From 0203ed742d1f08c68c660b545ff5c57ffd5b5c4b Mon Sep 17 00:00:00 2001 From: JacobPEvans <20714140+JacobPEvans-personal@users.noreply.github.com> Date: Tue, 18 Aug 2026 07:10:54 -0400 Subject: [PATCH 1/2] fix: hide the Splunk Cloud stack name at untrusted output boundaries Opt-in via VCT_SPLUNK_REDACT_TARGET=1: hides the Cloud stack label in prompts, JSON metadata, and transport error text, without touching the audit log (which still records the real host). `splunk inspect` reports `stack_configured: bool` instead of echoing the stack name. The Splunk Cloud Read Canary workflow sets the variable and scans its own pytest output for a leaked target or credential before publishing anything. --- .env.example | 5 ++ .github/scripts/run-cloud-suite.sh | 43 +++++++++++++++ .github/scripts/scan-cloud-ci-leaks.py | 53 ++++++++++++++++++ .github/workflows/cloud-read.yml | 14 +++-- CHANGELOG.md | 9 +++ docs/architecture.md | 4 +- src/vct_splunk/commands/context.py | 4 +- src/vct_splunk/utils/backends.py | 5 +- src/vct_splunk/utils/redact.py | 29 ++++++++++ tests/unit/test_acs.py | 6 +- tests/unit/test_public_target.py | 76 ++++++++++++++++++++++++++ 11 files changed, 237 insertions(+), 11 deletions(-) create mode 100644 .github/scripts/run-cloud-suite.sh create mode 100644 .github/scripts/scan-cloud-ci-leaks.py create mode 100644 tests/unit/test_public_target.py diff --git a/.env.example b/.env.example index 47f2c3b..0ee8079 100644 --- a/.env.example +++ b/.env.example @@ -71,6 +71,11 @@ SPLUNK_TOKEN= # FedRAMP stacks use https://admin.splunkcloudgc.com. # SPLUNK_ACS_BASE_URL= +# Hide the Cloud stack name at untrusted output boundaries (e.g. CI logs) in +# the target shown by prompts, JSON metadata, and error text. The audit log is +# unaffected -- it always records the real host. +# VCT_SPLUNK_REDACT_TARGET=1 + # --- Live test opt-ins ------------------------------------------------------- # Enables live read tests. Enterprise writes also require SPLUNK_WRITE_TEST=true. diff --git a/.github/scripts/run-cloud-suite.sh b/.github/scripts/run-cloud-suite.sh new file mode 100644 index 0000000..4d735e5 --- /dev/null +++ b/.github/scripts/run-cloud-suite.sh @@ -0,0 +1,43 @@ +#!/usr/bin/env bash +# Run one Cloud pytest suite, tee its output, and fail if a leak scan finds a +# target or credential in the resulting artifacts. Shared by the read and +# write canary workflows so the pipefail/tee/scan/exit dance lives in one +# place instead of being copy-pasted per step. +# +# Usage: run-cloud-suite.sh