-
Task
-
Resolution: Done
-
Undefined
-
None
-
None
-
False
-
False
-
NEW
-
NEW
-
-
Sprint 214
kube-rbac-proxy currently protects the /metric endpoint in the prometheus-operator.
The operator is deployed as a TLS enabled server, and its metrics endpoint is scraped by Prometheus through kube-rbac-proxy over mTLS.
This task is to investigate the removal of kube-rbac-proxy entirely since the current setup allows anyone to query other endpoints from any pod in the cluster
For example, the following will return a 200 response.
- is blocked by
-
MON-2221 Deploy validating webhook in HA fashion
- Closed
- links to