What this collects
What leaves your build, and how to send less of it.
Every build is one trace: a build span, a span per stage, and under each stage a
span per phase and per Dockerfile command.
What leaves the machine
- Timings and the cache outcome for every instruction, plus the instruction text verbatim.
- Your Dockerfile source and the build plan.
- Cache keys, when
--cacheis on. - Explicitly-set
FF_KANIKO_*feature flags and their values. Flags left at their defaults are not reported. - Registry connection counters and timings: sockets, requests, TLS and dial time.
- Where the build ran: repo path, pipeline, commit sha and branch. From v1.28.5
kaniko reads these from your CI's predefined variables. Before that, your
pipeline passes them in
OTEL_RESOURCE_ATTRIBUTES.
kaniko's own telemetry attributes is the authoritative list, attribute by attribute. It is the emitter, so it is the thing to check rather than this page.
Nothing beyond that is captured. The value behind a RUN --mount=type=secret
and the contents of a --mount=type=cache never reach a trace.
Your instruction text does, though. If a RUN line carries a credential, that
credential is in the trace โ treat this backend as inside your secret boundary.
Sending less
KANIKO_TELEMETRY_OMIT_DOCKERFILE=true keeps both the Dockerfile source and the
build plan out of the trace. Timings, cache outcomes and the instruction ranking
all still work; the build history loses the panel that overlays timings on your
source.
Before v1.28.5, dropping entries from OTEL_RESOURCE_ATTRIBUTES sends less about
where a build came from. None of it is required โ the fleet views simply show
fewer columns.
Turning it off
Unset KANIKO_TELEMETRY_ENDPOINT. kaniko exports nothing and builds exactly as
it did before: there is no agent and no background process to remove.