Uploaded image for project: 'Puppet Development Kit'
  1. Puppet Development Kit
  2. PDK-1068

Resource API is leaking Sensitive parameters when running in Debug Mode

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:

      Using Puppet CE 5.5 with latest PDK (1.6). 

      I created a simple type/provider combo, and one of my params is a password (to a nexus artifact, in this case). I don't want this password to show up in logs 

    • Template:
    • Team:
      Network Automation
    • Method Found:
      Needs Assessment
    • QA Risk Assessment:
      Needs Assessment

      Description

      When running in -d mode, the resource api seems to leak the Target State, which includes the password, even if I wrap the param in my manifest in a Sensitive(). 

       

      How can I suppress this data if my admin does a -d run?

      in my puppet Log I see:

      Debug: Target State:  {...resource params in clear text...}

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned
              Reporter:
              Codej Cody Campbell
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Zendesk Support