Security Notes
Observability data can contain sensitive information. Treat it like production data.
- Restrict access by role
- Avoid logging secrets, credentials, or PII
- Encrypt telemetry in transit
- Align retention with compliance requirements
Access Controls
Ensure metrics and trace backends are protected with authentication and network policies. Avoid exposing telemetry endpoints publicly.
Data Minimization
Keep attributes and log fields minimal. Prefer identifiers over payloads.
Redaction
If payload content must be logged, redact sensitive fields at the logger or mapper level.