prometheus operator v0.93.1

PrometheusAgent.spec.containers.startupProbe.httpGet.httpHeaders.spec.arbitraryFSAccessThroughSMs

arbitraryFSAccessThroughSMs when true, ServiceMonitor, PodMonitor and Probe object are forbidden to reference arbitrary files on the file system of the 'prometheus' container. When a ServiceMonitor's endpoint specifies a `bearerTokenFile` value (e.g. '/var/run/secrets/kubernetes.io/serviceaccount/token'), a malicious target can get access to the Prometheus service account's token in the Prometheus' scrape request. Setting `spec.arbitraryFSAccessThroughSM` to 'true' would prevent the attack. Users should instead provide the credentials using the `spec.bearerTokenSecret` field.

1 fields
PrometheusAgent.spec.containers.startupProbe.httpGet.httpHeaders.spec.arbitraryFSAccessThroughSMs fields and descriptions
Field / TypeDescription
deny
boolean

deny prevents service monitors from accessing arbitrary files on the file system. When true, service monitors cannot use file-based configurations like BearerTokenFile that could potentially access sensitive files. When false (default), such access is allowed. Setting this to true enhances security by preventing potential credential theft attacks.