chmonitorchmonitor
Deployment

Traefik

Put chmonitor behind Traefik as a reverse proxy on Kubernetes or Docker, with optional ForwardAuth for SSO via oauth2-proxy.

Run chmonitor behind Traefik as reverse proxy / ingress. Same pattern on Kubernetes (IngressRoute or Ingress) and Docker (container labels).

Traefik handles TLS, routing, and — with oauth2-proxy — authentication. chmonitor can stay on none and trust the forwarded identity.

Loading diagram…

Prerequisites

What you need

  • A running Traefik instance (ingress controller or Docker provider)
  • chmonitor via Helm or Docker
  • For SSO: oauth2-proxy (Dex, Google, GitHub, …)

Setup

chmonitor listens on port 3000.

If you installed with the Helm chart, expose the Service with an IngressRoute:

apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
  name: chmonitor
  namespace: monitoring
spec:
  entryPoints:
    - websecure
  routes:
    - match: Host(`chmonitor.example.com`)
      kind: Rule
      services:
        - name: chmonitor          # chart Service name
          port: 3000               # service.port (default 3000)
  tls:
    certResolver: letsencrypt      # or tls.secretName

Prefer standard Ingress? Enable it in the chart:

ingress:
  enabled: true
  className: traefik
  hosts:
    - host: chmonitor.example.com
      paths:
        - path: /
          pathType: Prefix
  tls:
    - hosts: [chmonitor.example.com]
      secretName: chmonitor-tls

With Compose and Traefik watching Docker:

services:
  chmonitor:
    image: ghcr.io/chmonitor/chmonitor:latest
    environment:
      CLICKHOUSE_HOST: http://clickhouse:8123
      CLICKHOUSE_USER: default
      CLICKHOUSE_PASSWORD: ""
    labels:
      - traefik.enable=true
      - traefik.http.routers.chmonitor.rule=Host(`chmonitor.example.com`)
      - traefik.http.routers.chmonitor.entrypoints=websecure
      - traefik.http.routers.chmonitor.tls.certresolver=letsencrypt
      - traefik.http.services.chmonitor.loadbalancer.server.port=3000

Authentication via ForwardAuth

Put chmonitor behind oauth2-proxy using Traefik ForwardAuth, and read identity with the trusted auth provider.

Define the ForwardAuth middleware

apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
  name: oauth2-proxy-auth
  namespace: monitoring
spec:
  forwardAuth:
    address: http://oauth2-proxy.monitoring.svc.cluster.local/oauth2/auth
    trustForwardHeader: true
    authResponseHeaders:
      - X-Auth-Request-User
      - X-Auth-Request-Email
      - X-Auth-Request-Preferred-Username
      - X-Auth-Request-Groups

Attach the middleware to the route

Add middlewares: [{ name: oauth2-proxy-auth }] on the IngressRoute, or traefik.http.routers.chmonitor.middlewares=... on Docker.

Configure chmonitor's trusted provider

CHM_AUTH_PROVIDER=trusted
# oauth2-proxy forwards X-Auth-Request-* (not X-Forwarded-*)
CHM_TRUSTED_USER_HEADER=X-Auth-Request-User
CHM_TRUSTED_EMAIL_HEADER=X-Auth-Request-Email
CHM_TRUSTED_NAME_HEADER=X-Auth-Request-Preferred-Username
CHM_TRUSTED_GROUPS_HEADER=X-Auth-Request-Groups
# Restrict to Dex groups (optional)
CHM_TRUSTED_ALLOWED_GROUPS=sre,platform-admins

See Trusted proxy for headers, shared-secret vs CHM_TRUSTED_ALLOW_INSECURE, and Dex/oauth2-proxy flags.

Verify

chmonitor exposes /healthz (liveness, static) and /api/healthz (readiness, ClickHouse-gated). Traefik can health-check:

services:
  - name: chmonitor
    port: 3000
    healthCheck:
      path: /healthz
      intervalSeconds: 15

Don't guard health endpoints with ForwardAuth

Do not put ForwardAuth on /healthz and /api/healthz, or probes redirect to login. Use a higher-priority router without auth, or the chart's Kubernetes probes (hit the pod, bypass Traefik).

Troubleshooting

On this page