[
https://issues.apache.org/jira/browse/FLINK-30443?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17651289#comment-17651289
]
Gunnar Morling commented on FLINK-30443:
----------------------------------------
Hey [~jiabao.sun] and [~zhuzh], thanks for your feedback! I certainly can make
this configurable, but do you think it's worth it? I'm not so much concerned
about the engineering time for making it happen, this shouldn't take long. But
it adds to the configuration surface and complexity of Flink; generally, the
less bells and whistles, the better, IMO. It makes things easier for users. How
about we add those keys verbatim for now (I've just sent a PR for that), and if
there's another request for extending them down the road, we'll make it
configurable then?
> Expand list of sensitive keys
> -----------------------------
>
> Key: FLINK-30443
> URL: https://issues.apache.org/jira/browse/FLINK-30443
> Project: Flink
> Issue Type: Improvement
> Components: API / Core
> Reporter: Gunnar Morling
> Priority: Major
> Labels: pull-request-available
>
> In {{{}GlobalConfiguration{}}}, there is [a list of known configuration
> keys|https://github.com/apache/flink/blob/master/flink-core/src/main/java/org/apache/flink/configuration/GlobalConfiguration.java#L47-L48]
> whose values will be masked in log output. In our Flink deployment there's a
> few more keys which we would like to mask, specifically, the following ones:
> * "auth-params"
> * "service-key"
> * "token"
> * "basic-auth"
> * "jaas.config"
> While those are somewhat use-case specific, I feel they are generic enough
> for being added to that list, and there already is precedence in form of
> "fs.azure.account.key". In that light, I don't think it's worth making this
> somehow pluggable, but I'm curious what other folks here think. Thanks!
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)