LokiLogger._log() printed every log line to stdout. decrypt_vault_secrets.py uses stdout to return the decrypted plaintext, and store_secrets_in_vault.sh captures that stdout via command substitution — so the logger's DEBUG lines were captured along with the plaintext and stored in Vault as part of the secret value.
Result: api_key (and any other decrypted field) is written to Vault with four DEBUG log lines prepended to the actual key, e.g. secret/llm/connections/azure_openai/{key}. Any service reading that secret gets an unusable credential.
Fix: route LokiLogger console output to stderr in all three copies of the logger (src/, grafana-configs/, src/vector_indexer/), leaving stdout exclusively for the script's return value. Logs are unaffected — the shell already forwards the Python process's stderr to the cron-manager log stream.
LokiLogger._log() printed every log line to stdout. decrypt_vault_secrets.py uses stdout to return the decrypted plaintext, and store_secrets_in_vault.sh captures that stdout via command substitution — so the logger's DEBUG lines were captured along with the plaintext and stored in Vault as part of the secret value.
Result: api_key (and any other decrypted field) is written to Vault with four DEBUG log lines prepended to the actual key, e.g. secret/llm/connections/azure_openai/{key}. Any service reading that secret gets an unusable credential.
Fix: route LokiLogger console output to stderr in all three copies of the logger (src/, grafana-configs/, src/vector_indexer/), leaving stdout exclusively for the script's return value. Logs are unaffected — the shell already forwards the Python process's stderr to the cron-manager log stream.