Overview
Monitoring security encompasses agent authentication via per-node tokens, dashboard access control through Polystack identity roles, and TLS certificate lifecycle management for all platform communications.Agent Authentication
Each Monitoring agent authenticates to the collector using a unique per-node token. Rotate tokens periodically and immediately when a node is decommissioned or suspected compromised.- Token Lifecycle
- Token Rotation Procedure
Generate a new agent token
List all agent tokens with expiry
Revoke an agent token
Dashboard Access Control
Monitoring dashboard access is controlled through Polystack identity roles. Assign roles based on job function to enforce least-privilege access.
Assign roles through the deployment console → Identity → Role Assignments.
TLS Configuration
All Monitoring communication uses TLS:- Agent-to-collector: TLS 1.3 minimum
- Dashboard and API: TLS 1.3 minimum, HSTS enabled
- Internal service communication: mTLS for collector-to-store traffic
- Certificate Status
- Manual Renewal
Check all certificate expiry dates
Next Steps
Agent Configuration
Deploy and configure agents whose tokens are managed here
Alert Channels
Secure notification channel credentials and SMTP authentication
Troubleshooting
Diagnose TLS and authentication errors
Polystack Identity
Manage the Polystack identity roles used for Monitoring access control
