
Prometheus
Protect access to Prometheus metrics and administration as an upstream web application.
Overview
Prometheus is a monitoring and alerting system with a web interface and HTTP API, normally on port 9090. It also has scrape, remote read, remote write, and automation flows that do not use an interactive browser.
Prometheus can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Prometheus. Prometheus remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Separate human query access from scrape, remote-write, and automation endpoints when their authentication model differs. Keep Prometheus web TLS and authentication active.
Example
Operators query a private Prometheus interface through Pomerium. Scrapers, Grafana, and remote clients use a separate compatible machine path. Prometheus keeps its TLS and authentication settings when enabled.
Considerations
- Prometheus documents that mutating endpoints lack CSRF protection. Do not expose them without a reviewed control model.
- Scrapers, remote clients, Grafana, and automation need noninteractive access.
