Lesson 23 / 25

Security and Privacy

Telemetry can leak secrets.

Treat telemetry as sensitive data

Spans and logs can accidentally capture personal data, tokens, passwords or full URLs with query parameters. Avoid recording such data in instrumentation, configure instrumentations not to capture request bodies or sensitive headers, and redact centrally in the Collector. Use TLS and authentication between SDKs, Collectors and backends, restrict who can query telemetry, and set retention that matches your data protection obligations.

A privacy review list for attributes

Questions for each attribute you add.

Does it identify a person (email, phone, name, IP)?      -> drop, hash or pseudonymise
Could it contain secrets (tokens, cookies, API keys)?     -> never record
Is it a full URL with a query string?                       -> record the route template instead
Is it needed to debug or measure something?                 -> if not, remove it
Who can read it, and for how long is it kept?               -> access control + retention

Test with real-looking data

Inspect exported spans in a staging environment with the debug exporter to see exactly what leaves your services.

Quick check: What should you record instead of a full URL with query parameters?

  • The route template, such as /orders/{id}
  • The user's password
  • The entire request body
  • Cookies
Answer

The route template, such as /orders/{id} — Avoid sensitive values and high cardinality.