Session

Secure your Prometheus server from indiscreet eyes or die by metrics

Prometheus has become the standard for monitoring Kubernetes services. It comes with a set of helpful exporters, and Kubernetes offers several metrics endpoints directly through the API. These features enable monitoring and troubleshooting of most situations that SREs face on a daily basis. But, what if an attacker accesses your Prometheus server? How much information can they get for fingerprinting the cluster? Kernel versions, IP addresses, instance types, library versions…the list goes on and on.

In this session, you will learn the best practices on how to secure your Prometheus server from curious eyes and what could be the consequences of not implementing them.

Miguel Hernández

Staff Threat Researcher Engineer - Sysdig

Zaragoza, Spain

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top