Skip to main content
RunBook Academy

← All runbooks in Observability

critical riskdata loss risk~30 min

Runbook: Respond to a Telemetry Data Leak

1 · Prerequisites

Confirm every item is in place before any state change.

  • Loki
  • Tempo
  • Trace / Log content

2 · Pre-checks

Read-only diagnostic commands. If any of these don't match expected output, stop and investigate further.

  • · Identify the affected service
  • · Identify the sensitive data type
  • · Contain the leak

3 · Procedure

Execute each step in order. Verify the expected output of a step before moving to the next.

  1. 1Contact the service team to redact
  2. 2Use redaction in the agent (Alloy / OTel Collector)
  3. 3Prune the affected logs / traces
  4. 4Investigate how the data reached telemetry
  5. 5Document the leak
  6. 6Notify compliance / security

4 · Verification

Confirm the procedure actually fixed the problem.

  • Sensitive data is no longer in telemetry
  • Telemetry is back online
  • Compliance is notified

5 · Rollback

If verification fails, undo the procedure in reverse order.

  • Disable the affected telemetry source temporarily

6 · Escalation

When the runbook isn't enough, contact:

  • · Engage security / compliance team
  • · Engage legal if needed

Purpose

Respond to a Telemetry Data Leak

When to use this runbook

Use this runbook when the operator needs a guided procedure to handle the situation described above.

Pre-checks

Before starting the procedure, confirm the prerequisites and pre-checks are met. The structured lists are rendered from the frontmatter by the page layout.

Procedure

Follow the steps from the frontmatter procedure steps. The page layout renders the steps as a checklist with copy-to-clipboard affordances.

Verification

After the procedure, the structured verification items from the frontmatter are rendered as a checklist.

Rollback

If the procedure fails or makes things worse, follow the structured rollback steps from the frontmatter.

Escalation

The structured escalation path is rendered from the frontmatter. Use it if the operator cannot complete the procedure safely.

References

  1. Prometheus documentation
  2. Grafana documentation
  3. Loki documentation
  4. Tempo documentation