Requirements
You need a Prometheus remote write endpoint and credentials that can write to it. If the endpoint requires authentication, store the credential in the Namespace vault and reference the secret ID from the instance configuration. For Grafana Cloud Metrics, use the remote write endpoint shown in the Grafana Cloud portal. It usually has this form:Store the remote write secret
Create a Namespace vault secret from a local file that contains the remote write password or token:object_id value in the sink configuration.
The secret is resolved by the host and is not exposed inside the guest.
Create an instance with a metrics sink
Create an experimental configuration file:prometheus-metrics-sink.json
--experimental_from with the other flags you normally pass to nsc create, such as shape, image, duration, labels, or purpose.
For the full configuration schema, see the PrometheusMetricsSink API reference.
Bearer token endpoints
If your remote write endpoint accepts bearer token authentication, usebearerTokenSecretRef instead of basic auth:
prometheus-metrics-sink-bearer.json
Metrics and labels
The external sink exports guest metrics with these default metric name prefixes:guest_cpu_guest_memory_guest_disk_guest_filesystem_
nsc_instance_idnsc_tenant_id
cpu and mode, disk metrics include device, and filesystem metrics include device, filesystem, and mountpoint when the source metric provides them.
Namespace-internal routing labels are removed before export. The sink does not send labels such as nsc_vm_id, nsc_cluster_id, nsc_region, nsc_worker, or nsc_layer.