Skip to main content

Audit Logs page

Sidebar → Audit Logs. Append-only HTTP-request log of every mutation in the org.

What's recorded​

Every POST / PUT / DELETE to the API surface lands here as one row, regardless of which feature triggered it. Login and register paths are explicitly skipped so passwords never enter the log.

List view​

Server-side filtered + paginated.

ColumnMeaning
WhenTimestamp
WhoUsername + email of the actor
MethodPOST / PUT / DELETE
PathRequest URL (e.g. /api/orgs/<id>/helm/install)
StatusHTTP status code returned
IPClient IP that made the call

Filter chips at the top:

  • Search — full-text on path + username
  • Method
  • Status range (e.g. only 4xx/5xx for errors)
  • Time range (last hour / day / week / custom)
  • Actor (multi-select from members)

Row click → Detail panel​

Right-side drawer with the full row:

  • All list columns plus
  • User-Agent
  • Request body (sanitized) — JSON, with sensitive fields (password, token, kubeconfig, secret, key) replaced with [redacted]
  • Response body — captured as text

The sanitization is centralized in the audit middleware; you can't see passwords no matter who you are. Same for kubeconfigs and tokens.

Admin (cross-org) view​

Admin → Audit Logs shows the same shape across all orgs. Adds two filters:

  • Org (multi-select)
  • Org only toggle — when on, only rows with non-NULL org_id show; when off, super-admin actions (where org_id IS NULL) also appear

What's NOT logged​

  • Reads (GET / HEAD) — they're frequent and noisy
  • WebSocket events
  • Login / register attempts — by design, to keep passwords out of the log. If you need bruteforce detection, that's a separate feature (TODO)

Retention​

Today: keep forever. No prune job. If disk pressure shows up, your admin would add a goose migration to truncate old rows; out of scope here.

Common questions​

"Who installed X release on Y date?" Filter: path contains helm/install, time range, search by release name in the request body. The actor + timestamp are right there.

"Who promoted Alice to admin?" Filter: path contains /members/, search "Alice's email" in the request body. Should match a PUT .../role call.

"Did the API return errors today?" Filter: status range 400-599, time range today. The path tells you which feature.

See also​