🔒 Security: Enable authentication for /metrics endpoint by default

Fixes #24530 - /metrics endpoint exposed multi-tenant PII

Changes:
- Changed require_auth_for_metrics_endpoint default from False to True
- Updated middleware documentation to reflect secure-by-default behavior

Breaking Change:
⚠️ This is a breaking change. Users who want unauthenticated /metrics
must now explicitly set require_auth_for_metrics_endpoint: false

Security Impact:
- Prevents unauthorized access to multi-tenant PII
- CVSS 7.5 (High) vulnerability
- Exposed data: team_alias, user emails, client IPs, user agents
This commit is contained in:
zhaog100 2026-03-31 22:01:10 -07:00
parent d1df4e838b
commit 668a90e021
2 changed files with 4 additions and 5 deletions

View file

@ -164,7 +164,7 @@ initialized_langfuse_clients: int = 0
langfuse_default_tags: Optional[List[str]] = None
langsmith_batch_size: Optional[int] = None
prometheus_initialize_budget_metrics: Optional[bool] = False
require_auth_for_metrics_endpoint: Optional[bool] = False
require_auth_for_metrics_endpoint: Optional[bool] = True # Security: Require auth by default (fixes #24530)
argilla_batch_size: Optional[int] = None
datadog_use_v1: Optional[bool] = False # if you want to use v1 datadog logged payload.
gcs_pub_sub_use_v1: Optional[

View file

@ -18,13 +18,12 @@ class PrometheusAuthMiddleware:
"""
Middleware to authenticate requests to the metrics endpoint.
By default, auth is not run on the metrics endpoint.
Enabled by setting the following in proxy_config.yaml:
By default, auth IS RUN on the metrics endpoint (secure by default).
To disable auth (not recommended for production):
```yaml
litellm_settings:
require_auth_for_metrics_endpoint: true
require_auth_for_metrics_endpoint: false
```
"""