Skip to content

fix: ship an active logback.xml defaulting to INFO - #104

Closed
hongwei1 wants to merge 4 commits into
develop-obpfrom
fix/logback-default-info-level
Closed

hongwei1 wants to merge 4 commits into
develop-obpfrom
fix/logback-default-info-level

Conversation

@hongwei1

@hongwei1 hongwei1 commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • logback.xml.example sat in src/main/resources with <root level="DEBUG">, but the .example suffix means Logback never auto-loads it. Deployments that never manually copy it over (which, on the affected sandbox, is all of them) get Logback's own built-in fallback configurator instead -- which also happens to default to DEBUG-to-console. Same visible symptom, but the file itself was inert; there was no actual lever to turn the level down short of hand-authoring a real logback.xml per deployment.
  • Verified directly against a running deployment: extracted the actual jar from a live container (unzip -p obp-api.jar logback.xml) and confirmed no logback.xml (without the suffix) exists inside it.

Change

  • Renamed logback.xml.example -> logback.xml so it's picked up automatically.
  • Changed the hard-coded DEBUG to ${LOG_LEVEL:-INFO} -- Logback's standard default-value substitution (supported since 1.0.x; this repo is on 1.5.18), resolved from a JVM system property or OS environment variable, falling back to the literal default when unset. A plain LOG_LEVEL=DEBUG container env var is enough to override; no need to route through -Dlogback.configurationFile for that part.
  • Default is INFO, not DEBUG: an opt-out-of-quiet default means every deployment silently pays full log volume -- including the per-message masking pass in SecureLogging (see fix: gate MdcLoggable masking on log-level and Redis-shipping checks #102) -- unless someone remembers to turn it down. Verbose logging should be an explicit per-environment opt-in instead.
  • Updated the two docs (README.md, docs/brief_system_documentation.md) that described the old manual-copy workflow.
  • logback-test.xml.example is untouched -- it's a separate, already-active setup for test runs (src/test/resources/logback-test.xml already exists and takes priority during tests regardless of this change).

Test plan

  • mvn -pl obp-commons,obp-api -am compile -DskipTests -o -- BUILD SUCCESS, logback.xml (not .example) confirmed present in target/classes.

Superseded -- squashed together with #102 and #103 into one combined commit, PR'd upstream directly: OpenBankProject#2920

logback.xml.example sat in src/main/resources with root level DEBUG,
but the .example suffix means Logback never loads it -- deployments
that never manually copy it over get Logback's own built-in fallback
configurator instead, which also happens to be DEBUG-to-console. Same
visible symptom, but the file itself was inert; there was no actual
lever to turn the level down short of hand-authoring a real logback.xml
per deployment.

Rename it to logback.xml so it's picked up automatically, and change
the hard-coded DEBUG to ${LOG_LEVEL:-INFO} (Logback's standard
default-value substitution, resolved from a system property or OS
environment variable, falling back to the literal default when unset).
Default is INFO, not DEBUG: an opt-out-of-quiet default means every
deployment silently pays full log volume -- including the per-message
masking pass in SecureLogging -- unless someone remembers to turn it
down. Verbose logging should be an explicit per-environment opt-in via
LOG_LEVEL instead.

Also updates the two docs describing the old manual-copy workflow.
logback-test.xml.example is untouched; it's a separate, already-active
setup for test runs.
Follow-up to the previous commit: these two docs both described the
old "copy logback.xml.example to logback.xml yourself" workflow, which
is now stale now that logback.xml ships active. Point at LOG_LEVEL
instead.
The previous commit only renamed logback.xml.example to logback.xml;
the actual level change didn't make it into that commit. Change the
hard-coded DEBUG to ${LOG_LEVEL:-INFO}: an unset LOG_LEVEL now falls
back to INFO instead of DEBUG, and any environment that wants more can
set LOG_LEVEL=DEBUG or TRACE explicitly.
Added a direct test that parses the shipped logback.xml into a fresh
LoggerContext via Joran (the same parser Logback uses internally) with
LOG_LEVEL set beforehand, since the application's own LoggerContext is
configured once at JVM start and wouldn't exercise the default-value
resolution this fix depends on.

Writing it caught a real bug: the explanatory comment above <root>
contained a bare "--", which XML disallows anywhere inside a comment
body, not just at the delimiters. Xerces rejected the file outright
(SAXParseException) rather than silently ignoring the comment, so this
would have broken every deployment picking up this branch, not just
this test. Reworded the comment to drop the double dash.
@sonarqubecloud

Copy link
Copy Markdown

@hongwei1

Copy link
Copy Markdown
Owner Author

Superseded — squashed together with #102 and #103 into one combined commit, PR'd upstream directly: OpenBankProject#2920

@hongwei1 hongwei1 closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant