Skip to content

out_opensearch,in_opensearch: mask hosts in the configuration dump - #193

Merged
Watson1978 merged 1 commit into
mainfrom
fix-secret
Oct 7, 2026
Merged

Watson1978 merged 1 commit into
mainfrom
fix-secret

Conversation

@kenhys

@kenhys kenhys commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Before: hosts accepts "https://user:password@host" and endpoint.url can carry a user and a password, but neither was marked secret. Fluentd logs the whole configuration after configure and masks only secret parameters, so those passwords were written to the log in plain text.

After: hosts in both plugins and endpoint.url are secret, so the dump shows "xxxxxx" for them. The host list no longer appears in the startup log.

@kenhys
kenhys marked this pull request as ready for review September 17, 2026 03:25
Before: `hosts` accepts "https://user:password@host" and `endpoint.url`
can carry a user and a password, but neither was marked secret. Fluentd
logs the whole configuration after configure and masks only secret
parameters, so those passwords were written to the log in plain text.

After: `hosts` in both plugins and `endpoint.url` are secret, so the
dump shows "xxxxxx" for them. The host list no longer appears in the
startup log.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
@kenhys

kenhys commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Rebased with main.

@kenhys
kenhys requested a review from Watson1978 October 7, 2026 01:22

@Watson1978 Watson1978 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏻

@Watson1978
Watson1978 merged commit 9f9ef04 into main Oct 7, 2026
23 checks passed
@Watson1978
Watson1978 deleted the fix-secret branch October 7, 2026 02:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants