mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
🔒 Security: Remove PII labels from Prometheus metrics & add warning
Phase 2: Sanitize PII labels - Removed team_alias (contains company names and employee emails) - Removed user_email (contains email addresses) - Removed client_ip (contains client IP addresses) - Removed user_agent (contains workflow IDs and infrastructure info) Phase 3: Add startup warning - Added security warning when /metrics is exposed without auth - Warns about PII exposure risk - Suggests enabling require_auth_for_metrics_endpoint These changes complement Phase 1 (default auth) to provide defense in depth: 1. Auth by default prevents unauthorized access 2. Sanitized labels reduce PII exposure even if auth is disabled 3. Startup warning alerts operators to security risk
This commit is contained in:
parent
668a90e021
commit
d3d31dea85
2 changed files with 13 additions and 4 deletions
|
|
@ -3429,6 +3429,14 @@ class PrometheusLogger(CustomLogger):
|
|||
from litellm._logging import verbose_proxy_logger
|
||||
from litellm.proxy.proxy_server import app
|
||||
|
||||
# Security warning for metrics endpoint (fixes #24530)
|
||||
if not litellm.require_auth_for_metrics_endpoint:
|
||||
verbose_proxy_logger.warning(
|
||||
"⚠️ SECURITY WARNING: /metrics endpoint is exposed without authentication. "
|
||||
"This may leak multi-tenant PII including team aliases, user emails, client IPs, and user agents. "
|
||||
"Set 'require_auth_for_metrics_endpoint: true' in litellm_settings to enable authentication."
|
||||
)
|
||||
|
||||
# Create metrics ASGI app
|
||||
if "PROMETHEUS_MULTIPROC_DIR" in os.environ:
|
||||
from prometheus_client import CollectorRegistry, multiprocess
|
||||
|
|
|
|||
|
|
@ -334,13 +334,14 @@ class PrometheusMetricLabels:
|
|||
UserAPIKeyLabelNames.API_KEY_ALIAS.value,
|
||||
UserAPIKeyLabelNames.REQUESTED_MODEL.value,
|
||||
UserAPIKeyLabelNames.TEAM.value,
|
||||
UserAPIKeyLabelNames.TEAM_ALIAS.value,
|
||||
# Security: Removed PII labels (fixes #24530)
|
||||
# UserAPIKeyLabelNames.TEAM_ALIAS.value, # Contains company names and employee emails
|
||||
UserAPIKeyLabelNames.USER.value,
|
||||
UserAPIKeyLabelNames.STATUS_CODE.value,
|
||||
UserAPIKeyLabelNames.USER_EMAIL.value,
|
||||
# UserAPIKeyLabelNames.USER_EMAIL.value, # Contains email addresses
|
||||
UserAPIKeyLabelNames.ROUTE.value,
|
||||
UserAPIKeyLabelNames.CLIENT_IP.value,
|
||||
UserAPIKeyLabelNames.USER_AGENT.value,
|
||||
# UserAPIKeyLabelNames.CLIENT_IP.value, # Contains client IP addresses
|
||||
# UserAPIKeyLabelNames.USER_AGENT.value, # Contains workflow IDs and infrastructure info
|
||||
UserAPIKeyLabelNames.MODEL_ID.value,
|
||||
]
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue