From a4e5755560ae7aeefb9244933ab722c0d778ff0b Mon Sep 17 00:00:00 2001 From: Chris Lu Date: Mon, 14 Sep 2026 22:21:40 -0700 Subject: [PATCH] s3: do not serve /metrics on the tenant-facing API port Eight S3 metric families are labelled with bucket names, so serving the shared registry on the client-facing S3 listener lets any client that can reach the port enumerate buckets and their traffic, with no IAM check. S3 already has a dedicated -metricsPort for this. Master, volume and filer keep the route: they are internal cluster services and their metrics carry no tenant identifiers. --- weed/s3api/s3api_server.go | 3 --- 1 file changed, 3 deletions(-) diff --git a/weed/s3api/s3api_server.go b/weed/s3api/s3api_server.go index c12290c41..baefc8218 100644 --- a/weed/s3api/s3api_server.go +++ b/weed/s3api/s3api_server.go @@ -16,7 +16,6 @@ import ( "time" "github.com/gorilla/mux" - "github.com/prometheus/client_golang/prometheus/promhttp" "google.golang.org/grpc" "github.com/seaweedfs/seaweedfs/weed/cluster" @@ -34,7 +33,6 @@ import ( . "github.com/seaweedfs/seaweedfs/weed/s3api/s3_constants" "github.com/seaweedfs/seaweedfs/weed/s3api/s3err" "github.com/seaweedfs/seaweedfs/weed/security" - stats_collect "github.com/seaweedfs/seaweedfs/weed/stats" "github.com/seaweedfs/seaweedfs/weed/util" "github.com/seaweedfs/seaweedfs/weed/util/chunk_cache" "github.com/seaweedfs/seaweedfs/weed/util/grace" @@ -790,7 +788,6 @@ func (s3a *S3ApiServer) registerRouter(router *mux.Router) { apiRouter.Methods(http.MethodGet, http.MethodHead).Path("/status").HandlerFunc(s3a.StatusHandler) apiRouter.Methods(http.MethodGet, http.MethodHead).Path("/healthz").HandlerFunc(s3a.StatusHandler) apiRouter.Methods(http.MethodGet, http.MethodHead).Path("/readyz").HandlerFunc(s3a.StatusHandler) - apiRouter.Methods(http.MethodGet).Path("/metrics").Handler(promhttp.HandlerFor(stats_collect.Gather, promhttp.HandlerOpts{})) // Object path pattern with (?s) flag to match newlines in object keys const objectPath = "/{object:(?s).+}"