Repository navigation
Conversation
|
cc @jason810496, @henry3260. 🙌 |
4acedba to
56d4413
Compare
jason810496
left a comment
There was a problem hiding this comment.
Thanks!
Here's another direction for solving this issue. Would it be better to just mask the sensitive fields (e.g. ApiJWTSecretKey and Issuer for now) instead of hand wiring here (which might cause further drift).
Thx, that makes sense to me. I’ll move the redaction policy next to WorkerConfig by giving it a safe structured log representation, so callers can log the config without duplicating its field mapping. I’ll also update the test to verify that none of those raw values reach the log output. |
Worker logs often have a wider readership than the Edge API signing key. Exposing the key there would let log readers mint authentication tokens for the worker API. Signed-off-by: viiccwen <vicwen@apache.org>
56d4413 to
dc4a8bd
Compare
|
Hello @jason810496, politely tag for further review. |
jason810496
left a comment
There was a problem hiding this comment.
Sorry, as #71874 was merged. We don't need this PR any more. Thanks for your contribution.
Prevent the Go SDK Edge Worker from serializing its complete startup configuration into info-level logs.
The configuration contains the JWT signing key used to authenticate Edge Worker API requests, while process logs are often available to a wider audience than signing material.
Represent the logged configuration with an explicit
slog.LogValuerallowlist containing only the hostname, queues, and retry settings. Keep the log after successful worker construction so a constructor error cannot be followed by dereferencing an unavailable worker logger.Add a regression test that checks the exact safe configuration fields and verifies that the signing secret, its field name, and a credential-bearing API URL never reach the log output.
The approach follows the allowlisted structured-logging pattern used by #68355 for fetched Edge workloads.
Was generative AI tooling used to co-author this PR?
{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.