Allow providers to provide Redacted values for agent diagnostics #6964
Labels
enhancement
New feature or request
Team:Elastic-Agent-Control-Plane
Label for the Agent Control Plane team
Describe the enhancement:
As of today, provider variables that are part of the elastic-agent configuration are captured inside the
computed-config.yaml
of an agent diagnostics with their plain resolved value. However for certain providers, such askubernetes_secrets
this results in "leaking" the secret value in the diagnostics. Instead of that, it would be more correct if these values were redacted by the provider itself. In this way the provider could take part in the diagnostics generation phase and instead of rendering the secret value it could render the secret resource version instead for the case ofkubernetes_secrets
Describe a specific use case for the enhancement or feature:
kubernetes_secrets
(and any other provider that deals with sensitive values) could redact properly such values from diagnosticsWhat is the definition of done?
When sensitive values that originate from provider variables can be redacted from the diagnostics.
The text was updated successfully, but these errors were encountered: