Logstash HTTP Input and Monitoring API binding without authentication boundary
Goal is to avoid accidental public access to Logstash HTTP Input and the monitoring API while keeping local development usable. The HTTP Input plugin binds to all interfaces when host is unspecified and does not provide built-in authentication. The monitoring API for metrics and pipeline management is enabled by default and is unauthenticated in standard OSS