Bug 1994251

Summary: [RFE][GSS] Need ssl between node-exporter, Prometheus and mgr module
Product: [Red Hat Storage] Red Hat Ceph Storage Reporter: Lijo Stephen Thomas <lithomas>
Component: CephadmAssignee: Redouane Kachach Elhichou <rkachach>
Status: POST --- QA Contact: Sunil Angadi <sangadi>
Severity: medium Docs Contact:
Priority: high    
Version: 5.0CC: adking, ceph-eng-bugs, dwojewod, flucifre, jolmomar, mhackett, mmuench, rkachach, sangadi, saraut
Target Milestone: ---Keywords: FutureFeature
Target Release: 7.0   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Lijo Stephen Thomas 2021-08-17 07:01:38 UTC
Description of problem:
Customer needs ssl between node-exporter, mgr module and Prometheus.


Version-Release number of selected component (if applicable):
RHCS 5.x

Additional info:
As we do not have such capability, we would like to have this in future RHCS 5.x releases

Comment 3 Juan Miguel Olmo 2021-09-07 10:15:36 UTC
Rook part:
==========

I am currently working in bringing the complete monitoring stack we are using in baremetal installations to the k8s world:

https://github.com/rook/rook/issues/6519

Prometheus and Alert manager:
Deployed using the Prometheus operator (still in Beta) and both of them support TLS.
https://github.com/prometheus-operator/prometheus-operator

Node exporter
Deployed as a daemonset in k8s using the Node exporter built-in TLS feature

Grafana:
Deployed using grafana operator but using the Grafana built-in TLS feature
https://github.com/grafana-operator/grafana-operator


Prometheus manager module:
As Ernesto has pointed .. needed to implement the TLS support.

Comment 10 Ernesto Puerta 2021-12-13 19:33:03 UTC
*** Bug 2028338 has been marked as a duplicate of this bug. ***

Comment 24 Redouane Kachach Elhichou 2023-01-09 09:43:39 UTC
The following PR (Under review on Upstream) introduces several security enhancements related to monitoring:

https://github.com/ceph/ceph/pull/46601