Repository navigation
Fix misleading error message and redact credential URLs from App/PackageRepository status - #1869
Open
nikhilsagotiya wants to merge 4 commits into
Conversation
…-schema type
- config/values-schema.yml: fix "trusted ca's" -> "trusted CAs" in the
caCerts field description, surfaced to users via kubectl explain and
Package/PackageInstall value schemas.
- cli/pkg/kctrl/cmd/package/available/values_schema.go: reword the
"unsupported type" error raised while parsing a valuesSchema
'properties' field. The previous message leaked Go type syntax
(map[string]interface{}, json.RawMessage) at a package author working
in YAML/OpenAPI, not Go; it now describes the expected shape in plain
terms and uses %T for the actual type.
No behavior or control-flow change, message text only.
Signed-off-by: Nikhil Sagotiya <nikhil.sagotiya@broadcom.com>
Subprocess (vendir/ytt/kbld/kapp) stdout, stderr and error text were copied verbatim into App and PackageRepository .status fields (Fetch, Template, Deploy, Inspect, Conditions[].Message, FriendlyDescription, UsefulErrorMessage). If any of those tools ever emit a credential embedded in a URL (e.g. a GOPROXY, git, or registry URL of the form https://user:token@host), it would land verbatim in a Kubernetes resource's status, visible via `kubectl get app -o yaml` and any tooling that reads it. - pkg/exec/cmd_run_result.go: add RedactSecrets, which masks the userinfo component of a URL (scheme://user:pass@host -> scheme://[REDACTED]@host). The match is greedy up to the last '@' before the host so a userinfo containing a literal '@' (e.g. in a password) is fully masked rather than partially. - pkg/app/app_reconcile.go, pkg/pkgrepository/app_reconcile.go: apply RedactSecrets at every point subprocess-derived text is written into .status (Fetch/Template/Deploy/Inspect Stdout/Stderr/Error, Condition.Message, FriendlyDescription, UsefulErrorMessage). No control flow, exit codes, or non-text fields changed. Signed-off-by: Nikhil Sagotiya <nikhil.sagotiya@broadcom.com>
aroradaman
approved these changes
Oct 6, 2026
aroradaman
left a comment
Member
There was a problem hiding this comment.
Changes look good. Just wondering why this doesn't require a unit/integration test change.
Add comprehensive test coverage for the new RedactSecrets function, covering: - Basic URL credential redaction (https, http, ftp, custom schemes) - Edge case: passwords containing @ symbols (greedy match to last @) - Multiple URLs in a single string - Multiline output with embedded credentials - Special characters in passwords - Malformed URLs and non-URL text (unchanged) - Empty strings All 16 test cases pass and validate the regex pattern's correctness and the greedy-to-last-@ behavior for passwords with @ characters. Signed-off-by: Sameer Khan <sameer.khan@broadcom.com>
Contributor
Added 16 unit tests for RedactSecrets covering all URL patterns and edge cases; the other changes are text-only. |
sameerforge
force-pushed
the
topic/nikhilsagotiya/fix-error-message-and-secrets-redaction
branch
from
October 7, 2026 09:10
c6481d6 to
ff8cbd0
Compare
- Fix grammar inconsistency: "can not be empty" -> "cannot be empty" (validations.go:108) - Replace full TokenRequest object logging with specific safe field logging (token_manager.go:127) Signed-off-by: Sameer Khan <sameer.khan@broadcom.com>
sameerforge
force-pushed
the
topic/nikhilsagotiya/fix-error-message-and-secrets-redaction
branch
from
October 7, 2026 10:16
ff8cbd0 to
ca80848
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it:
Two independent, related fixes found while auditing user-facing error/status text in
kapp-controller:Error message clarity (
cli/pkg/kctrl/cmd/package/available/values_schema.go,config/values-schema.yml):values-schema.ymlcaCertsdescription had a grammar error ("trusted ca's" instead of "trusted CAs"), surfaced to users viakubectl explainand the Package/PackageInstall value schema.valuesSchemapropertiesfield leaked raw Go type syntax (map[string]interface{},json.RawMessage) at a package author working in YAML/OpenAPI, not Go. Reworded to describe the expected shape in plain terms.Redact credential-bearing URLs from
.status(pkg/exec/cmd_run_result.go,pkg/app/app_reconcile.go,pkg/pkgrepository/app_reconcile.go):AppandPackageRepositoryreconciliation copies subprocess (vendir/ytt/kbld/kapp) stdout, stderr, and error text verbatim into.statusfields (Fetch,Template,Deploy,Inspect,Conditions[].Message,FriendlyDescription,UsefulErrorMessage).GOPROXY, git, or registry URL of the formhttps://user:token@host), it lands verbatim in a Kubernetes resource's status — visible viakubectl get app -o yamland any tooling/logging that reads it.exec.RedactSecrets, which masks the userinfo component of a URL (scheme://user:pass@host→scheme://[REDACTED]@host), and applied it at every point subprocess-derived text is written intoApp/PackageRepositorystatus. The regex is greedy up to the last@before the host so a userinfo containing a literal@(e.g. in a password) is fully masked rather than partially.Both are pure message-text/output-sanitization changes; no behavior, API, or control-flow changes.
Which issue(s) this PR fixes:
Fixes #
Does this PR introduce a user-facing change?
Additional Notes for your reviewer:
go build ./...,go vet ./..., andgolangci-lint run(pinnedv2.12.2, matching.github/workflows/golangci-lint.yml) are clean on all touched packages (0 issues).go test ./pkg/app/... ./pkg/pkgrepository/... ./pkg/exec/...was run locally; two pre-existing failures inpkg/app/pkg/pkgrepositoryreproduce identically on unmodifieddevelopin this sandbox (missingvendir/kbldbinaries in$PATH) and are unrelated to this change — confirmed by stashing the diff and re-running.RedactSecretsmasking pattern (URL userinfo) covers the credential-leak shape most relevant to this codebase (GOPROXY/git/registry URLs); it does not attempt to redact arbitrary secret shapes (API keys, tokens outside a URL) since none of the current subprocess integrations are known to emit those into status text.Review Checklist:
Additional documentation e.g., Proposal, usage docs, etc.: