Query Cloudflare Access-protected Prometheus and Thanos endpoints with promtool and the bundled promq CLI...
Use this skill to query Prometheus or Thanos endpoints protected by Cloudflare Access using promtool plus the bundled promq CLI. Rely on promq to fetch Access tokens, apply the correct header casing, and generate promtool HTTP config files.
| Endpoint | URL | Description |
|---|---|---|
| Thanos (Global) | https://metrics.cfdata.org |
Global Thanos query endpoint with all metrics |
| PDX Core | https://pdx01.prometheus-access.cfdata.org |
PDX datacenter core metrics |
| Colo-specific | https://{colo}01.prometheus-access.cfdata.org |
Per-colo metrics (e.g., sjc01, lax01, ams01) |
promtool and cloudflared are installed and on PATH.eval "$(node skills/prometheus-query/scripts/promq.js login --endpoint https://metrics.cfdata.org)"
node skills/prometheus-query/scripts/promq.js query \
--endpoint https://metrics.cfdata.org \
'up{job="prometheus"}'
eval when needed (if cache is enabled):node skills/prometheus-query/scripts/promq.js labels \
--endpoint https://metrics.cfdata.org \
__name__
Run commands via node skills/prometheus-query/scripts/promq.js <command> or install locally with npm --prefix skills/prometheus-query install and use npx --prefix skills/prometheus-query promq <command>.
Fetch an Access token and emit shell exports by default.
promq login --endpoint <url>
promq login --endpoint <url> --json
promq login --endpoint <url> --token
promq login --endpoint <url> --no-cache
promq query --endpoint <url> '<promql>'
promq range --endpoint <url> \
--start="2024-01-01T00:00:00Z" \
--end="2024-01-01T01:00:00Z" \
--step=1m \
'<promql>'
promq labels --endpoint <url> __name__
promq labels --endpoint <url> <label_name>
promq series --endpoint <url> --match='{job="prometheus"}'
CF_ACCESS_TOKEN or PROMQ_ACCESS_TOKEN to override cached tokens.eval "$(promq login --endpoint <url>)" to set CF_ACCESS_TOKEN and PROMQ_ENDPOINT in the current shell.CF-Access-Token for metrics.cfdata.org, cf-access-token for all other endpoints.PROMQ_DEFAULT_ENDPOINT to change the default endpoint without passing --endpoint..opencode/skill/prometheus-query/token-cache.json (relative to the working directory) unless PROMQ_TOKEN_CACHE overrides the path.login and confirming header case.https://{colo}01.prometheus-access.cfdata.org.up first or listing __name__ labels.login to refresh the cache.skills/prometheus-query/scripts/promq.js - CLI wrapper around promtool and cloudflaredskills/prometheus-query/scripts/promq.test.js - CLI unit testsskills/prometheus-query/scripts/.env.example - environment defaults and overrides