Agent skill

Configuration Logging

by greenpau in greenpau/caddy-security

Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Logging

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-logging -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-logging --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-logging .claude/skills/configuration-logging && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-logging
GitHub stars
2.3k
Token cost
~2.1k tokens
SKILL.md length
958 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary.

  • Component/message filtering
  • SKILL.md covers Supported Scope, Configuration, Missing Caddy Host Extension and Validation
  • Calls make and go
  • Access logs and authorization outcomes are separate concerns

What it does

Configuration Logging is an agent skill from greenpau/caddy-security. Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Use for component/message filtering; access logs and authorization outcomes are separate concerns.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Component/message filtering
  • Access logs and authorization outcomes are separate concerns

Example prompts

  • “/configuration-logging”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Logging loads about 2.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 958 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 958 words, ~2,132 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-logging/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuration-logging
description
Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Use for component/message filtering; access logs and authorization outcomes are separate concerns.

Configuration Logging

Supported Scope

The root security logging block configures AuthCrunch component diagnostics. Caddy v2.11.7's independent http.handlers.authentication logger remains unfiltered. Issue #280 is not fixed by this adapter. Read the host boundary below before recommending the issue's message/error patterns to an operator. Current authorize Caddyfiles use http.handlers.authorization; the legacy JSON authentication-provider chain is still supported and emits the host error. Do not change that chain's behavior to silence it.

Published AuthCrunch v1.3.4 supplies Config.Logging, pkg/logging, the shared parser, and root logger wrapping. No local replacement or library release is needed for these interfaces. Recheck go list -m -json when dependencies change; the dependency workflow owns selection changes. Sibling source and skills remain read-only references.

Configuration

Inside the global options block:

caddyfile
{
	security {
		logging {
			skip exact text "token validation error"
		}
	}
}

This suppresses the AuthCrunch gatekeeper's diagnostic message; it leaves its returned errors, HTTP denial, redirects and authorization decisions unchanged. Other security declarations and site routes are configured normally.

The complete body grammar is one statement per line:

text
skip <exact|partial|prefix|suffix|regex> text <value>

Every statement has four tokens. Quote multiword values. Repeated rules, including identical rules and imported rule bodies, append in order and match with OR. Duplicate logging blocks, header arguments, nested blocks, empty tokens, malformed keywords/arity, invalid regular expressions, whitespace-only text and raw newlines are rejected with location-aware errors. Omission or an empty multiline block suppresses nothing; there are no implicit rules. The enclosing global security option also occurs once; repeating it fails instead of silently replacing the earlier app and discarding its rules.

Matching is case-sensitive. Exact compares the whole value, partial finds a substring, prefix/suffix match an edge, and regex uses Go regexp semantics (unanchored unless the pattern supplies anchors). Spaces, quotes, Unicode and regex escapes survive Caddy tokenization, argument encoding and JSON. Patterns are literal during provisioning: {env.*} and secrets:* are not expanded. Caddy's normal {$ENV} preprocessing still occurs before tokenization.

The library compares the message and individual string, byte-string, error and Stringer values, including fields bound after wrapping by With/WithLazy. Keys, logger names, numeric values, arrays and object contents are outside this selector. In the host error, reason: no token found occurs in the error field, not in the message. The component's error field contains no token found without that host prefix; a partial rule for that value selectively suppresses its missing-token diagnostics while retaining malformed-token diagnostics.

Native Caddy JSON stores the library type directly:

json
{"apps":{"security":{"config":{"logging":{"skip":[
  {"match":"exact","text":"token validation error"}
]}}}}}

caddyfile_logging.go collects the complete block with Caddy's tokenized values, rejects empty arguments/unsupported structure, encodes each statement with cfgutil.EncodeArgs, then calls logging/parser.NewLoggingConfigFromDirectives. Do not split or concatenate tokens manually, implement another matcher, or publish a partial config. App.Provision copies the declarative graph through JSON and invokes the library's Config.Validate before constructing/serving. NewServer creates an immutable filter and wraps its supplied logger before creating components. The app's original base logger and unrelated host/access logs remain unchanged; Caddy retains flushing and lifetime ownership.

Reload creates a new app/runtime/filter from the base logger. Replacing/removing rules cannot mutate the old instance or accumulate wrappers. Logging is excluded from AuthCrunch's persistent-session binding: logging-only stop/start changes retain refresh sessions. Existing runtime restrictions still apply: overlapping persistent roots or local identity files are rejected. Do not relax those restrictions for logging changes.

