LOGBOOK

HELP

Quiz Entry - updated: 2026.10.01

What does --web.listen-address=0.0.0.0:9090 do, and is it a sensible setting?

Prometheus listens on port 9090 on all network interfaces, so anyone who can reach the host can open the web UI and API. That's fine in an isolated lab but risky in production, because there is no authentication by default.

Top: bound to 0.0.0.0, both a local process via lo and anyone on the network via eth0 reach Prometheus without authentication. Bottom: bound to 127.0.0.1, only the local process gets through and network connections are refused

* 0.0.0.0 opens every interface; 127.0.0.1 keeps it local. *

0.0.0.0 means "every IPv4 address of this machine": loopback, LAN, any other interface. The alternative 127.0.0.1:9090 would accept only local connections.

Why it is a judgement call:

  • For: Grafana or other Prometheus servers on other hosts need to reach the API, and admins want the UI in their browser.
  • Against: out of the box the UI and API have no login and no TLS. Anyone on the network can read every metric (host names, versions, internal topology), which is useful reconnaissance for an attacker.

Sensible production options: restrict access with a firewall to the hosts that need it, bind to localhost behind a reverse proxy that adds TLS and authentication, or configure Prometheus's own TLS and basic-auth via --web.config.file. Any active firewall must allow 9090/tcp.

Go deeper:

From Quiz: ITIA / Monitoring Lab: Prometheus and Grafana | Updated: Oct 01, 2026