feat: purge boundary logs past retention (#24815)

Add a periodic purge job for `boundary_logs` rows past their retention
threshold, following the same pattern as the existing audit log and
connection log purge jobs in `dbpurge`.

Expose a `--boundary-log-retention` deployment flag (env
`CODER_BOUNDARY_LOG_RETENTION`, YAML `retention.boundary_logs`). Default
is `0` (keep indefinitely). When set to a positive duration, `purgeTick`
deletes rows where `captured_at` is older than the threshold in batches
of 10,000, matching other log purge operations. The `boundary_logs`
label is added to the `records_purged_total` Prometheus counter.

Also removes the random-UUID fallback for `OwnerID` in
`dbgen.BoundarySession`. The previous fallback generated a UUID that
could never satisfy the `boundary_sessions_owner_id_fkey` FK constraint,
masking test setup bugs. Callers must now provide a valid user ID or
accept NULL (the legitimate "user deleted" state).
This commit is contained in:
Sas Swart
2026-06-16 14:32:54 +02:00
committed by GitHub
parent e345e061f2
commit 2716e2181c
20 changed files with 446 additions and 7 deletions
+6
View File
@@ -878,6 +878,12 @@ that data type.
indefinitely). We advise keeping audit logs for at least a year, and
in accordance with your compliance requirements.
--boundary-log-retention duration, $CODER_BOUNDARY_LOG_RETENTION (default: 0)
How long boundary audit log entries are retained. Boundary logs record
HTTP requests processed by a Boundary confinement proxy. Set to 0 to
disable automatic deletion (keep indefinitely). Adjust to match your
organization's regulatory requirements.
--connection-logs-retention duration, $CODER_CONNECTION_LOGS_RETENTION (default: 0)
How long connection log entries are retained. Set to 0 to disable
(keep indefinitely).
+6
View File
@@ -1122,6 +1122,12 @@ retention:
# build are always retained. Set to 0 to disable automatic deletion.
# (default: 7d, type: duration)
workspace_agent_logs: 168h0m0s
# How long boundary audit log entries are retained. Boundary logs record HTTP
# requests processed by a Boundary confinement proxy. Set to 0 to disable
# automatic deletion (keep indefinitely). Adjust to match your organization's
# regulatory requirements.
# (default: 0, type: duration)
boundary_logs: 0s
templateBuilder:
# Disable the template builder feature for guided template creation. When
# disabled, all /api/v2/templatebuilder/* endpoints return 404.