Reliable multi-tenant auto setup audit capability
Find a file
tegwick 576caa2665
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Redact secret-shaped fields by default, countable per field path
AUDIT-WP-0004-T04, closing the workplan.

Decision (Bernd): default to redaction, allow rejection per sender. Losing an
audit record over one field is worse than storing it masked, but a
higher-assurance channel must be able to refuse rather than mask. secret_policy
is set per sender identity in AUDIT_CORE_SENDERS and defaults to redact.

Detection now covers the whole payload at any depth, including lists, rather
than only the top level of data. Under redaction the value is masked and the
key is preserved: dropping the key would hide that the sender transmitted the
field at all, which is exactly what an operator needs in order to stop it. The
stored record carries details.redaction with policy and affected paths, so a
reader never has to infer whether what they see is what was sent.

Idempotency is unaffected - the payload hash is taken over the original request
body, so redaction is deterministic and a resubmission still reconciles as a
duplicate.

Both outcomes are counted durably by sender, source, action and field path,
exposed at GET /v1/secret-findings. Per-path aggregation is the point: the
actionable unit is "stop emitting data.auth.token on membership.added", not
"there were 47 redactions". Counters survive restart because the fix they drive
lives in another service.

Contract doc updated to match. Tests 46 -> 50. WP-0004 is finished.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 16:02:22 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 5) 2026-07-08 19:50:55 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:28:40 +02:00
audit_core Redact secret-shaped fields by default, countable per field path 2026-08-10 16:02:22 +02:00
docs Redact secret-shaped fields by default, countable per field path 2026-08-10 16:02:22 +02:00
registry Add capability registry with seed entry from reuse-surface 2026-06-16 01:46:53 +02:00
spec Added PRD for what we want to do 2026-06-01 23:38:26 +02:00
tests Redact secret-shaped fields by default, countable per field path 2026-08-10 16:02:22 +02:00
workplans Redact secret-shaped fields by default, countable per field path 2026-08-10 16:02:22 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-10 12:44:56 +02:00
.gitignore Initial commit 2026-06-01 21:16:10 +00:00
.repo-classification.yaml Human-review .repo-classification.yaml (CUST-WP-0050 follow-up) 2026-06-22 17:56:17 +02:00
AGENTS.md Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01) 2026-07-08 14:50:17 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:24 +02:00
Containerfile Bind sender identities, add operator read surface, real serving layer 2026-08-10 14:50:02 +02:00
INTENT.md Seeded repo with intent 2026-06-01 23:20:04 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-29 23:53:10 +02:00
Makefile Add mock file audit backend 2026-06-01 23:44:03 +02:00
pyproject.toml Bind sender identities, add operator read surface, real serving layer 2026-08-10 14:50:02 +02:00
README.md Moved audit forward somewhat 2026-07-04 00:39:03 +02:00
SCOPE.md Seeded intent, scope and workplan 2026-06-22 17:52:32 +02:00
WORK-RECORDS.md Redact secret-shaped fields by default, countable per field path 2026-08-10 16:02:22 +02:00

Reliable multi-tenant auto setup audit capability

Backend contract

The pluggable backend interface, event schema (audit-core.event.v1alpha1), retention policy, and migration path from the mock file backend are documented in docs/audit-backend-contract.md.

Development Mock Backend

The first implementation is intentionally tiny: a replaceable audit interface with a mock file backend.

By default it writes JSONL audit events to:

/tmp/audit-core/audit-YYYYMMDDTHH.jsonl

Files older than 7 days are removed when the backend writes or when cleanup is run explicitly. This backend is for local integration and bootstrap wiring. It is not durable audit custody.

Example:

python3 -m audit_core emit \
  --source openbao \
  --action openbao.authenticated_readiness_proof \
  --resource openbao/openbao-0 \
  --outcome success \
  --detail file_audit_visible=true \
  --detail backend=mock-file

Cleanup:

python3 -m audit_core cleanup

Make targets:

make test
make mock-audit-smoke
make mock-audit-cleanup

Environment:

  • AUDIT_CORE_MOCK_DIR: override the output directory.
  • AUDIT_CORE_MOCK_RETENTION_DAYS: override the default 7-day cleanup window.