Sign inSign up

basa/spki-fingerprint-exporter

By basa

•Updated about 1 month ago

Prometheus exporter for SHA-256 SPKI fingerprints of TLS certificates presented by remote services.

Image
0

780

basa/spki-fingerprint-exporter repository overview

⁠SPKI Fingerprint Exporter

Prometheus exporter that reports the SHA-256 fingerprint of the Subject Public Key Info (SPKI) in certificates presented by TLS services. Useful for monitoring certificate key rotation and validating HPKP-style pin sets.

⁠Quick start

docker run -p 3000:3000 basa/spki-fingerprint-exporter
curl "http://localhost:3000/probe?target=example.com:443"

Example output:

spki_fingerprint{fingerprint="base64encodedsha256sumofspki=",target="example.com:443"} 1
probe_success 1
probe_duration_seconds 0.042

Targets are host:port or a URL. Without an explicit port, it is derived from the URL scheme (https, smtps, submissions, nntps, ldaps, domain-s, ftps, imaps, pop3s, sips); other protocols need the port spelled out.

⁠Prometheus configuration

Scrape it like the blackbox exporter, with one probe per target:

scrape_configs:
  - job_name: spki-fingerprint
    metrics_path: /probe
    static_configs:
      - targets:
          - example.com:443
          - smtps://mail.example.com
    relabel_configs:
      - source_labels: [__address__]
        target_label: __param_target
      - source_labels: [__param_target]
        target_label: instance
      - target_label: __address__
        replacement: spki-fingerprint-exporter:3000

⁠Endpoints

PathPurpose
/probe?target=<host:port or URL>Probe a TLS service and return its SPKI fingerprint metrics
/metricsThe exporter's own process metrics
/-/healthy, /-/readyLiveness and readiness checks

⁠Configuration

VariableDescriptionDefault
LISTEN_ADDRESSAddress to listen on:3000
DEFAULT_TIMEOUTProbe timeout: integer seconds or a Go duration (750ms, 15s)10
MAX_CONCURRENT_PROBESMaximum simultaneous outbound TLS probes64

Invalid or non-positive timeout values are a configuration error at startup, not a silent fallback.

⁠Image details

  • Architectures: linux/amd64, linux/arm64
  • Base: scratch — a single static Go binary, runs as a non-root user (UID 1000)
  • Tags: latest, plus per-release version tags in both forms (1.2.3 and v1.2.3)

⁠Kubernetes

A Helm chart (with optional ServiceMonitor support) is attached to each GitHub release⁠.

⁠Source

Source code, issues, and releases: https://github.com/samuelb/spki-fingerprint-exporter⁠

Tag summary

Content type

Image

Digest

sha256:34cadcaa2…

Size

8.4 MB

Last updated

about 1 month ago

docker pull basa/spki-fingerprint-exporter