Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[prometheus-node-exporter] Metrics endpoint exposed on node IP #5009

Open
abhishekc-92 opened this issue Nov 21, 2024 · 0 comments
Open

[prometheus-node-exporter] Metrics endpoint exposed on node IP #5009

abhishekc-92 opened this issue Nov 21, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@abhishekc-92
Copy link

abhishekc-92 commented Nov 21, 2024

Is your feature request related to a problem ?

Security scans caught a metrics endpoint on our stack exposed on the node IP. One solution that we found to mitigate this was to override the hostnetwork parameter on the chart, after which the service endpoint is not exposed outside anymore.

Describe the solution you'd like.

The ask is for documentation/clarification for us to understand what the repercussions of this override will be on functionality, other than not exposing the endpoint on the node IP, and why it is on the host network by default.

If the component does need access to the host network to function properly, an ideal solution would be to have it access host network for monitoring but expose the port only internally(not on a node IP)

Describe alternatives you've considered.

n/a

Additional context.

Looking for some clarity on this ask #4190 (comment)

@abhishekc-92 abhishekc-92 added the enhancement New feature or request label Nov 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant