Skip to content

Exempt GET /metrics from admin API auth - #30

Merged
bartzon merged 2 commits into
v0.9.30-shopify-patchesfrom
bartzon/v0.9.30-admin-metrics-auth-exempt
Sep 15, 2026
Merged

bartzon merged 2 commits into
v0.9.30-shopify-patchesfrom
bartzon/v0.9.30-admin-metrics-auth-exempt

Conversation

@bartzon

@bartzon bartzon commented Sep 8, 2026 •

Copy link
Copy Markdown

Why

We want to set LIBSQL_ADMIN_AUTH_KEY in production (the admin port serves AdminShell — arbitrary SQL on any namespace — and POST /v1/namespaces/:ns/config with jwt_key, i.e. install-your-own-signing-key). Today the key is unset, so auth_middleware in http/admin/mod.rs is a no-op.

Blocker: the middleware is layered onto the merged admin router, which includes GET /metrics, and our chart scrapes metrics on the admin port via prometheus.io/* annotations that cannot attach credentials. Setting the key as-is would 401 every scrape and blind the fleet.

What

GET /metrics bypasses admin auth; every other admin route stays guarded.

The admin listener serves both the admin API and Prometheus metrics.
Annotation-based scraping cannot attach credentials, so guarding
/metrics behind LIBSQL_ADMIN_AUTH_KEY would blind the fleet. Keep
GET /metrics open; all other admin routes remain guarded.
@bartzon bartzon self-assigned this Sep 8, 2026
@bartzon
bartzon marked this pull request as ready for review September 8, 2026 12:39
@bartzon
bartzon requested a review from a team September 8, 2026 12:40
The Extensions Tests job fresh-resolves rust_suite deps on every run;
icu 2.3.0 (via idna_adapter 1.2) now requires rustc 1.88 while the
repo pins 1.85.0, failing CI on any branch of this tag. Pinning
idna_adapter to 1.1.0 (unicode-rs backend) drops icu from the graph.
@@ -0,0 +1,2550 @@
# This file is automatically @generated by Cargo.
# It is not intended for manual editing.
version = 4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How come this lock was not present before 🤔

@bartzon

bartzon commented Sep 14, 2026

Copy link
Copy Markdown
Author

/merge

@sle-c

sle-c commented Sep 14, 2026

Copy link
Copy Markdown

@bartzon you can click Merge pull request on this PR, it doesn't support the merge queue

@bartzon
bartzon merged commit 856b4d2 into v0.9.30-shopify-patches Sep 15, 2026
23 of 24 checks passed
@RaVbaker

Copy link
Copy Markdown

I think it deserves to backport it to https://github.com/tursodatabase/libsql

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants