Skip to content

Commit 19495ef

Browse files
fmountclaude
andcommitted
Fix client IP logging in Keystone API VirtualHost
The VirtualHost CustomLog directive was overriding the server-level dual-log setup, causing all requests to be logged with the OpenShift router IP instead of the real client IP from X-Forwarded-For. Add SetEnvIf and dual CustomLog lines inside the VirtualHost block to match the nova-operator pattern. Closes: OSPRH-32109 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Francesco Pantano <fpantano@redhat.com>
1 parent 981eddc commit 19495ef

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

templates/keystoneapi/config/httpd.conf

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,9 @@ CustomLog /dev/stdout proxy env=forwarded
4141
## Logging
4242
ErrorLog /dev/stdout
4343
ServerSignature Off
44-
CustomLog /dev/stdout combined
44+
SetEnvIf X-Forwarded-For "^.*\..*\..*\..*" forwarded
45+
CustomLog /dev/stdout combined env=!forwarded
46+
CustomLog /dev/stdout proxy env=forwarded
4547

4648
{{- if $vhost.TLS }}
4749
SetEnvIf X-Forwarded-Proto https HTTPS=1

0 commit comments

Comments
 (0)