Skip to main content

OpenTelemetry Audit Logs

Extensions – OIDC

Last Updated: 1 minute read

XProtect services have been configured to provide bearer tokens that contain information unique to services. The tokens can be validated using the OIDC authenticator extension:

extensions:

oidc/server: # OIDC extension with the unique name 'server' issuer_url: https://localhost/IDP # URL to IDP server

audience: serverlogs # Specific audience to verify on each incoming token issuer_ca_path: [PATH TO CERTIFICATE] # CA public certificate of IDP server attribute: authorization # Name of the header with the bearer token (Case sensitive!)

Please ensure that the “issuer_url” and the “issuer_ca_path” are set correctly, the other parameters must not be modified.

receivers:

otlp/server:

protocols:

http: # Use HTTP Protobuf

endpoint: "0.0.0.0:4318" # Listen on port 4318 and accept any address auth:

authenticator: oidc/server # OIDC extension configuration matching the unique name 'server' tls:

cert_file: [PATH TO SERVER CERTIFICATE] # Public server certificate key_file: [PATH TO SERVER CERTIFICATE KEY] # Private server key

processors:

resource/authtoken: # resource processor with the unique name 'authtoken' attributes:

- key: oidc.sub # Include the subject of the token in the log message action: upsert

from_context: auth.subject