Collector Redaction Cannot Erase Sensitive Data Copied Before It Reaches the Pipeline
A common misconception in OpenTelemetry usage is that configuring the Collector to redact sensitive data cleans up the entire observability pipeline. In reality, the Collector only processes what is sent to it and cannot delete copies already written to local files, disk buffers, or third-party SDKs at the application level. For example, if a service logs a credit card number locally before sending telemetry, that data persists even after the Collector strips the relevant attribute from incoming spans. OpenTelemetry's own documentation advises that the best approach is to never collect sensitive data in the first place, following the principle of data minimization. Developers are urged to treat the application boundary as the primary control point and audit instrumentation libraries to prevent inadvertent capture of personally identifiable information.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in