supabase: keep logflare's API key out of its log (hq issue 268)
vector handed logflare its API key as ?api_key= in every sink URL, and logflare 1.4.0 prints a failed request's whole URL in its Plug.Cowboy error report. Its ingest fails on every request here, so the key was in the analytics log about every ten seconds. The report is an error, so no log level hides it. Every sink now sends the key in the x-api-key header, which logflare reads first. A start script refuses to start logflare while the vector config it is given still puts the key in a URL. The key is marked "applied", not "at-start": logflare writes it into its default user once and never updates it, so the mesh must not rotate it by restarting.
This commit is contained in:
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user