Skip to content

Require secure and redacted OTLP endpoint configuration in Production #316

Description

@mforce

Parent: #244
Epic: #15
Severity: Medium
Execution mode: AFK

What to build

Harden Otlp:Endpoint validation and startup logging. The app currently accepts plaintext HTTP endpoints and logs resolved endpoint URIs. A URI containing userinfo, query credentials, or sensitive tenant/vendor parameters could leak into console logs, while plaintext export exposes telemetry and authentication headers in transit.

Require HTTPS in Production, with any insecure loopback development escape hatch explicit and unavailable by accident. Reject endpoint userinfo, query, and fragment components; vendor credentials belong only in Otlp:Headers. Log a sanitized destination that cannot carry secrets.

Any host-specific collector, TLS, CA, credential-delivery, or vendor wiring should be addressed separately in a private deploy/infra tracker.

Acceptance criteria

  • Production boot fails when an enabled OTLP endpoint is plaintext HTTP.
  • Endpoint URIs containing userinfo, query, or fragment components fail validation in every environment.
  • Vendor authentication is accepted only through Otlp:Headers and those values are never logged.
  • Startup logs contain only a sanitized scheme, host, port, and non-sensitive path.
  • Development can use an explicitly documented loopback-only insecure mode without weakening Production defaults.
  • Tests cover HTTPS, plaintext Production rejection, loopback development behavior, userinfo/query rejection, and sanitized logging.

Blocked by

None. Actual collector and CA configuration, if needed, belongs in a private deploy/infra tracker.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:apiAPI/endpoint layerbugSomething isn't workingepic-1.5sliceThin vertical work item

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions