Alertmanager
The types follow Alertmanager v0.34.1 (PROMETHEUS_PIN.alertmanager). Field names are the file’s own, so the Alertmanager configuration docs apply as written.
| Field | Type | Meaning |
|---|---|---|
receiver | Receiver or string | Where matching alerts go. Required on the root route. |
matchers | string[] | Alertmanager matchers, e.g. severity="page", team=~"db|infra". Not allowed on the root. |
group_by | string[] | Labels alerts are grouped by into one notification. ["..."] groups by every label. |
group_wait, group_interval, repeat_interval | duration | Notification timing. |
continue | boolean | Keep matching sibling routes after this one matches. |
mute_time_intervals, active_time_intervals | (TimeInterval | string)[] | When the route is muted, or the only times it is active. |
labels | LabelSet | Labels on the route, inherited by child routes and exposed to notification templates as routeLabels. Values may be Go templates. |
routes | (Route | RouteProps)[] | Child routes, tried in order. |
The root route is the one Route entity no other route lists in routes. Declaring two roots is a build warning, and the first is used.
A route that references a Receiver or TimeInterval entity pulls it into the output even when it isn’t exported on its own. A name string must match a declared one (PROM201, PROM204).
Receiver
Section titled “Receiver”| Field | Integration |
|---|---|
name | Unique (PROM203). |
labels | Labels exposed to notification templates. |
webhook_configs | url or url_file, http_config, max_alerts, timeout, payload. |
email_configs | to, from, smarthost, auth_username, auth_password_file, require_tls, force_implicit_tls, threading, headers, html, text. |
slack_configs | api_url_file (or api_url), or app_token_file with app_url; channel, title, text, message_text, fields, actions, update_message. |
pagerduty_configs | routing_key_file (or routing_key, or the v1 service_key), severity, class, component, group, details, links, timeout. |
opsgenie_configs | api_key_file (or global.opsgenie_api_key_file), message, priority, responders, tags, details. |
msteams_configs, msteamsv2_configs | webhook_url_file, title, text (and summary for the connector webhook). |
discord_configs | webhook_url_file, title, message, content. |
telegram_configs | bot_token_file (or the global one), chat_id or chat_id_file, message, parse_mode. |
sns_configs | topic_arn, phone_number or target_arn; sigv4, subject, message, attributes. |
wechat_configs | api_secret_file (or the global one), corp_id, to_user, agent_id, message. |
webex_configs | room_id, message, and the bot token in http_config.authorization. |
victorops_configs | api_key_file (or the global one), routing_key, message_type, custom_fields. |
pushover_configs | user_key_file, token_file, priority, retry, expire, sound. |
jira_configs | project, issue_type, summary, description, labels, the transitions, fields. |
incidentio_configs | url or url_file, alert_source_token_file. |
rocketchat_configs | token_file and token_id_file (or the global ones), channel, fields, actions. |
mattermost_configs | webhook_url_file (or the global one), channel, text, attachments, priority. |
The types follow the Go structs of Alertmanager v0.34.1 field for field, so a misspelled or unknown field is a type error.
Every integration takes send_resolved. A receiver with no integrations is valid: Alertmanager holds the alerts and sends nothing.
Credentials
Section titled “Credentials”Alertmanager does not expand environment variables in its config. Mount each secret as a file and use the *_file field. PROM001 flags a literal credential in a Receiver or AlertmanagerSettings: a Slack api_url or app_token, a PagerDuty routing_key or service_key, a webhook_url, api_key, api_secret, bot_token, token, token_id, user_key or alert_source_token, the SMTP auth_password and auth_secret, their global counterparts, and the http_config credentials, bearer_token, password and client_secret. Each has a *_file sibling. An api_url outside Slack and a VictorOps routing_key are not secrets and are not flagged. A webhook url is not flagged either; put a tokenized URL in url_file.
InhibitRule
Section titled “InhibitRule”An optional name, then source_matchers, target_matchers and equal: while an alert matching the source fires, alerts matching the target that agree on every equal label are muted.
TimeInterval
Section titled “TimeInterval”name and time_intervals, each a period with any of times (start_time/end_time, HH:MM), weekdays (monday:friday), days_of_month, months, years and location (an IANA zone).
AlertmanagerSettings
Section titled “AlertmanagerSettings”global (resolve_timeout, http_config, smtp_*, and each integration’s default URL and credential file, such as slack_api_url_file, opsgenie_api_key_file or telegram_bot_token_file), templates and tracing (where Alertmanager sends its own traces). Declare at most one.
Output
Section titled “Output”alertmanager.yml sections come out in the order global, templates, route, inhibit_rules, receivers, time_intervals, tracing. Receivers and time intervals are sorted by name; routes keep the order they are written in, since Alertmanager tries them in order.
| Function | Returns |
|---|---|
buildAlertmanagerConfig(entities) | { config, warnings, count } |
alertmanagerYaml(entities) | The file text, exactly as the serializer writes it. |
validateAlertmanagerConfig(config) | PROM201 and PROM203 to PROM210 findings. |
validateSeverityRouting(ruleFiles, config) | PROM202 findings. |
parseMatchers(s), matcherMatches(m, labels), matcher(name, op, value) | Matcher parsing, evaluation and quoting. |