Exempt GET /metrics from admin API auth - #30
Merged
bartzon merged 2 commits intoSep 15, 2026
Merged
Conversation
The admin listener serves both the admin API and Prometheus metrics. Annotation-based scraping cannot attach credentials, so guarding /metrics behind LIBSQL_ADMIN_AUTH_KEY would blind the fleet. Keep GET /metrics open; all other admin routes remain guarded.
The Extensions Tests job fresh-resolves rust_suite deps on every run; icu 2.3.0 (via idna_adapter 1.2) now requires rustc 1.88 while the repo pins 1.85.0, failing CI on any branch of this tag. Pinning idna_adapter to 1.1.0 (unicode-rs backend) drops icu from the graph.
jd-erreape
reviewed
Sep 14, 2026
| @@ -0,0 +1,2550 @@ | |||
| # This file is automatically @generated by Cargo. | |||
| # It is not intended for manual editing. | |||
| version = 4 | |||
There was a problem hiding this comment.
How come this lock was not present before 🤔
jd-erreape
approved these changes
Sep 14, 2026
Author
|
/merge |
|
@bartzon you can click Merge pull request on this PR, it doesn't support the merge queue |
|
I think it deserves to backport it to https://github.com/tursodatabase/libsql |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
We want to set
LIBSQL_ADMIN_AUTH_KEYin production (the admin port serves AdminShell — arbitrary SQL on any namespace — andPOST /v1/namespaces/:ns/configwithjwt_key, i.e. install-your-own-signing-key). Today the key is unset, soauth_middlewareinhttp/admin/mod.rsis a no-op.Blocker: the middleware is layered onto the merged admin router, which includes
GET /metrics, and our chart scrapes metrics on the admin port viaprometheus.io/*annotations that cannot attach credentials. Setting the key as-is would 401 every scrape and blind the fleet.What
GET /metricsbypasses admin auth; every other admin route stays guarded.