Skip to main content
See All Integrations

Prometheus

Protect access to Prometheus metrics and administration as an upstream web application.

Standard protected service pattern

Categories
Monitoring and Observability, Upstream Applications

Overview

Prometheus is a monitoring and alerting system with a web interface and HTTP API, normally on port 9090. It also has scrape, remote read, remote write, and automation flows that do not use an interactive browser.

Prometheus can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Prometheus. Prometheus remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.

Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.

Separate human query access from scrape, remote-write, and automation endpoints when their authentication model differs. Keep Prometheus web TLS and authentication active.

Example

Operators query a private Prometheus interface through Pomerium. Scrapers, Grafana, and remote clients use a separate compatible machine path. Prometheus keeps its TLS and authentication settings when enabled.

Considerations

  • Prometheus documents that mutating endpoints lack CSRF protection. Do not expose them without a reviewed control model.
  • Scrapers, remote clients, Grafana, and automation need noninteractive access.

Sources and official resources

  • Protect access to Grafana Loki HTTP endpoints as upstream web applications.

  • Protect access to Kibana dashboards and administration as an upstream web application.

  • Protect the Elasticsearch HTTP API while keeping cluster transport traffic on the private network.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo