Skip to content

fix: add webhook mutation audit trail and stop logging full pod labels - #184

Merged
miyunari merged 1 commit into
sigstore:mainfrom
sampras343:fix/webhook-audit-logging
Sep 20, 2026
Merged

miyunari merged 1 commit into
sigstore:mainfrom
sampras343:fix/webhook-audit-logging

Conversation

@sampras343

Copy link
Copy Markdown
Contributor

Summary

What

  • Add structured audit log line for every validation container injection: pod name, namespace, ModelValidation CR, auth method, continuous mode, sidecar type
  • Replace "labels", pod.Labels (full label map) with "matchLabel", pod.Labels[ModelValidationLabel] (only the match value)
  • Remove redundant narration logs ("label found", "Search CR", "construct args", "found sigstore config")
  • Add missing error log for pod marshal failure
  • Promote "missing validation config" from Info to Error

Why

The webhook is the operator's primary security function, it decides what gets injected into which pods. Today, successful injections produce zero log output. You can see skips and errors, but not the actual mutations. This makes incident investigation and compliance auditing impossible.

The full label map dump leaks business metadata (team names, environment tags, deployment identifiers) into operator logs on every single pod admission in the cluster. A security operator shouldn't be the source of an information leak.

Closes #183

Release Note

Documentation

Add structured audit log for every validation container injection with
pod name, namespace, ModelValidation CR, auth method, continuous mode,
and sidecar type. Replace full pod.Labels dump with only the match label
value to prevent leaking business metadata in operator logs.

Also removes redundant narration logs from the admission path and
promotes "missing validation config" to Error level.

Signed-off-by: Sachin Sampras M <sampras343@gmail.com>
@miyunari
miyunari merged commit 1aa5933 into sigstore:main Sep 20, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Webhook mutations have no audit trail and pod labels are leaked in logs

2 participants