Logging and Observability¶
Source of truth: internal/logging/logging.go, internal/middleware/middleware.go, installer scripts. The Go process always writes slog to os.Stdout. There is no application file logger.
Application logger¶
| Setting | Default | Effect |
|---|---|---|
LOG_FORMAT |
json |
JSON slog; only text switches to text |
LOG_LEVEL |
debug |
debug / info / warn / error |
Always-on fields from logging.New: service, environment, instance_id, version.
Go slog.JSONHandler also emits time, level, msg.
Where logs go¶
| Runtime | Destination |
|---|---|
Console serve |
Process stdout |
| Windows Native | Process stdout (SCM typically discards it). Installer file: C:\IQVizyon\IQVIntegrationAPI\logs\installer-update.log. Event Log source is registered; application slog is not written there. |
| Linux Native | systemd journal (journalctl -u iqv-integration-api.service). /var/log/iqvizyon/iqv-integration-api is a unit ReadWritePaths directory, not an application log file sink. |
| Docker | Container stdout/stderr → Docker json-file (max-size: 10m, max-file: 5) |
```bash
Linux native¶
sudo journalctl -u iqv-integration-api.service -f
Docker¶
docker logs -f
request_id¶
- Header:
X-Request-ID(internal/requestid) - Missing/invalid → new UUID
- Echoed on the response and stored in the JSON envelope as
request_id - Access logs include
request_id
Access log fields¶
middleware.RequestLogger: timestamp, request_id, method, path, status_code, duration_ms, remote_ip, user_agent, message.
Panic recover adds panic, stack. HTTP start/stop may log addr, tls_mode.
Collecting logs for troubleshooting¶
- Capture
/health/liveand/health/readyresponses (no secrets). - Collect installer/update logs (Windows
installer-update.log; Linux script stdout). - Collect application stdout/journal/
docker logsfor the samerequest_id. - Collect
deployment.json/ Linux deployment metadata (no secrets). - Do not attach
.env, Mongo URIs, tokens, or raw request bodies.
Never log¶
- Authorization headers
- Client secrets / JWT secrets
- Access tokens / passwords / private keys
- Unredacted MongoDB URIs
- Full sensitive request bodies
- Integration actor ObjectIDs
Config.RedactedMap() redacts mongodb_uri and health-push bearer tokens and exposes only integration_actor_configured (boolean).