root root   43 Jun  1 14:12 chain.pem -> ../../archive/veeamtech.ddns.net/chain1.pem
lrwxrwxrwx 1 root root   47 Jun  1 14:12 fullchain.pem -> ../../archive/veeamtech.ddns.net/fullchain1.pem
lrwxrwxrwx 1 root root   45 Jun  1 14:12 privkey.pem -> ../../archive/veeamtech.ddns.net/privkey1.pem
-rw-r--r-- 1 root root  692 Jun  1 14:12 README

¿Lo mejor de todo? Certbot de Let’s Encrypt se encargará de renovar estos certificados cada 90 días, ya que hay una tarea que se ejecuta dos veces por día para comprobar el estado del SSL, todo esto grátis, ¿qué más queremos?

Mi recomendación si estamos usando este SSL para otros menésteres, como por ejemplo Grafana, es que hagamos una copia del mismo de la siguiente manera:

mkdir /etc/influxdb/ssl
cp /etc/letsencrypt/live/veeamtech.ddns.net/* /etc/influxdb/ssl/

Si quisiéramos ver cómo se renueva, podemos ejecutar el siguiente comando:

sudo certbot renew --dry-run

Configuración de InfluxDB para forzar el tráfico por HTTPS/SSL

Ahora que ya tenemos nuestros ficheros listos, tendremos que editar el fichero de configuración de InfluxDB, que podemos encontrar aquí:

vi /etc/influxdb/influxdb.conf

Y editar lo siguiente, básicamente decirle que queremos usar https, el dominio que está esperando,  y muy importante la ruta que he mencionado anteriormente a los ficheros de Let’s Encrypt:

hostname = "YOURPUBLICFQDN"
...
[http]
   enabled = true
   bind-address = "YOURFQDN:8086"
   log-enabled = true

   https-enabled = true
   https-certificate = "/etc/influxdb/ssl/fullchain.pem"
   https-private-key = "/etc/influxdb/ssl/privkey.pem"

Como pequeño truco, ya que el grupo de influxdb en mi caso no tiene acceso a estos ficheros, he tenido que realizar lo siguiente:

chgrp -R influxdb /etc/influxdb/ssl
chmod -R g=rX /etc/influxdb/ssl
sudo service influxdb restart

Accediendo a InfluxDB de manera segura con HTTPS

Ahora que ya tenemos todo preparado, configurado y todo funciona, vamos a acceder a nuestro FQDN con HTTPS delante y el puerto 8086, ya podremos ver nuestra conexión mediante SSL, ¡buen trabajo!

influx -ssl -host TUFQDN
Connected to https://TUFQDN:8086 version 1.6.3
InfluxDB shell version: 1.6.3

Con curl podemos ver el SSL que se está mostrando, así y nos mostrará algo similar:

curl -vvI https://TUFQDN:8086
* Rebuilt URL to: https://TUFQDN:8086/
* Connected to TUFQDN (192.168.1.3) port 8086 (#0)
* found 148 certificates in /etc/ssl/certs/ca-certificates.crt
* found 593 certificates in /etc/ssl/certs
* ALPN, offering http/1.1
* SSL connection using TLS1.2 / ECDHE_RSA_AES_128_GCM_SHA256
*        server certificate verification OK
*        server certificate status verification SKIPPED
*        common name: TUFQDN (matched)
*        server certificate expiration date OK
*        server certificate activation date OK
*        certificate public key: RSA
*        certificate version: #3
*        subject: CN=TUFQDN
*        start date: Wed, 31 Jul 2019 19:01:06 GMT
*        expire date: Tue, 29 Oct 2019 19:01:06 GMT
*        issuer: C=US,O=Let's Encrypt,CN=Let's Encrypt Authority X3
*        compression: NULL
* ALPN, server did not agree to a protocol
> HEAD / HTTP/1.1
> Host: TUFQDN:8086
> User-Agent: curl/7.47.0
> Accept: */*

Tendremos que editar todos nuestros Telegrafs para que apunten a la nueva dirección en HTTPS, de la siguiente manera en cada agente Telegraf:

    ###############################################################################
    #                            OUTPUT PLUGINS                                   #
    ###############################################################################

    # Configuration for InfluxDB server to send metrics to
    [[outputs.influxdb]]
      ## The full HTTP or UDP endpoint URL for your InfluxDB instance.
      ## Multiple urls can be specified as part of the same cluster,
      ## this means that only ONE of the urls will be written to each interval.
      # urls = ["udp://localhost:8089"] # UDP endpoint example
      urls = ["https://TUFQDN:8086"]

Os dejo todas las entradas sobre Grafana, InfluxDB y Telegraf, por si os son de ayuda:

  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte I (Instalando InfluxDB, Telegraf y Grafana)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte II (Instalar agente Telegraf en Nodos remotos Linux)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte III Integración con PRTG
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte IV (Instalar agente Telegraf en Nodos remotos Windows)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte V (Activar inputs específicos, Red, MySQL/MariaDB, Nginx)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte VI (Monitorizando Veeam)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte VII (Monitorizar vSphere)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte VIII (Monitorizando Veeam con Enterprise Manager)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte IX (Monitorizando Zimbra Collaboration)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte X (Grafana Plugins)
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XI
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XII – Plugin nativo de Telegraf para vSphere
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XIII – Veeam Backup for Microsoft Office 365
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XIV – Veeam Availability Console
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XV – Monitorización IPMI de nuestros Hosts ESXi
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XVI – Rendimiento y seguridad avanzada de Veeam Backup for Microsoft Office 365
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XVII – Mostrando los Dashboards en dos monitores usando Raspberry Pi 4
  • En busca del Dashboard perfecto: InfluxDB, Telegraf y Grafana – Parte XVIII – Monitorizar temperatura y estado de Raspberry Pi 4

Filed Under: opensource Tagged With: influxdb, influxdb certificate, influxdb letsencrypt, influxdb security, influxdb ssl, influxdb telegraf ssl, influxdb telegraf tls

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

  • Email
  • GitHub
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Gold Partners

Silver Partners

Libros Gratuitos

Cloud por vExperts
VMware por vExperts

VMware vExpert

Puesto 16 en Top vBlog

Calendario de Posts

September 2019
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
30  
« Aug   Oct »

Disclaimer

Todas las opiniones expresadas en este sitio son las mías propias y no representan las opiniones de ninguna compañía con la que haya trabajado, esté trabajando o vaya a estar trabajando.

Copyright © 2026 · El Blog de Jorge de la Cruz