mirror of
https://github.com/helmfile/helmfile.git
synced 2026-10-03 14:21:52 +02:00
* fix: make AWS SDK debug logging configurable (issue #2270) This PR fixes issue #2270 where AWS SDK debug logs expose sensitive credentials in helmfile output, by adding flexible, configurable AWS SDK logging with secure defaults. Problem: -------- Despite PR #2288's fix, AWS SDK debug logs still appeared in helmfile output, exposing sensitive information: - AWS tokens and authorization headers - Request/response bodies containing credentials - Secret metadata from vals providers Root Cause: ----------- 1. PR #2288 only suppressed vals' own logging via LogOutput: io.Discard 2. AWS SDK v2 uses separate logging (AWS_SDK_GO_LOG_LEVEL, WithClientLogMode) 3. Vals library defaulted to verbose logging (aws.LogRetries | aws.LogRequest) 4. No programmatic way to control AWS SDK logging Solution: --------- Two-part fix in conjunction with vals PR #893: 1. Vals library enhancement (helmfile/vals#893): - Added Options.AWSLogLevel field for programmatic control - Changed default from verbose to secure (no logging) - Added preset levels: off, minimal, standard, verbose - Maintains AWS_SDK_GO_LOG_LEVEL precedence 2. Helmfile changes (this PR): - Added HELMFILE_AWS_SDK_LOG_LEVEL environment variable - Enhanced vals configuration to use new AWSLogLevel field - Added conditional AWS SDK log suppression in remote.go (3 locations) - Comprehensive unit tests (15 test cases) Configuration: -------------- Preset levels via HELMFILE_AWS_SDK_LOG_LEVEL: - "off" (default) - No logging, secure, prevents credential leakage - "minimal" - Log retries only - "standard" - Log retries + requests (previous default behavior) - "verbose" - Log everything (requests, responses, bodies, signing) - Custom - Comma-separated values (e.g., "request,response") Priority order: 1. AWS_SDK_GO_LOG_LEVEL env var (highest) 2. HELMFILE_AWS_SDK_LOG_LEVEL env var 3. Secure default ("off") Testing: -------- Added comprehensive unit tests: - pkg/plugins/vals_test.go: 9 test cases * TestAWSSDKLogLevelConfiguration - all preset levels * TestEnvironmentVariableReading - env var parsing - pkg/remote/remote_test.go: 6 test cases * TestAWSSDKLogLevelInit - init() logic All tests passing: - pkg/plugins: PASS (3/3 test suites) - pkg/remote: PASS (all test suites) - golangci-lint: 0 issues Files changed: 7 files, 271 insertions(+), 31 deletions(-) Security: --------- Before: Credentials exposed by default (aws.LogRetries | aws.LogRequest) After: Credentials protected by default (no logging unless explicitly enabled) Follows security principles: - Secure by default - Principle of least privilege - Explicit opt-in for sensitive logging - Defense in depth Dependency: ----------- Depends on: helmfile/vals#893 Currently using: aditmeno/vals@a97336ce2b (via go.mod replace) After vals PR merges: Update to official release Fixes: #2270 Related: #2288, #2289, helmfile/vals#893 Signed-off-by: Aditya Menon <amenon@canarytechnologies.com> * chore: update vals to use parameter-based AWS log level configuration Updated vals dependency to commit 06d7cd29 which implements clean parameter-based AWS SDK logging configuration instead of using global state mutation. Changes in vals implementation: - AWS log level passed through function parameters to each provider - No os.Setenv() - no environment mutation - No package-level global variables - No sync/atomic dependency needed - Thread-safe by design - each provider instance has its own log level This maintains the same functionality as before but with a cleaner implementation that avoids global state mutation. Signed-off-by: Aditya Menon <amenon@canarytechnologies.com> * deps: update vals to upstream v0.42.6 Update from vals fork (aditmeno/vals) to official release v0.42.6. Remove replace directive now that vals PR #893 has been merged upstream. This brings in the AWS SDK log level configuration improvements: - SetDefaultLogLevel() package-level function - Options.AWSLogLevel field support - Secure default (no logging) - Preset log levels (off, minimal, standard, verbose) Also updates related dependencies: - Azure SDK and auth libraries - AWS SDK config and credentials - OAuth2 library Signed-off-by: Aditya Menon <amenon@canarytechnologies.com> --------- Signed-off-by: Aditya Menon <amenon@canarytechnologies.com>
