You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Spec-only OpenSpec change for #1065: support audit log configuration on the serverless project resources (ec_elasticsearch_project, ec_observability_project, ec_security_project) via an optional monitoring.logging.audit block.
This PR adds only openspec/changes/add-serverless-project-audit-logging/ (proposal, delta spec, design, tasks). No provider code, docs, or changelog changes.
Key decisions
monitoring, logging, and audit are optional; destination is required only when audit is set. enabled defaults to true.
ignore_filter_ids is a set of strings, at most 10 (the API maxItems). Null and an empty set both mean no filters; read preserves whichever form the configuration uses.
destination.status is computed inside destination and never sent on write (LoggingDestinationCreateRequest has additionalProperties: false).
Clearing audit sends "audit":null (never "monitoring":null); clearing filters sends "ignore_filters":null. Both go through Patch*ProjectWithBodyWithResponse because generated *T + omitempty fields cannot encode JSON null. Global nullable-type is not enabled.
One Read serves create, update, and refresh. Audit configured outside Terraform is adopted on refresh and then planned for removal; a dropped write surfaces as an inconsistent result after apply.
Implementation gate
The vendored public serverless bundle (public-user-serverless-api-dereferenced.yml) still strips monitoring.logging.* via x-exclude-from-documentation, and so does upstream main. Task 1.1 stops the implementation loop until the public bundle contains monitoring.logging.audit. The raw production user spec was used to author the contract; nothing was vendored in this PR.
Spec-only OpenSpec change adding an optional monitoring.logging.audit
block to ec_elasticsearch_project, ec_observability_project, and
ec_security_project.
- ignore_filter_ids is a set (max 10); null and empty both mean no filters
- destination.status is computed, never sent on write
- clearing audit or filters sends JSON null via Patch*ProjectWithBodyWithResponse
- implementation is blocked until the public serverless API bundle
contains monitoring.logging.audit (task 1.1 stops otherwise)
No provider code changes; no changelog entry for a spec-only PR.
This task says externally configured audit logging is removed unless configuration includes monitoring, but the specified behavior is conditional on monitoring.logging.audit: an empty monitoring/logging shell still has audit unset and the removal path sends "audit":null (spec.md:202-217). Please use the full attribute path here so the implementation and changelog do not promise that a shell preserves audit logging.
This changelog instruction says externally configured audit logging is preserved whenever monitoring is present, but the proposed behavior clears audit whenever monitoring.logging.audit is omitted—even for monitoring = {} or monitoring = { logging = {} } (spec.md:84-88 and 210-217). Change the condition to the audit block so the implementation PR does not document the wrong migration behavior.
…curity
project-api rejects an audit destination without project_type (403
"Unable to determine project type") and accepts only observability and
security projects as logging destinations, even though the API schema
marks project_type optional with the full ProjectType enum. Make the
attribute required with a two-value validator so both fail at plan
instead of apply, and drop the "send only when known" clauses and the
unknown/omitted project_type scenarios that no longer apply.
This changelog instruction is too broad: a configured monitoring shell with no audit does not preserve audit logging. The read requirements say an API audit object is adopted even when the plan has monitoring set with audit null, after which Terraform still plans the audit removal. State the exception as configuration containing monitoring.logging.audit, not merely monitoring, so the implementation changelog does not promise the wrong behavior.
The reason will be displayed to describe this comment to others. Learn more.
Possible inconsistent-result error on apply. If the API ever adds filters server-side while the plan has ignore_filter_ids null, apply would fail with an inconsistent result
I'm not sure it's reasonable to expect server injected filters, but this got flagged. Otherwise LGTM.
Thanks Toby! Good catch, and it's deliberate: Read stores whatever ignore_filters the API returns, so server-added filters during an apply would surface as an inconsistent result rather than being silently absorbed. Same rule as for the audit object and linked today.
I agree there's no reason to expect that case. project-controller only writes destination.status or nulls audit when the destination is hard-deleted; nothing server-side touches ignore_filters. Going optional+computed would also change what null means for users (from "no filters" to "whatever the API has"), so I'd rather not do it speculatively. If acceptance testing ever trips on it, that's our evidence and the spec tweak is small.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Spec-only OpenSpec change for #1065: support audit log configuration on the serverless project resources (
ec_elasticsearch_project,ec_observability_project,ec_security_project) via an optionalmonitoring.logging.auditblock.This PR adds only
openspec/changes/add-serverless-project-audit-logging/(proposal, delta spec, design, tasks). No provider code, docs, or changelog changes.Key decisions
monitoring,logging, andauditare optional;destinationis required only whenauditis set.enableddefaults totrue.ignore_filter_idsis a set of strings, at most 10 (the APImaxItems). Null and an empty set both mean no filters; read preserves whichever form the configuration uses.destination.statusis computed insidedestinationand never sent on write (LoggingDestinationCreateRequesthasadditionalProperties: false).auditsends"audit":null(never"monitoring":null); clearing filters sends"ignore_filters":null. Both go throughPatch*ProjectWithBodyWithResponsebecause generated*T+omitemptyfields cannot encode JSON null. Globalnullable-typeis not enabled.Readserves create, update, and refresh. Audit configured outside Terraform is adopted on refresh and then planned for removal; a dropped write surfaces as an inconsistent result after apply.Implementation gate
The vendored public serverless bundle (
public-user-serverless-api-dereferenced.yml) still stripsmonitoring.logging.*viax-exclude-from-documentation, and so does upstreammain. Task 1.1 stops the implementation loop until the public bundle containsmonitoring.logging.audit. The raw production user spec was used to author the contract; nothing was vendored in this PR.Validation
openspec validate add-serverless-project-audit-logging --type change --strictpasses.Out of scope
Hosted
ec_deployment, a VectorDB project resource, the ignore-filter catalog (list/get only), and log categories other thanaudit.Closes nothing yet; tracks #1065.