Redis:Omit command arguments from span.resource by default#3235
Merged
Conversation
marcotc
force-pushed
the
redis-only-command-default
branch
from
October 30, 2023 20:40
3bc30b4 to
648bbc8
Compare
marcotc
force-pushed
the
redis-only-command-default
branch
from
October 30, 2023 21:44
648bbc8 to
d1a30df
Compare
marcotc
marked this pull request as ready for review
October 30, 2023 21:55
urseberry
reviewed
Oct 31, 2023
Co-authored-by: Ursula Chen <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #3235 +/- ##
=======================================
Coverage 98.22% 98.22%
=======================================
Files 1252 1252
Lines 72201 72173 -28
Branches 3353 3348 -5
=======================================
- Hits 70917 70890 -27
+ Misses 1284 1283 -1 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
ekump
approved these changes
Nov 1, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
For release notes
The Datadog Agent removes command arguments from the resource name. However there are cases, like compressed keys, where this obfuscation cannot correctly remove command arguments. To safeguard that situation, the resource name set by the tracer will only be the command (e.g. SET) with no arguments. To retain the previous behavior and keep arguments in the span resource, with the potential risk of some command arguments not being fully obfuscated, set
DD_REDIS_COMMAND_ARGS=trueor optionc.instrument :redis, command_args: true.What does this PR do?
This PR changes the value of
span.resourcefor the Redis tracing instrumentation to only capture the command name by default (e.g.GET,BLPOP).It's possible to revert back to the previous default, capturing command arguments, with the environment variable
DD_REDIS_COMMAND_ARGSor optioncommand_args.Motivation:
Redis command arguments can contain sensitive information and thus must not be captured by default.
Additional Notes:
How to test the change?
For Datadog employees:
credentials of any kind, I've requested a review from
@DataDog/security-design-and-guidance.Unsure? Have a question? Request a review!