5 ms·
The ops people. In many companies access to production is limited.
by wainstead 5y ago
The ops people. In many companies access to production is limited.
- deleted 5y ago[deleted]
- closeparen 5y agoIt's important for data to be limited to those with business need to know, which is why developers (who are responsible for the application) should have access to its data while ops (who are responsible for core infrastructure) must not. I would not put an email address in logs, but definitely some kind of account identifier so that we can investigate bug reports from specific users.
- pastage 5y agoWhat you want to prevent is logdumping to some third party which is a pretty easy exploit in many applications I have touched. Ops always have access to the data I think that is why we have devops, so maybe you are talking about some other kind of ops.