Conversation
- HTTP worker checkout waits in two FIFO tiers; API clients and background cache refreshes only get a worker when no interactive request is waiting - Queue timeout unchanged and shared by both tiers
- Keep both ends of each label and the public suffix readable; the hidden middle is encrypted deterministically (short HMAC tag seeding an AES-CTR keystream), so a value always masks to the same short token - Instance key lives in the CraftInstanceKeys table, created on first start - LogBridge reveals masked values before filtering, so search, exclude and regex work on the originals - Platform hosts, tenant ids and GUIDs are left as is; CRAFT_LOG_REDACTION=false turns it off
…ser traffic - record each response against its endpoint (bytes, requests, max size, cache hits, errors, shed) on daily client rows and instance 15-minute buckets - handlers can sub-label traffic with an X-Craft-Endpoint response header, which is stripped before the response is sent - signed-in users are tracked in an 'interactive' partition that never counts toward the cap - instance daily request count now includes clients idle since an earlier bucket
JohnDuprey
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces detailed endpoint-level accounting and interactive user traffic tracking to the egress logging and metering system. It also adds configurable log redaction for sensitive information in logs and console output. The changes enhance observability, enable more granular reporting, and improve privacy controls.
Egress metering enhancements:
Log redaction improvements:
FileLoggingSettingsfor masking UPNs and customer domains in logs, with an allow list for readable domains and environment variable override. [1] [2]Other improvements:
LogBridge, ensuring authorized access sees the original data.These changes provide more accurate and privacy-aware logging and metering, supporting better reporting and diagnostics for both API and interactive user traffic.