Show full SKILL.md (439 more words)Show less

Missing Caddy Host Extension

Trace the pinned host before attempting integration:

  • modules/caddyhttp/caddyauth/caddyauth.go: Authentication.Provision saves ctx.Logger() into its private logger before loading providers. Authentication.ServeHTTP calls that logger's Check and Write on returned provider errors, attaching provider and zap.Error(err).
  • context.go: Context.Logger calls Logging.Logger. There is no supported instance logger setter/wrapper. Slog factories do not intercept these Zap calls.
  • logging.go: Logging.Logger assembles configured cores and names the result. BaseLog.provisionCommon installs CoreRaw using zapcore.NewTee(cl.core, core); the extension does not receive the existing core, so dropping its own copy cannot suppress the original output. Logging setup runs before app provisioning. Encoder/writer modules are too late to preserve the requested pre-sampling, typed-field, full-entry semantics.

The required upstream change is an instance-owned wrapping hook reached by the actual authentication logger. A concrete option is an opt-in provider interface that accepts the middleware's original *zap.Logger and returns a wrapped clone or error during provisioning. Caddy would retain a clone per provider and use it for that provider's actual error call. The authorizer could then supply logging.NewFilter(config.Logging).WrapLogger(base). Install it before any With/WithLazy fields; retain the base logger and existing Sync owner. This is a proposed upstream contract, not an API available in v2.11.7.

A supported scoped core-wrapper hook is another option, provided it wraps the existing core rather than tees beside it and is isolated to the correct configuration/module. Use the library wrapper to preserve samplers, tees, hooks, error output and terminal actions. Do not add global mutable filters, unsafe private-field access, a Caddy fork, dead-code wrappers, or an alternate authentication implementation. Never swallow a returned error or permit a protected handler to avoid a diagnostic.

Validation

caddyfile_logging_test.go covers the issue's exact example, all matchers, encoding, imports/repetition, malformed grammar/structure, omission/empty blocks, native JSON validation, public config-file round trips and provisioning. Adaptation fixtures are testcase_security_logging, testcase_security_logging_matchers and testcase_security_logging_empty. TestAppLoggingInstanceIsolation checks multiple simultaneous runtime filters, detached snapshots, the unchanged base logger and rule removal.

TestCaddyLoggingE2E builds the actual race-enabled Caddy command and captures JSON output. It uses verified local TLS, temporary identity databases, both current and legacy routes, real password login and a counted protected upstream. It proves baseline noise; error-only/message-only/combined host rules remaining ineffective; selective component filtering; all matchers, case sensitivity and OR; unchanged denials/success; unrelated access/app output; two live processes; replacements, removal and invalid-JSON rollback. Its persistent journey rotates the same refresh session across logging-only stop/start replacements.

These passing tests certify the consumer/component integration and the known host limitation. They do not satisfy the issue's host-suppression acceptance criteria. Once the host hook exists, require error-text-only suppression of missing-token errors while malformed-token errors from the same logger remain, and message-only suppression of the middleware message, through this real process.

sh
make test TEST='TestParseCaddyfileLogging|TestLogging|TestAppLogging|TestCaddyLoggingE2E|TestCaddyfileAdaptAuthenticationToJSON|TestResolveRuntimeAppConfig' TEST_DIR=. COVERAGE_DIR=.coverage/logging

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/configuration-logging of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Logging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Logging this skillgreenpau/caddy-security2.3k—~2.1kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Convex Setup Authspokvulcan/poker-planning1148 repos~1.8kAutomated safety check: PassMIT
Abp Authorizationabpframework/abp14k—~1.3kAutomated safety check: PassLGPL-3.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    spokvulcan/poker-planning

    Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

    114 GitHub starsUsed in 8 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • UI Audit

    bagofwords1/bagofwords

    Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…

    458 GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Configuration Logging

What does Configuration Logging do?

Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Configuration Logging is an agent skill from greenpau/caddy-security. Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary.

When should I use Configuration Logging?

Configuration Logging fits situations like: component/message filtering; access logs and authorization outcomes are separate concerns.

How do I install Configuration Logging in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-logging -a claude-code`. Or copy the skill folder (.codex/skills/configuration-logging in greenpau/caddy-security) into .claude/skills/configuration-logging in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Logging in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-logging -a codex`. Or copy the skill folder (.codex/skills/configuration-logging in greenpau/caddy-security) into .agents/skills/configuration-logging in your project. Codex loads it when a task matches its description.

Can I use Configuration Logging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-logging, .gemini/skills/configuration-logging, .github/skills/configuration-logging and .opencode/skills/configuration-logging in your project.

What does Configuration Logging need to run?

Going by SKILL.md and its folder, Configuration Logging needs the command-line tools its instructions call (make and go).

Does Configuration Logging access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Logging safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Logging use?

Configuration Logging is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Logging use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuration Logging?

Skills that share tags, products or a category with Configuration Logging: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Logging?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.