Serve the log at /logs for a collector, off unless an operator turns it on #51

Closed
opened 2026-09-06 15:46:47 +00:00 by tiagoagueda · 0 comments
Owner

Observation

enable "clean" logs collections at /logs endepoint
enabled by end or option on server setting (default:false)

Shape

  • Off by default: POSTULO_LOGS_ENDPOINT_ENABLED (default false) and a switch under
    Server settings → Monitoring, beside the metrics one. Off, the address is a 404.
  • A token, not a session (POSTULO_LOGS_TOKEN): the reader is a collector, not a
    person. With the endpoint on and no token set, it refuses to serve — an unauthenticated
    log endpoint is a data leak with a URL.
  • The shape a collector expects: one JSON object per line, oldest first, with since
    and limit so a scraper can ask only for what it has not seen. No pagination cleverness
    beyond that.
  • "Clean" means something different here than in #50. Metrics can genuinely carry
    nothing personal; a log entry about a failed delivery names the connection and may name
    the application. So the endpoint is off, token-gated, and documented in Hardening as
    personal data leaving the instance.
  • Why an endpoint at all, when the ordinary answer is to read the container's stdout:
    because a self-hoster running Grafana Alloy or Vector elsewhere on their network can
    point it at a URL without arranging log shipping from the host. Anybody who can read
    stdout should keep doing that.

Classification

Enhancement. Not breaking.

Depends on

#49, which decides how Postulo writes and keeps its records.

Open questions

  1. Answer once, or stream? Proposal: answer once. A collector polls, and a streaming
    response ties up a gunicorn worker for as long as it is open.
  2. One Monitoring section holding both switches? Proposal: yes.
## Observation > enable "clean" logs collections at /logs endepoint > enabled by end or option on server setting (default:false) ## Shape - **Off by default**: `POSTULO_LOGS_ENDPOINT_ENABLED` (default false) and a switch under *Server settings → Monitoring*, beside the metrics one. Off, the address is a 404. - **A token, not a session** (`POSTULO_LOGS_TOKEN`): the reader is a collector, not a person. With the endpoint on and no token set, it refuses to serve — an unauthenticated log endpoint is a data leak with a URL. - **The shape a collector expects**: one JSON object per line, oldest first, with `since` and `limit` so a scraper can ask only for what it has not seen. No pagination cleverness beyond that. - **"Clean" means something different here than in #50.** Metrics can genuinely carry nothing personal; a log entry about a failed delivery names the connection and may name the application. So the endpoint is off, token-gated, and documented in *Hardening* as personal data leaving the instance. - **Why an endpoint at all**, when the ordinary answer is to read the container's stdout: because a self-hoster running Grafana Alloy or Vector elsewhere on their network can point it at a URL without arranging log shipping from the host. Anybody who can read stdout should keep doing that. ## Classification Enhancement. Not breaking. ## Depends on #49, which decides how Postulo writes and keeps its records. ## Open questions 1. Answer once, or stream? Proposal: answer once. A collector polls, and a streaming response ties up a gunicorn worker for as long as it is open. 2. One *Monitoring* section holding both switches? Proposal: yes.
tiagoagueda added this to the 0.2.0 milestone 2026-09-06 15:46:47 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Postulo/postulo#51
No description provided.