Skip to content

SPIFFE scrape support #702

Open
Open
@kfox1111

Description

@kfox1111

The SPIFFE Workload API can be used to get a tls client key/certificate and keep it up to date (they typically rotate hourly). Exporters can then verify that only the spiffe id associated with Prometheus is able to fetch data from them.

I'm thinking there should be two new options added,
in scrape_config.tls_config, an option added for saying to use spiffe for this target

and an option up at the global section to specify where the spiffeSocketPath

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions