You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@apisix.apache.org by GitBox <gi...@apache.org> on 2020/10/20 09:41:55 UTC

[GitHub] [apisix] Miss-you edited a comment on issue #2362: prometheus plugin publicly exposes metrics, even if not enabled

Miss-you edited a comment on issue #2362:
URL: https://github.com/apache/apisix/issues/2362#issuecomment-712728248


   Hi, thanks for the advice.
   The Prometheus metrics usually use another port to expose the service instead of a business port, such as controller, scheduler, ingress, etc., which is a new non-business port to expose the service.
   
   Currently, Apache APISIX uses the 80/443 port to expose the metrics service, which is unreasonable and may have information leakage risk, but I suggest to merge it into the Apache APISIX project as a feature after full discussion of the technical solution.
   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org