Skip to content

[k8s-keystone-auth] Don't log tokens - #3164

Open
stephenfin wants to merge 1 commit into
kubernetes:masterfrom
shiftstack:stop-logging-tokens
Open

[k8s-keystone-auth] Don't log tokens#3164
stephenfin wants to merge 1 commit into
kubernetes:masterfrom
shiftstack:stop-logging-tokens

Conversation

@stephenfin

Copy link
Copy Markdown
Member

What this PR does / why we need it:

The Keystone authentication webhook handler writes the raw bearer token submitted in every TokenReview to the log stream when verbosity is 4 or higher. It is pretty common to set this level (-v=4) while e.g. debugging. Additionally, it is common for logs to be sent to a central store, with different access controls than the main cluster. A user with access to this store can use the captured token for replay attacks for any user that authenticates against the cluster until the token's TTL.

Stop logging the token and avoid all of this. The combo of user, any error and the usual timestamp etc. should be more than sufficient.

Which issue this PR fixes(if applicable):

(none)

Special notes for reviewers:

Release note:

NONE

The Keystone authentication webhook handler writes the raw bearer token
submitted in every TokenReview to the log stream when verbosity is 4 or
higher. It is pretty common to set this level (-v=4) while e.g.
debugging. Additionally, it is common for logs to be sent to a central
store, with different access controls than the main cluster. A user with
access to this store can use the captured token for replay attacks for
any user that authenticates against the cluster until the token's TTL.

Stop logging the token and avoid all of this. The combo of user, any
error and the usual timestamp etc. should be more than sufficient.

Signed-off-by: Stephen Finucane <stephenfin@redhat.com>
@kubernetes-prow kubernetes-prow Bot added release-note-none Denotes a PR that doesn't merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Aug 25, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign stephenfin for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. release-note-none Denotes a PR that doesn't merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant