docker: find and hide secrets a container printed into its log (hq issue 268)

letta printed two passwords into its log for weeks and nothing noticed,
and docker_logs handed them to whoever asked. docker_secrets_in_logs
compares each container's recent lines with the secret-named values of
its environment, the passwords in its URIs, and any URI carrying a
password, and names what it found by container, module and variable -
never the value. docker_logs redacts the same values before answering.
This commit is contained in:
jochen
2026-10-06 02:13:42 +02:00
parent f9f27d4878
commit bbb67e41a0
7 changed files with 541 additions and 13 deletions
@@ -8,6 +8,7 @@ import (
"os"
"reflect"
"strings"
"sync"
"testing"
"time"
)
@@ -19,6 +20,7 @@ type call struct {
// fake answers each command by the first rule whose prefix matches "name arg arg…".
type fake struct {
mu sync.Mutex
rules []rule
calls []call
}
@@ -31,6 +33,8 @@ type rule struct {
func (f *fake) on(prefix string, r Ran) *fake { f.rules = append(f.rules, rule{prefix, r}); return f }
func (f *fake) run(_ context.Context, name string, args ...string) Ran {
f.mu.Lock()
defer f.mu.Unlock()
f.calls = append(f.calls, call{name, args})
line := strings.Join(append([]string{name}, args...), " ")
for _, r := range f.rules {