Aiven-Open/pghoard

[Security] Prometheus

dsever opened this issue · 0 comments

Hi,

I would like to check with community security risks regarding to prometheus. So it is exposed using default web server, but I don't understand for what else this webserver is dedicated to. So my question is there any other kind of risks, or bad things can happen if prometheus is exposed without ACL?

Thanks
Dubravko