mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: purge boundary logs past retention (#24815)
Add a periodic purge job for `boundary_logs` rows past their retention threshold, following the same pattern as the existing audit log and connection log purge jobs in `dbpurge`. Expose a `--boundary-log-retention` deployment flag (env `CODER_BOUNDARY_LOG_RETENTION`, YAML `retention.boundary_logs`). Default is `0` (keep indefinitely). When set to a positive duration, `purgeTick` deletes rows where `captured_at` is older than the threshold in batches of 10,000, matching other log purge operations. The `boundary_logs` label is added to the `records_purged_total` Prometheus counter. Also removes the random-UUID fallback for `OwnerID` in `dbgen.BoundarySession`. The previous fallback generated a UUID that could never satisfy the `boundary_sessions_owner_id_fkey` FK constraint, masking test setup bugs. Callers must now provide a valid user ID or accept NULL (the legitimate "user deleted" state).
This commit is contained in:
@@ -1194,6 +1194,12 @@ type RetentionConfig struct {
|
||||
// Logs from the latest build are always retained regardless of age.
|
||||
// Defaults to 7 days to preserve existing behavior.
|
||||
WorkspaceAgentLogs serpent.Duration `json:"workspace_agent_logs" typescript:",notnull"`
|
||||
// BoundaryLogs controls how long boundary audit log entries are
|
||||
// retained. Boundary logs record every HTTP request processed by
|
||||
// a Boundary confinement proxy. Set to 0 to disable automatic
|
||||
// deletion (keep indefinitely). Adjust to match your
|
||||
// organization's regulatory requirements.
|
||||
BoundaryLogs serpent.Duration `json:"boundary_logs" typescript:",notnull"`
|
||||
}
|
||||
|
||||
type NotificationsConfig struct {
|
||||
@@ -4703,6 +4709,17 @@ Write out the current server config as YAML to stdout.`,
|
||||
YAML: "workspace_agent_logs",
|
||||
Annotations: serpent.Annotations{}.Mark(annotationFormatDuration, "true"),
|
||||
},
|
||||
{
|
||||
Name: "Boundary Log Retention",
|
||||
Description: "How long boundary audit log entries are retained. Boundary logs record HTTP requests processed by a Boundary confinement proxy. Set to 0 to disable automatic deletion (keep indefinitely). Adjust to match your organization's regulatory requirements.",
|
||||
Flag: "boundary-log-retention",
|
||||
Env: "CODER_BOUNDARY_LOG_RETENTION",
|
||||
Value: &c.Retention.BoundaryLogs,
|
||||
Default: "0",
|
||||
Group: &deploymentGroupRetention,
|
||||
YAML: "boundary_logs",
|
||||
Annotations: serpent.Annotations{}.Mark(annotationFormatDuration, "true"),
|
||||
},
|
||||
{
|
||||
Name: "Enable Authorization Recordings",
|
||||
Description: "All api requests will have a header including all authorization calls made during the request. " +
|
||||
|
||||
Reference in New Issue
Block a user