feat: Add JSON Log Format Support to Vault CSI Provider - #398
Conversation
|
Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement Learn more about why HashiCorp requires a CLA and what the CLA includes Khajan Bisht seems not to be a GitHub user. Have you signed the CLA already but the status is still pending? Recheck it. |
|
Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement Learn more about why HashiCorp requires a CLA and what the CLA includes Have you signed the CLA already but the status is still pending? Recheck it. |
Summary
This PR adds support for JSON-formatted logging to the vault-csi-provider, enabling better integration with log aggregation systems like Datadog, ELK, and Splunk.
Changes
Core Implementation
New CLI Flag:
-log-formatflag with support forjsonandtextformatstextto maintain backward compatibilityJSON,TEXT, etc.)Files Modified:
main.go: ImplementedsetupLogger()function with format selection logicinternal/config/config.go: AddedLogFormatfield toFlagsConfigTesting
Unit Tests (
main_test.go):TestSetupLoggerFormat: Validates format configuration (JSON, TEXT, default)TestSetupLoggerFormatValidation: Tests case-insensitive validationTestSetupLoggerIntegration: End-to-end JSON output verificationTest Configuration:
test/bats/configs/vault-csi-provider-test.yaml: Kubernetes test manifesttest/bats/configs/test-app-with-vault-secrets.yaml: Sample app for mount testingUsage
Command Line
Kubernetes Deployment
Example Output
JSON Format
{"@level":"info","@message":"Logger initialized","@module":"vault-csi-provider","@timestamp":"2025-10-07T23:14:08.986Z","format":"json","level":"info"} {"@level":"info","@message":"Creating new gRPC server","@module":"vault-csi-provider","@timestamp":"2025-10-07T23:14:08.987Z"} {"@level":"info","@message":"Processing unary gRPC call","grpc.method":"/v1alpha1.CSIDriverProvider/MountSecretsStoreObjectContent","@timestamp":"..."}Manual Testing
Benefits
Migration Guide
For existing deployments wanting to switch to JSON logging:
-log-format=jsonin container argsRelated Issues
#177
PCI review checklist
I have documented a clear reason for, and description of, the change I am making.
If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.
If applicable, I've documented the impact of any changes to security controls.
Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.