Ziel
One log format across web, worker and AI service so a log shipper can parse and correlate all three without per-service rules. Today web/worker log pino JSON (time, lower-case level labels such as "info", fixed key whitelist – #28 / PR #45) while the AI service logs ts and upper-case levels.
Akzeptanzkriterien
Nicht Teil dieser Aufgabe
- Log shipping, alerting, dashboards.
Betroffene Bereiche
services/ai/src/requestflow_ai/ (logging setup), services/ai/tests/, docs/technical/operations.md
Testplan
| Kriterium |
Prüfart |
| Shared key set + format |
pytest capturing a log line |
| No content in logs |
existing privacy tests + new assertion |
Security/Privacy betroffen?
Logs are a data-leak path – keep the whitelist approach; no request bodies.
Found in the security review of PR #45.
Ziel
One log format across web, worker and AI service so a log shipper can parse and correlate all three without per-service rules. Today web/worker log pino JSON (
time, lower-caselevellabels such as"info", fixed key whitelist – #28 / PR #45) while the AI service logstsand upper-case levels.Akzeptanzkriterien
logEvent:time(ISO 8601),level(lower-case label),event, and correlation keysrequestId,jobId,companyIdwhere known.docs/technical/operations.mddocuments the shared format once.Nicht Teil dieser Aufgabe
Betroffene Bereiche
services/ai/src/requestflow_ai/(logging setup),services/ai/tests/,docs/technical/operations.mdTestplan
Security/Privacy betroffen?
Logs are a data-leak path – keep the whitelist approach; no request bodies.
Found in the security review of PR #45.