Skip to content

Sensitive api and app keys exposed in logs #64

Description

@sk-ez

Expected Behavior

API/APP keys should not be exposed in logs

Actual Behavior

API/APP keys are logged to cloudwatch via DatadogAPICall lambda function

Steps to Reproduce the Problem

Deploy Datadog AWS integration cloudformation template in AWS account
Check cloudwatch logs of DatadogAPICall function deployed as part of the above deployment - api and app keys are logged

Specifications

  • Datadog CloudFormation template version:

https://github.com/DataDog/cloudformation-template/blob/master/aws_quickstart/datadog_integration_api_call_v2.yaml
https://github.com/DataDog/cloudformation-template/blob/53d9b7f5dccbf3b0049cbbb21ec6ea024fbb7327/aws_organizations/main_organizations.yaml

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions