Serve the log at /logs for a collector, off unless an operator turns it on #51
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
#49 Read the log from the administration area
Postulo/postulo
Reference
Postulo/postulo#51
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Shape
POSTULO_LOGS_ENDPOINT_ENABLED(default false) and a switch underServer settings → Monitoring, beside the metrics one. Off, the address is a 404.
POSTULO_LOGS_TOKEN): the reader is a collector, not aperson. With the endpoint on and no token set, it refuses to serve — an unauthenticated
log endpoint is a data leak with a URL.
sinceand
limitso a scraper can ask only for what it has not seen. No pagination clevernessbeyond that.
nothing personal; a log entry about a failed delivery names the connection and may name
the application. So the endpoint is off, token-gated, and documented in Hardening as
personal data leaving the instance.
because a self-hoster running Grafana Alloy or Vector elsewhere on their network can
point it at a URL without arranging log shipping from the host. Anybody who can read
stdout should keep doing that.
Classification
Enhancement. Not breaking.
Depends on
#49, which decides how Postulo writes and keeps its records.
Open questions
response ties up a gunicorn worker for as long as it is open.