[FLINK-38815] Mask sensitive values in Pekko configuration logs#27784
Open
dataengineervishal wants to merge 2 commits intoapache:masterfrom
Open
[FLINK-38815] Mask sensitive values in Pekko configuration logs#27784dataengineervishal wants to merge 2 commits intoapache:masterfrom
dataengineervishal wants to merge 2 commits intoapache:masterfrom
Conversation
Collaborator
2063fe5 to
bc36a5b
Compare
mukul-8
reviewed
Mar 19, 2026
...ink-rpc-akka/src/main/java/org/apache/flink/runtime/rpc/pekko/ActorSystemBootstrapTools.java
Outdated
Show resolved
Hide resolved
5e0704f to
b3ecdfa
Compare
Author
|
@XComp Can you please take a look and approve this? |
Samrat002
reviewed
Mar 20, 2026
...ink-rpc-akka/src/main/java/org/apache/flink/runtime/rpc/pekko/ActorSystemBootstrapTools.java
Outdated
Show resolved
Hide resolved
59f81a1 to
32c31f6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR depends on https://issues.apache.org/jira/browse/FLINK-38815
What is the purpose of the change
This pull request fixes a security issue where sensitive values in the Pekko RPC configuration were logged in plain text.
The Pekko configuration is based on Typesafe Config and was directly logged, bypassing Flink’s existing masking logic. This change ensures that sensitive values (such as passwords and secrets) are masked before being logged.
Brief change log
Verifying this change
This change is already covered by existing tests.
Additionally, the fix was manually verified by enabling debug logging and confirming that sensitive fields such as key-password and trust-store-password are masked (replaced with ******) in the logs.
Does this pull request potentially affect one of the following parts:
@Public(Evolving): noDocumentation