Skip to content

Allow filtering of private-token in gitlab-workhorse

Overview

The private-token is retracted from the GitLab rails application logs, however it is still contained in NGINX and gitlab-workhorse logs. Can we enable scrubbing of the private token in these logs as well.

This is a security related issue for GitLab.com and Logging to https://log.gitlap.com/app/kibana (marked as confidential for that reason)

//cc @jacobvosmaer-gitlab @stanhu

Edited by Nick Thomas