Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

/metrics endpoint is available on KKP installation URL #7060

Open
embik opened this issue Jan 6, 2025 · 0 comments
Open

/metrics endpoint is available on KKP installation URL #7060

embik opened this issue Jan 6, 2025 · 0 comments
Labels
sig/ui Denotes a PR or issue as being assigned to SIG UI.

Comments

@embik
Copy link
Member

embik commented Jan 6, 2025

What happened

Dashboard metrics are available without authentication on the /metrics path of a KKP hostname, e.g. https://dev.kubermatic.io/metrics. Metrics include information about which URLs are accessible.

Expected behavior

Metrics are not publicly accessible and ideally hosted on a dedicated metrics port.

How to reproduce

Environment

  • UI Version: main
  • API Version: main
  • Domain: dev.kubermatic.io
  • Others:

Current workaround

Patch Ingress resources to block /metrics, perhaps?

Affected user persona

Business goal to be improved

Metric to be improved

@embik embik added kind/bug Categorizes issue or PR as related to a bug. sig/ui Denotes a PR or issue as being assigned to SIG UI. labels Jan 6, 2025
@ahmedwaleedmalik ahmedwaleedmalik removed the kind/bug Categorizes issue or PR as related to a bug. label Jan 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
sig/ui Denotes a PR or issue as being assigned to SIG UI.
Projects
None yet
Development

No branches or pull requests

2 participants