When, set service monitoring prometheus blackbox-exporter modules icmp is configured, ICMP probes silently fail with probe_success=0 in Prometheus metrics.
The blackbox exporter runs under the node_exporter system user. The VyOS kernel default for net.ipv4.ping_group_range is '1 0'.
This permits only the privileged group to create ICMP sockets. The node_exporter user therefore cannot send ICMP packets, and probes fail.
Configuration:
set service monitoring prometheus blackbox-exporter listen-address 0.0.0.0 set service monitoring prometheus blackbox-exporter port 9115 set service monitoring prometheus blackbox-exporter modules icmp name ping4 preferred-ip-protocol ipv4
Then scrape the probe endpoint from Prometheus:
/probe?target=8.8.8.8&module=ping4
Expected result: probe_success 1
Actual result: probe_success 0 with no error logged
Possible Solutions:
- Automatically configure sysctl when any modules icmp entry is present (during commit) and apply net.ipv4.ping_group_range = 0 2147483647, removing it when no ICMP modules remain configured. (Reference: https://github.com/prometheus/blackbox_exporter#permissions)
- Add AmbientCapabilities=CAP_NET_RAW and CapabilityBoundingSet=CAP_NET_RAW to blackbox_exporter.service.j2 conditionally when ICMP modules are present.