Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Protection of web web endpoint #20

Closed
hynek opened this issue Oct 1, 2015 · 1 comment
Closed

Protection of web web endpoint #20

hynek opened this issue Oct 1, 2015 · 1 comment

Comments

@hynek
Copy link

hynek commented Oct 1, 2015

Hi,

it seems like there’s no way of protecting the web endpoint although Prometheus supports both basic auth TLS certificates (at least according to the docs :)).

Any chance of collected_exporter growing them? I would prefer to not install a nginx on each server just to be able to use HTTPS for my metrics…

Metrics might not be the most sensitive data and our metrics subnet is private but for example on customer servers I’m uncomfortable to expose all system statistics to all users.

@brian-brazil
Copy link
Contributor

Due to how many different ways it's possible to configure security, authorisation and authentication we've decided that we'd rather dedicate our time to improving monitoring and delegate to other systems like nginx that are more suited for this purposet.

If you're worrried about connections over localhost Linux iptables supports filtering on UID/GID.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants