is there any way to turn off the /metrics endpoint...
# fleet
j
is there any way to turn off the /metrics endpoint? we don't want that data exposed, and it's available without going through SSO
z
Typically folks will front Fleet with a proxy that handles exposing/not exposing particular endpoints. Check out https://defensivedepth.com/2020/04/02/kolide-fleet-breaking-out-the-osquery-api-web-ui/ for some guidance on that.