HydraIssues

Edge traefik has no access logging, so a request that fails before a service is invisible
open improvement Project: hydrascalerouter Reporter: cederik 14 Sep 2026 10:30

Description

PROBLEM

The edge at 141.227.136.199 (traefik plus hydrascalerouter) records only lifecycle events. journalctl -u traefik over three days returned 13 lines, none of them per-request. There is no record of which requests arrived, for which Host, from where, or what status they got.

WHY IT MATTERS, with a concrete cost

While debugging #644 a dashboard visit from a new Android tablet appeared to vanish. hydraorganization logged nothing, so the investigation concluded the request was never arriving and spent two rounds on DNS, TLS chains and network routes. In fact the request arrived fine and hit an uninstrumented path on the service. One line of edge access log would have shown the request, its Host, its path and its status, and ended the question immediately.

Every service behind this edge has the same blind spot. When a request fails before reaching a service, or reaches the wrong service, there is nothing to look at.

ASK

Enable traefik access logging with bounded retention, recording at least: timestamp, client address, Host, method, path, status and duration. Keep the volume sane with rotation, and be deliberate about NOT logging query strings, since sessions have travelled in them (see #591).

ACCEPTANCE

  • A request to any domain behind the edge appears in an access log with Host, path and status.
  • The log rotates and cannot fill the disk.
  • Query strings are excluded or scrubbed, so a session token in a URL is never written to disk.
  • The hydrascalerouter or hydraskin runbook records where the log lives and how to read it over the hydracluster exec transport.