Getting Started with ClusterNest Managed Prometheus
ClusterNest Managed Prometheus runs Cortex behind a Prometheus-compatible remote-write/query API, so any tool that speaks the Prometheus HTTP API (Prometheus itself, Grafana Agent, an OpenTelemetry Collector, Grafana) works against it without changes. This guide creates a cluster, fetches its credentials, and runs a first query.
Every example below needs your organization's numeric ID - find it in the console (it's in the
URL once you're inside an organization), or via GET /auth/user-info with a bearer token, which
lists every organization you belong to along with its id.
1. Create a cluster
- Console
- Terraform
- Raw API
resource "clusternest_prometheus" "metrics" {
name = "metrics"
tier = "standard"
organization_id = 123
}
See the resource reference for the full field list.
POST /cluster/prometheus/, authenticated with a bearer token (see
Get an access token):
curl -X POST https://api.clusternest.com/cluster/prometheus/ \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "metrics",
"organization_id": 123,
"tier": "standard"
}'
The trailing slash on /cluster/prometheus/ is required - without it the API 307-redirects,
and most HTTP clients don't resend a POST body across that automatically.
The response includes the cluster's id - every other call in this guide needs it.
2. Get your credentials
Every Prometheus cluster has three static credentials: admin (full access), readonly
(query only), and write (push only) - see Managing credentials
for exactly what each one can reach.
- Console
- Terraform
- Raw API
Shown automatically once the cluster in step 1 finishes creating - save them then. The console has no way to view them again later; use Terraform or the raw API for that.
data "clusternest_prometheus_credentials" "metrics" {
cluster_id = clusternest_prometheus.metrics.id
}
curl https://api.clusternest.com/cluster/prometheus/$CLUSTER_ID/credentials \
-H "Authorization: Bearer $ACCESS_TOKEN"
{
"admin": "<password>",
"readonly": "<password>",
"write": "<password>"
}
3. Run your first query
Fetch the cluster's hostname (the prometheus_url field, returned by GET /cluster/prometheus/$CLUSTER_ID or shown in the console, minus the https:// - that's
$PROMETHEUS_HOST in every other guide here too), then query it with PromQL under the
/prometheus prefix, using the admin username and the admin password from the step above:
curl -u "admin:$ADMIN_PASSWORD" \
"https://$PROMETHEUS_HOST/prometheus/api/v1/query?query=up"
An empty result array is expected here - nothing has pushed metrics into the cluster yet.
Next steps
- Push metrics in with the
writecredential. - Query and wire up Grafana with the
readonlycredential. - Let your own identity provider authenticate directly instead of managing static passwords.