Skip to content

Go SDK: Prevent Edge Worker config secrets from reaching logs - #69920

Closed
viiccwen wants to merge 1 commit into
apache:mainfrom
viiccwen:fix-go-sdk-config-secret-logging
Closed

viiccwen wants to merge 1 commit into
apache:mainfrom
viiccwen:fix-go-sdk-config-secret-logging

Conversation

@viiccwen

@viiccwen viiccwen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Prevent the Go SDK Edge Worker from serializing its complete startup configuration into info-level logs.
The configuration contains the JWT signing key used to authenticate Edge Worker API requests, while process logs are often available to a wider audience than signing material.

Represent the logged configuration with an explicit slog.LogValuer allowlist containing only the hostname, queues, and retry settings. Keep the log after successful worker construction so a constructor error cannot be followed by dereferencing an unavailable worker logger.

Add a regression test that checks the exact safe configuration fields and verifies that the signing secret, its field name, and a credential-bearing API URL never reach the log output.

The approach follows the allowlisted structured-logging pattern used by #68355 for fetched Edge workloads.


Was generative AI tooling used to co-author this PR?
  • Yes - GPT-5.6 Sol

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

@viiccwen

Copy link
Copy Markdown
Contributor Author

cc @jason810496, @henry3260. 🙌

@viiccwen
viiccwen force-pushed the fix-go-sdk-config-secret-logging branch 2 times, most recently from 4acedba to 56d4413 Compare July 16, 2026 12:05

@jason810496 jason810496 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

Here's another direction for solving this issue. Would it be better to just mask the sensitive fields (e.g. ApiJWTSecretKey and Issuer for now) instead of hand wiring here (which might cause further drift).

@viiccwen

Copy link
Copy Markdown
Contributor Author

Thanks!

Here's another direction for solving this issue. Would it be better to just mask the sensitive fields (e.g. ApiJWTSecretKey and Issuer for now) instead of hand wiring here (which might cause further drift).

Thx, that makes sense to me. I’ll move the redaction policy next to WorkerConfig by giving it a safe structured log representation, so callers can log the config without duplicating its field mapping.

I’ll also update the test to verify that none of those raw values reach the log output.

Worker logs often have a wider readership than the Edge API signing key. Exposing the key there would let log readers mint authentication tokens for the worker API.

Signed-off-by: viiccwen <vicwen@apache.org>
@viiccwen
viiccwen force-pushed the fix-go-sdk-config-secret-logging branch from 56d4413 to dc4a8bd Compare July 20, 2026 09:18
@viiccwen

viiccwen commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

Hello @jason810496, politely tag for further review.

@jason810496 jason810496 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, as #71874 was merged. We don't need this PR any more. Thanks for your contribution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants