Skip to content

fix: keep env values out of calcium logs; warn on options cocoon cannot apply - #758

Merged
CMGS merged 3 commits into
masterfrom
fix/log-opts-cocoon-warn
Sep 29, 2026
Merged

CMGS merged 3 commits into
masterfrom
fix/log-opts-cocoon-warn

Conversation

@CMGS

@CMGS CMGS commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Two small fixes.

Env values in logs. CreateWorkload, CalculateCapacity, RunAndWait and ExecuteWorkload attached the whole options struct as a log field. Deploy and exec env values reached every info and error line, and deploy file contents did too (base64 in the JSON field). The options dump now carries env keys only (DeployOptions.Redacted), and the loggers name the app or the workload ID instead. ReplaceWorkload (which embeds the deploy options, reached by replace and deploy --auto-replace), Send (file contents) and BuildImage (build envs and args) had the same full-options field and now name the app, the target IDs or the image.

cocoon ignores some create options without a trace. cocoon vm create has no flag for env, dns, extra hosts, entrypoint commands or entrypoint dir, so the engine dropped them without any log. It now logs a warning that names them. Core's own APP_NAME/ERU_* env keys move into cluster constants, so the check skips them; the process engine uses the same constant for ERU_POD. Applying these options inside a guest would need cocoon support first (cidata), which is out of scope here.

Verified with a throwaway probe at info level. For replace, send and build: before the change each line carried its secret; after it, none do. For create and exec: before the change, 3 log lines carried the secret env values; after it, none do, and the dump shows Env:[]string{"DEPLOY_TOKEN"}. A cocoon create with core env only logs nothing; one with a deploy env logs cocoon does not apply env to vm <name>.

CreateWorkload, CalculateCapacity, RunAndWait and ExecuteWorkload attached
the whole options struct as a log field, so deploy and exec env values (and
file contents, base64 in JSON) reached every info and error line. The
options dump now carries env keys only, and the loggers name the app or
workload instead.
cocoon vm create has no way to apply env, dns, extra hosts, the entrypoint
commands or its dir, and the engine dropped them without a trace. The
engine now logs a warning naming them. Core's own env keys move into
cluster constants so the check skips what core adds to every workload.
…build logs

ReplaceWorkload, Send and BuildImage attached their whole options as a log
field, so replace env, sent file contents (base64) and build envs and args
reached their info and error lines. The loggers name the app, the target
IDs or the image instead.
@CMGS
CMGS merged commit dde5863 into master Sep 29, 2026
8 of 9 checks passed
@CMGS
CMGS deleted the fix/log-opts-cocoon-warn branch September 29, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant