Well, there should only be a few people with the access needed to discover logging is happening.
You'll have a server image where SSH can be toggled on using a config value in the test environment, to assist in debugging. That's normal. Don't worry, it's turned off in production. Obviously you're going to deploy the same server image you tested, only idiots test one thing and deploy another.
And you'll have a high security configuration management tool, to look after your production TLS keys and suchlike. Only a tiny handful of people have access to view production configuration values.