Uploaded image for project: 'OpenShift Cloud'
  1. OpenShift Cloud
  2. OCPCLOUD-2277

Ensure Cluster Machine Approver metrics are only available via HTTPS

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • CLOUD Sprint 245

      Background

      CMA currently exposes metrics on two ports via the 0.0.0.0 all hosts binding. We need to make sure that only the TLS port is accessible from outside localhost.

      Steps

      • Move the binding for the local metrics server to localhost only
      • Ensure kube-rbac-proxy is still proxying the requests over TLS

      Stakeholders

      • Cluster Infra
      • Subin M

      Definition of Done

      • Metrics from CMA are only exposed over TLS
      • Docs
      • <Add docs requirements for this card>
      • Testing
      • <Explain testing that will be added>

            raryan@redhat.com Rachel Ryan
            joelspeed Joel Speed
            Milind Yadav Milind Yadav
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: