Improve the Netdata service role (meza/src/roles/netdata/tasks/main.yml) - see what roles exist through Netdata the project, etc. One thing we could do immediately is to add simple auth in HAProxy with some task variables. Also update documentation on how to utilize/incorporate that role. Also ensure that the default is either NOT to expose the service, or at least document that any exposed service could give attackers great visibility into how to attack your infrastructure.
Issue details
Improve the Netdata service role (
meza/src/roles/netdata/tasks/main.yml
) - see what roles exist through Netdata the project, etc. One thing we could do immediately is to add simple auth in HAProxy with some task variables. Also update documentation on how to utilize/incorporate that role. Also ensure that the default is either NOT to expose the service, or at least document that any exposed service could give attackers great visibility into how to attack your infrastructure.