Bug 1994251 - [RFE][GSS] Need ssl between node-exporter, Prometheus and mgr module
Summary: [RFE][GSS] Need ssl between node-exporter, Prometheus and mgr module
Keywords:
Status: POST
Alias: None
Product: Red Hat Ceph Storage
Classification: Red Hat Storage
Component: Cephadm
Version: 5.0
Hardware: x86_64
OS: Linux
high
medium
Target Milestone: ---
: 7.0
Assignee: Redouane Kachach Elhichou
QA Contact: Sunil Angadi
URL:
Whiteboard:
: 2028338 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-08-17 07:01 UTC by Lijo Stephen Thomas
Modified: 2023-08-15 13:50 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHCEPH-719 0 None None None 2021-08-17 07:02:37 UTC

Internal Links: 2028335

Description Lijo Stephen Thomas 2021-08-17 07:01:38 UTC
Description of problem:
Customer needs ssl between node-exporter, mgr module and Prometheus.


Version-Release number of selected component (if applicable):
RHCS 5.x

Additional info:
As we do not have such capability, we would like to have this in future RHCS 5.x releases

Comment 3 Juan Miguel Olmo 2021-09-07 10:15:36 UTC
Rook part:
==========

I am currently working in bringing the complete monitoring stack we are using in baremetal installations to the k8s world:

https://github.com/rook/rook/issues/6519

Prometheus and Alert manager:
Deployed using the Prometheus operator (still in Beta) and both of them support TLS.
https://github.com/prometheus-operator/prometheus-operator

Node exporter
Deployed as a daemonset in k8s using the Node exporter built-in TLS feature

Grafana:
Deployed using grafana operator but using the Grafana built-in TLS feature
https://github.com/grafana-operator/grafana-operator


Prometheus manager module:
As Ernesto has pointed .. needed to implement the TLS support.

Comment 10 Ernesto Puerta 2021-12-13 19:33:03 UTC
*** Bug 2028338 has been marked as a duplicate of this bug. ***

Comment 24 Redouane Kachach Elhichou 2023-01-09 09:43:39 UTC
The following PR (Under review on Upstream) introduces several security enhancements related to monitoring:

https://github.com/ceph/ceph/pull/46601


Note You need to log in before you can comment on or make changes to this bug.