Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow providers to provide Redacted values for agent diagnostics #6964

Open
pkoutsovasilis opened this issue Feb 21, 2025 · 1 comment
Open
Labels
enhancement New feature or request Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team

Comments

@pkoutsovasilis
Copy link
Contributor

Describe the enhancement:

As of today, provider variables that are part of the elastic-agent configuration are captured inside the computed-config.yaml of an agent diagnostics with their plain resolved value. However for certain providers, such as kubernetes_secrets this results in "leaking" the secret value in the diagnostics. Instead of that, it would be more correct if these values were redacted by the provider itself. In this way the provider could take part in the diagnostics generation phase and instead of rendering the secret value it could render the secret resource version instead for the case of kubernetes_secrets

Describe a specific use case for the enhancement or feature:

kubernetes_secrets (and any other provider that deals with sensitive values) could redact properly such values from diagnostics

What is the definition of done?

When sensitive values that originate from provider variables can be redacted from the diagnostics.

@pkoutsovasilis pkoutsovasilis added enhancement New feature or request Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team labels Feb 21, 2025
@elasticmachine
Copy link
Contributor

Pinging @elastic/elastic-agent-control-plane (Team:Elastic-Agent-Control-Plane)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team
Projects
None yet
Development

No branches or pull requests

2 participants