feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가 - #178

Merged
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth
Aug 19, 2026
Merged

feat: /actuator/prometheus에 스크레이핑 전용 Basic Auth 추가#178
BcKmini merged 5 commits into
mainfrom
feat/177-prometheus-scrape-auth

Conversation

@BcKmini

@BcKminiBcKmini commented Aug 14, 2026

Copy link
Copy Markdown
Member

요약

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를 스크레이핑하면 401을 받는다 — 지금은 observability & !prod 프로필일 때만 permitAll이라 prod에서는 항상 막힌다(의도된 설계).

/actuator/** 전체가 이미 public ingress로 나가 있어서(k8s/05-ingress.yaml) 그냥 prod에서도 permitAll로 바꾸면 내부 지표가 인증 없이 인터넷에 노출된다. 그래서 스크레이핑 전용 Basic Auth 계정 하나만 추가:

  • SecurityFilterChain(prometheusScrapeAuthSecurityFilterChain, @Profile("!(observability & !prod)"))이 /actuator/prometheus를 담당.
  • app.observability.prometheus-scrape-password(env: PROMETHEUS_SCRAPE_PASSWORD)가 비어 있으면(기본값) 계정 자체를 안 만들고 전부 거부 — "설정 안 하면 막힘"이 기본.
  • 값이 있으면 prometheus 계정의 Basic Auth로만 허용.
  • 로컬 compose.observability.yml 워크플로우(observability 프로필, permitAll)는 그대로 유지.

테스트

  • ./gradlew test 전체: BUILD SUCCESSFUL
  • 신규 PrometheusScrapeAuthIntegrationTest: 무자격 401 / 잘못된 비밀번호 401 / 올바른 자격 200
  • 기존 ServerApplicationTests#prometheusEndpointIsNotPublicWithoutObservabilityProfile(비밀번호 미설정 시 401), PrometheusEndpointIntegrationTest(observability 프로필 permitAll) 모두 그대로 통과

배포 시 필요

server-env Secret에 PROMETHEUS_SCRAPE_PASSWORD 추가 필요 (fowoco/infra의 grafana-admin처럼 git에는 커밋하지 않음). Prometheus 쪽 scrape config에도 같은 값으로 basic_auth 설정 필요 — 별도로 처리.

Closes#177

fowoco/infra#34에서 붙인 클러스터 내부 Prometheus가 /actuator/prometheus를
스크레이핑할 수 있도록, observability 프로필이 아닌 환경(prod 포함)에서도
그 경로만 여는 두 번째 SecurityFilterChain을 추가한다. permitAll이 아니라
app.observability.prometheus-scrape-password로 설정한 계정의 Basic Auth로만
접근 가능 — /actuator/**가 이미 public ingress로 나가 있어서 permitAll은
내부 지표를 인터넷에 그대로 노출시키기 때문이다.
비밀번호를 설정하지 않으면(기본값) 기존과 동일하게 전부 거부 — 로컬/테스트
환경은 지금처럼 observability 프로필의 permitAll 체인을 그대로 쓴다.
Closes#177
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hywznn

Copy link
Copy Markdown
Member

확인했습니다 인프라 Basic Auth 같은 경우는 인프라에서 안쓰는건가요 몰라서 궁금해서 물어봅니다

@hywznn

Copy link
Copy Markdown
Member

최신 main을 PR 브랜치에 반영했습니다. 갱신된 head 기준으로 Server CI와 API·DB 문서 빌드가 모두 성공했습니다. 실제 Prometheus scrape 동작에는 Infra의 PROMETHEUS_SCRAPE_PASSWORD와 동일한 Basic Auth 설정이 함께 필요합니다.

@BcKmini
BcKmini merged commit 477d97f into mainAug 19, 2026
4 checks passed
@BcKmini
BcKmini deleted the feat/177-prometheus-scrape-auth branch August 19, 2026 07:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/actuator/prometheus에 스크레이핑 전용 Basic Auth 추가

2 participants

@BcKmini@hywznn