dask-gateway icon indicating copy to clipboard operation
dask-gateway copied to clipboard

Limit access to scheduler dashboards to authenticated users

Open olivier-lacroix opened this issue 2 years ago • 0 comments

Hello,

I have successfully proxied dask-gateway through Jupyterhub, (ala daskhub, with traefik ingress being of type CLusterIP) and dask scheduler dashboards are available on URLs of the type

https://my-domain.com/services/dask-gateway/clusters/xxx.yyy/status

Such URLs seem to be publicly accessible: is this intended? the URLs are hard to guess, but shouldn't dask-gateway only allow users authenticated to jupyterhub to connect to the dashboards?

Thanks in advance

Olivier

olivier-lacroix avatar Jun 06 '22 00:06 olivier-lacroix