Prometheus
Self-managed or managed (Grafana Cloud, Amazon Managed Prometheus, Thanos)
Access mode: Read-only
Niche connector. This system is queryable via Flume’s Lakehouse (Trino) and supported on request. It is not part of the standard data estate onboarding but is available for clients with specific requirements.
Required information
| Field | Details |
|---|---|
| Prometheus endpoint | Prometheus server URL or Thanos Query endpoint. Grafana Cloud: provided endpoint. |
| Port | Default 9090. Grafana Cloud: HTTPS on 443. |
| Authentication | Varies: no auth (internal), basic auth, bearer token, or OAuth (Grafana Cloud). |
| Metric scope | Metric names or label selectors to scope access. |
Network considerations
Self-managed: VPN or direct access to port 9090. Prometheus is often internal-only.
Grafana Cloud: HTTPS over 443. API key authentication.
Thanos: Query component endpoint, typically on port 9090 or custom.
Amazon Managed Prometheus: AWS SigV4 auth over HTTPS. VPC endpoint available.
Trino access: Flume’s Lakehouse queries Prometheus via the Trino Prometheus connector through the HTTP API.
Credential and auth management
Self-managed: Often no auth when behind VPN. If auth enabled, basic auth or reverse proxy with auth layer.
Grafana Cloud: API key with MetricsViewer role.
Amazon Managed Prometheus: IAM role with aps:QueryMetrics permission.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | curl http://<host>:9090/-/healthy | Returns Prometheus Server is Healthy. |
| Query test | curl 'http://<host>:9090/api/v1/query?query=up' | Returns metric data |
| Label listing | GET /api/v1/labels | Lists available labels |
| Trino query | SELECT * FROM prometheus.<metric> LIMIT 1 via Trino | Returns metric data points |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.