167 lines
3.9 KiB
Go
167 lines
3.9 KiB
Go
package plugins
|
|
|
|
import (
|
|
"io"
|
|
"os"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/helmfile/vals"
|
|
|
|
"github.com/helmfile/helmfile/pkg/envvar"
|
|
)
|
|
|
|
func TestValsInstance(t *testing.T) {
|
|
i, err := ValsInstance()
|
|
|
|
if err != nil {
|
|
t.Errorf("unexpected error: %v", err)
|
|
}
|
|
|
|
i2, _ := ValsInstance()
|
|
|
|
if i != i2 {
|
|
t.Error("Instances should be equal")
|
|
}
|
|
}
|
|
|
|
// TestAWSSDKLogLevelConfiguration tests the AWS SDK log level configuration logic
|
|
func TestAWSSDKLogLevelConfiguration(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
envValue string
|
|
expectedLogLevel string
|
|
expectedLogOutput bool // true if LogOutput should be io.Discard
|
|
}{
|
|
{
|
|
name: "no env var defaults to off",
|
|
envValue: "",
|
|
expectedLogLevel: "off",
|
|
expectedLogOutput: true, // LogOutput should be io.Discard
|
|
},
|
|
{
|
|
name: "explicit off",
|
|
envValue: "off",
|
|
expectedLogLevel: "off",
|
|
expectedLogOutput: true,
|
|
},
|
|
{
|
|
name: "minimal logging",
|
|
envValue: "minimal",
|
|
expectedLogLevel: "minimal",
|
|
expectedLogOutput: false, // LogOutput should NOT be io.Discard
|
|
},
|
|
{
|
|
name: "standard logging",
|
|
envValue: "standard",
|
|
expectedLogLevel: "standard",
|
|
expectedLogOutput: false,
|
|
},
|
|
{
|
|
name: "verbose logging",
|
|
envValue: "verbose",
|
|
expectedLogLevel: "verbose",
|
|
expectedLogOutput: false,
|
|
},
|
|
{
|
|
name: "custom logging",
|
|
envValue: "request,response",
|
|
expectedLogLevel: "request,response",
|
|
expectedLogOutput: false,
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
// Note: This test verifies the configuration logic, not the actual vals.New() call
|
|
// since ValsInstance() uses sync.Once and can only be initialized once per test run.
|
|
|
|
// Simulate the logic from ValsInstance()
|
|
var logLevel string
|
|
if tt.envValue != "" {
|
|
logLevel = strings.TrimSpace(tt.envValue)
|
|
}
|
|
|
|
// Default to "off" for security if not specified
|
|
if logLevel == "" {
|
|
logLevel = "off"
|
|
}
|
|
|
|
// Verify expected log level
|
|
if logLevel != tt.expectedLogLevel {
|
|
t.Errorf("Expected log level %q, got %q", tt.expectedLogLevel, logLevel)
|
|
}
|
|
|
|
// Verify LogOutput configuration logic
|
|
opts := vals.Options{
|
|
CacheSize: valsCacheSize,
|
|
}
|
|
opts.AWSLogLevel = logLevel
|
|
|
|
// Verify LogOutput is set to io.Discard only when level is "off"
|
|
if tt.expectedLogOutput {
|
|
opts.LogOutput = io.Discard
|
|
if opts.LogOutput != io.Discard {
|
|
t.Error("Expected LogOutput to be io.Discard for 'off' level")
|
|
}
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestEnvironmentVariableReading verifies that the HELMFILE_AWS_SDK_LOG_LEVEL env var is read correctly
|
|
func TestEnvironmentVariableReading(t *testing.T) {
|
|
tests := []struct {
|
|
name string
|
|
envValue string
|
|
expectedValue string
|
|
}{
|
|
{
|
|
name: "empty defaults to off",
|
|
envValue: "",
|
|
expectedValue: "off",
|
|
},
|
|
{
|
|
name: "whitespace trimmed",
|
|
envValue: " minimal ",
|
|
expectedValue: "minimal",
|
|
},
|
|
{
|
|
name: "standard value preserved",
|
|
envValue: "standard",
|
|
expectedValue: "standard",
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
// Save and restore env var
|
|
original := os.Getenv(envvar.AWSSDKLogLevel)
|
|
defer func() {
|
|
if original == "" {
|
|
os.Unsetenv(envvar.AWSSDKLogLevel)
|
|
} else {
|
|
os.Setenv(envvar.AWSSDKLogLevel, original)
|
|
}
|
|
}()
|
|
|
|
// Set test env var
|
|
if tt.envValue == "" {
|
|
os.Unsetenv(envvar.AWSSDKLogLevel)
|
|
} else {
|
|
os.Setenv(envvar.AWSSDKLogLevel, tt.envValue)
|
|
}
|
|
|
|
// Read and process like ValsInstance() does
|
|
logLevel := strings.TrimSpace(os.Getenv(envvar.AWSSDKLogLevel))
|
|
if logLevel == "" {
|
|
logLevel = "off"
|
|
}
|
|
|
|
if logLevel != tt.expectedValue {
|
|
t.Errorf("Expected %q, got %q", tt.expectedValue, logLevel)
|
|
}
|
|
})
|
|
}
|
|
}
|