-
-
Notifications
You must be signed in to change notification settings - Fork 223
Closed as not planned
Labels
area/auditstatus/invalidThis doesn't seem rightThis doesn't seem rightstatus/triage/completedAutomatic triage completedAutomatic triage completedstatus/triage/manualManual triage in progressManual triage in progress
Description
Describe the bug (actual behavior)
Audit log functionality is currently being enabled by using host variables. This practice could introduce security or configuration risks, as audit logging should be controlled via explicit and secure configuration methods rather than generic host variables.
Expected behavior
Audit log configuration should be managed through dedicated, secure, and explicit configuration options rather than being tied to host variables.
Your installation details
- App version: [please specify]
- Helm chart version: [if applicable, please specify]
- Application config: [please provide relevant config, redact sensitive info]
- IAAC configs: [if applicable, please provide]
Steps to reproduce
- Enable audit log using a host variable.
- Observe that audit logging is controlled by this variable rather than explicit configuration settings.
Screenshots
[add if applicable]
Logs
[add if applicable]
Additional context
This behavior may pose a security or configuration risk. Please review and consider enhancing the audit log configuration for improved security and clarity.
Metadata
Metadata
Assignees
Labels
area/auditstatus/invalidThis doesn't seem rightThis doesn't seem rightstatus/triage/completedAutomatic triage completedAutomatic triage completedstatus/triage/manualManual triage in progressManual triage in progress