Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

remove data_access_logs_enabled #1286

Open
eeaton opened this issue Jul 1, 2024 · 1 comment
Open

remove data_access_logs_enabled #1286

eeaton opened this issue Jul 1, 2024 · 1 comment
Labels
backlog enhancement New feature or request v5.0

Comments

@eeaton
Copy link
Collaborator

eeaton commented Jul 1, 2024

TL;DR

There is no practical recommendation to use data_access_logs_enabled in any realistic scenario. I suggest we remove it.

An earlier version implemented this variable by default and rolled it back when customers were unhappy with the surprise large bill caused by data access logs; it was later switched to false by default and requires explicit enablement. However, my argument is that this variable has no use because we would never recommend turning on all data access logs for all services, it generates an enormous amount of noise and cost. The choice to enable data_access_logs should be based on the requirements of specific workloads, in the context of data sensitivity and regulatory requirements. (not a foundation-wide control)

Terraform Resources

Remove all references to [`data_access_logs_enabled`](https://github.com/search?q=repo%3Aterraform-google-modules%2Fterraform-example-foundation+data_access_logs_enabled&type=code)

Detailed design

No response

Additional information

No response

Copy link

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days

@github-actions github-actions bot added the Stale label Aug 30, 2024
@eeaton eeaton removed the Stale label Sep 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backlog enhancement New feature or request v5.0
Projects
None yet
Development

No branches or pull requests

1 participant