Getting Security Policy : frame-ancestors error , please suggest

15 views
Skip to first unread message

sunils...@gmail.com

unread,
Aug 5, 2020, 12:54:25 PM8/5/20
to Prometheus Users
Hi All, 

In our current setup Prometheus is non-ssl configured , which means I am accessing Prometheus as http://server-name:9090

During our recent Security scan below details were reported . Please advise , what step I can take for this . 

Message : 
X-Frame-Options or Content-Security-Policy: frame-ancestors HTTP Headers missing on port 9090.

Please advise , 
Thanks 

Stuart Clark

unread,
Aug 5, 2020, 1:36:25 PM8/5/20
to sunils...@gmail.com, Prometheus Users
You can run a reverse proxy (e.g. nginx) in front of Prometheus to add
TLS, authentication or any HTTP headers you wish...


sunil sagar

unread,
Aug 5, 2020, 3:02:35 PM8/5/20
to Stuart Clark, Prometheus Users
Hi Stuart ,

Thank you for help on this . One thing I forgot to mention . We have Thanos also in front of Prometheus , will it impact if enable SSL ?

Thanks


> On 6 Aug 2020, at 1:36 AM, Stuart Clark <stuart...@jahingo.com> wrote:
Reply all
Reply to author
Forward
0 new messages