Files
my-rook-config/pkg/operator/ceph/csi
Anas Khan 245c45d536 csi: do not log peer bootstrap token secret
decodePeerToken logged the whole decoded PeerToken with "%+v" at debug
level. PeerToken embeds Key, the peer cluster's cephx auth secret, so
running the operator with ROOK_LOG_LEVEL=DEBUG wrote that credential to
the operator logs in plaintext (CWE-532).

Log only the non-sensitive fields (fsid, client id, mon host, namespace),
which keep the message useful for diagnostics, and drop Key. Add a
regression test that captures the debug output and asserts the key is
never present.

Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
(cherry picked from commit 1013a8effc)
2026-07-21 00:24:38 +00:00
..
2026-05-12 12:49:21 -10:00