You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
plugins/logs: Include http request context in decision logs
It would be useful if users had the ability to enhance the
decision log with info from the incoming HTTP request such as
headers. This change allows users to configure headers whose
values if present in the incoming HTTP request would be
surfaced via the decision log. This can be extended in the
future to include more context from the request.
Fixes: #6693
Signed-off-by: Ashutosh Narkar <[email protected]>
Copy file name to clipboardExpand all lines: docs/content/configuration.md
+15-14Lines changed: 15 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -723,21 +723,22 @@ included in the actual bundle gzipped tarball.
723
723
724
724
## Decision Logs
725
725
726
-
| Field | Type | Required | Description |
727
-
|---| --- | --- | --- |
728
-
|`decision_logs.service`|`string`| No | Name of the service to use to contact remote server. If no `plugin` is specified, and `console` logging is disabled, this will default to the first `service` name defined in the Services configuration. |
729
-
|`decision_logs.partition_name`|`string`| No | Deprecated: Use `resource` instead. Path segment to include in status updates. |
730
-
|`decision_logs.resource`|`string`| No (default: `/logs`) | Full path to use for sending decision logs to a remote server. |
731
-
|`decision_logs.reporting.buffer_size_limit_bytes`|`int64`| No | Decision log buffer size limit in bytes. OPA will drop old events from the log if this limit is exceeded. By default, no limit is set. Only one of `buffer_size_limit_bytes`, `max_decisions_per_second` may be set. |
|`decision_logs.service`|`string`| No | Name of the service to use to contact remote server. If no `plugin` is specified, and `console` logging is disabled, this will default to the first `service` name defined in the Services configuration. |
729
+
|`decision_logs.partition_name`|`string`| No | Deprecated: Use `resource` instead. Path segment to include in status updates. |
730
+
|`decision_logs.resource`|`string`| No (default: `/logs`) | Full path to use for sending decision logs to a remote server. |
731
+
|`decision_logs.reporting.buffer_size_limit_bytes`|`int64`| No | Decision log buffer size limit in bytes. OPA will drop old events from the log if this limit is exceeded. By default, no limit is set. Only one of `buffer_size_limit_bytes`, `max_decisions_per_second` may be set. |
732
732
|`decision_logs.reporting.max_decisions_per_second`|`float64`| No | Maximum number of decision log events to buffer per second. OPA will drop events if the rate limit is exceeded. Only one of `buffer_size_limit_bytes`, `max_decisions_per_second` may be set. |
733
-
|`decision_logs.reporting.upload_size_limit_bytes`|`int64`| No (default: `32768`) | Decision log upload size limit in bytes. OPA will chunk uploads to cap message body to this limit. |
734
-
|`decision_logs.reporting.min_delay_seconds`|`int64`| No (default: `300`) | Minimum amount of time to wait between uploads. |
735
-
|`decision_logs.reporting.max_delay_seconds`|`int64`| No (default: `600`) | Maximum amount of time to wait between uploads. |
736
-
|`decision_logs.reporting.trigger`|`string`| No (default: `periodic`) | Controls how decision logs are reported to the remote server. Allowed values are `periodic` and `manual` (`manual` triggers are only possible when using OPA as a Go package). |
737
-
|`decision_logs.mask_decision`|`string`| No (default: `/system/log/mask`) | Set path of masking decision. |
738
-
|`decision_logs.drop_decision`|`string`| No (default: `/system/log/drop`) | Set path of drop decision. |
739
-
|`decision_logs.plugin`|`string`| No | Use the named plugin for decision logging. If this field exists, the other configuration fields are not required. |
740
-
|`decision_logs.console`|`boolean`| No (default: `false`) | Log the decisions locally to the console. When enabled alongside a remote decision logging API the `service` must be configured, the default `service` selection will be disabled. |
733
+
|`decision_logs.reporting.upload_size_limit_bytes`|`int64`| No (default: `32768`) | Decision log upload size limit in bytes. OPA will chunk uploads to cap message body to this limit. |
734
+
|`decision_logs.reporting.min_delay_seconds`|`int64`| No (default: `300`) | Minimum amount of time to wait between uploads. |
735
+
|`decision_logs.reporting.max_delay_seconds`|`int64`| No (default: `600`) | Maximum amount of time to wait between uploads. |
736
+
|`decision_logs.reporting.trigger`|`string`| No (default: `periodic`) | Controls how decision logs are reported to the remote server. Allowed values are `periodic` and `manual` (`manual` triggers are only possible when using OPA as a Go package). |
737
+
|`decision_logs.mask_decision`|`string`| No (default: `/system/log/mask`) | Set path of masking decision. |
738
+
|`decision_logs.drop_decision`|`string`| No (default: `/system/log/drop`) | Set path of drop decision. |
739
+
|`decision_logs.plugin`|`string`| No | Use the named plugin for decision logging. If this field exists, the other configuration fields are not required. |
740
+
|`decision_logs.console`|`boolean`| No (default: `false`) | Log the decisions locally to the console. When enabled alongside a remote decision logging API the `service` must be configured, the default `service` selection will be disabled. |
741
+
|`decision_logs.request_context.http.headers`|`array`| No | List of HTTP headers to include in the decision log. OPA will include the values for these headers in the decision log if they exist in the incoming HTTP request. |
0 commit comments