TLS security for GitLab Pages metrics endpoints
Refer &7479 (closed)
GitLab components report metrics via Prometheus, and sometimes start a pprof listener to aid live profiling. Either of these may be open and listening when running GitLab in production, as they are on GitLab.com
- Inventory which endpoints report to Prometheus
- Determine of those endpoints are already or can be TLS-secured
- Secure each unsecured endpoint
~"devops::release" ~"group::release" Category:Pages
Edited by Sean Carroll