Eight S3 metric families are labelled with bucket names, so serving the
shared registry on the client-facing S3 listener lets any client that can
reach the port enumerate buckets and their traffic, with no IAM check.
S3 already has a dedicated -metricsPort for this.
Master, volume and filer keep the route: they are internal cluster
services and their metrics carry no tenant identifiers.