Skip to content

Fix LokiLogger console output to stdout, corrupting decrypted Vault secrets #514

Description

@PaulaMerle

LokiLogger._log() printed every log line to stdout. decrypt_vault_secrets.py uses stdout to return the decrypted plaintext, and store_secrets_in_vault.sh captures that stdout via command substitution — so the logger's DEBUG lines were captured along with the plaintext and stored in Vault as part of the secret value.

Result: api_key (and any other decrypted field) is written to Vault with four DEBUG log lines prepended to the actual key, e.g. secret/llm/connections/azure_openai/{key}. Any service reading that secret gets an unusable credential.

Fix: route LokiLogger console output to stderr in all three copies of the logger (src/, grafana-configs/, src/vector_indexer/), leaving stdout exclusively for the script's return value. Logs are unaffected — the shell already forwards the Python process's stderr to the cron-manager log stream.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

  • Status
    Merged to WIP

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions