Audit log: who did what, where and when
The Kubepier audit log shows who did what, on which client, cluster and resource, when, and whether it worked. On the web, entries live in the organization database and show up in the Audit log menu; on desktop, they live in the kubepier-audit.log file on your machine and show up in Preferences › TR › Audit. Metadata only: never the content.
What it does
- Web: lists the actions recorded in the organization database, newest first, with filters, the details of each row and CSV export.
- Desktop: lists what was done from this computer, read from kubepier-audit.log and kubepier-audit.log.1, with filters and CSV export.
- Web and desktop share the same action codes, groups and labels (Edited YAML, Purged queue, Opened shell…).
Where to find it
- Web: the Audit log item in the app sidebar, right above Plans. Everyone in the organization sees it, admin or member, on any plan.
- Desktop: Preferences › TR › Audit. The viewer arrived in 2.5.0; kubepier-audit.log has been written since 2.2.0.
Who sees what
| Plan and role | What shows up | Period | Export CSV |
|---|---|---|---|
| Web, Free | A preview: only your own entries, with a notice and a See plans button | Today or 7 days (at most the last 7 days) | No (the button shows a lock) |
| Web, Pro and Team, admin | The whole organization, with a user filter | Today, 7 days, 30 days or Custom, up to 90 days per query | Yes |
| Web, Team, member | Only your own entries, on the clients granted to you | Today, 7 days, 30 days or Custom, up to 90 days per query | Yes |
| Desktop, any plan | What was done on this computer, under your Kubepier account (email in the Who column) | Today, 7 days, 30 days or Custom | Yes |
On the web, the API enforces the rule, not just the screen: a member cannot request someone else’s entries or those of a client not granted to them.
On desktop, the recorded actions mostly belong to paid plans (edit, shell, tunnel, service actions, AI); from 2.7.0, port-forward, which is free on Free, is recorded too. On Free, the list only shows what was done while the organization had a paid plan.
Filters (web)
- Period: Today, 7 days (the default), 30 days or Custom, with From and To dates. Custom accepts up to 90 days; beyond that, the screen says "Up to 90 days per query." and does not search. On Free, only Today and 7 days.
- User: everyone or one person on the team. Admins only, on Pro and Team.
- Client and cluster: the cluster list follows the chosen client.
- Actions: a menu of checkboxes grouped by area (Cluster, Terminals, Cluster route, Data services, AI, Team and Setup and billing). You can tick several.
- Result: All, ok or error.
- Search: by target, namespace or cluster name, up to 100 characters.
- Clear filters resets user, client, cluster, actions, result and search; the period stays.
List and details (web)
- Columns: When (how long ago, with the full date and time on hover), Who (name and GitHub username), Action, Client, Cluster / namespace / target, Result and Duration (on shell and bastion close).
- 50 entries at a time; the Load more button brings the next 50.
- Click a row to see its details: date and time, kind, namespace and the action metadata, such as replicas, container, image, messages before and removed, queue threshold, TTL, size in bytes, field, new name, key count and names, AI provider and whether events and logs were sent, route before and after, role and granted clients. When it failed, the error message shows below.
- Someone who left the organization shows as Removed user; their entries stay.
Export CSV (web)
- Export CSV downloads the entries matching the current filters, up to 10,000 rows, as kubepier-auditoria-YYYYMMDD.csv.
- Columns: criado_em, usuario, github, acao, resultado, cliente, cluster, namespace, tipo, alvo, duracao_segundos and erro. The action is written as its code (for example, purgar_dlq).
- UTF-8 with a BOM, so Excel opens accented characters correctly.
- Spreadsheet-safe: every field is quoted, and a value starting with =, +, -, @, tab or carriage return gets a leading apostrophe so it is not read as a formula.
- Pro and Team only. Admins export the organization; members, their own entries.
What is recorded
| Area | Actions, as the screen shows them | Where |
|---|---|---|
| Cluster | Edited YAML, Scaled, Restarted, Deleted resource | Web and desktop |
| Cluster | Applied YAML, Cordoned node, Uncordoned node, Drained node | Desktop |
| Terminals | Opened shell, Closed shell | Web and desktop (pod and node shells) |
| Terminals | Opened bastion, Closed bastion | Web |
| Cluster route | Created relay, Removed relay | Web (cluster route relay) and desktop (Secure tunnel relay pod) |
| Cluster route | Changed connection route | Web |
| Cluster route | Opened secure tunnel, Closed secure tunnel | Desktop |
| Data services | Purged queue, Purged DLQ, Wrote Redis value, Wrote Redis hash field, Deleted Redis hash field, Set Redis TTL, Renamed Redis key, Deleted Redis keys | Web and desktop |
| Data services | Set queue threshold, Removed queue threshold, Removed Redis TTL | Web |
| AI | Requested AI diagnosis | Web and desktop |
| Team | Invited to the team, Canceled invitation, Accepted invitation, Changed member, Removed member | Web |
| Setup and billing | Add, edit and remove a cluster; create, edit and remove a Client; save and remove a credential; add, edit, remove and sync a cloud account; subscribe to and cancel a plan | Web |
Each entry carries who, when, client, cluster, namespace, kind and target name, the result and, when present, the error and the action metadata.
On the web, every attempt to edit, scale, restart or delete is recorded, even a failed one. On desktop, cordon, uncordon and drain record that the command was sent, not its result.
Setup and billing keeps metadata only: who, when, the cluster, Client or account name and the result. Never the credential, the kubeconfig or payment data.
From desktop 2.7.0, kubepier-audit.log also records Helm (install, upgrade, rollback and uninstall), port-forward (Free included) and opening and closing the local terminal.
What is never recorded
- Content: the applied YAML, manifest or patch, what is typed in a terminal and its output, queue message bodies, Redis key values, the text sent to the AI and its answer.
- Credentials: passwords, keys, tokens, connection strings and certificates.
- Reads: opening lists, viewing logs, peeking messages and browsing Redis are not audited.
- On the web, the screen and the CSV go through a fixed list of metadata fields: any other field is dropped before leaving the server, and long texts are cut at 300 characters.
- On desktop, the viewer reads only who, when, action, cluster or client, target, result and duration; the rest of the line stays out of the screen and the CSV.
What is accepted
- Periods Today, 7 days, 30 days and Custom. On the web, up to 90 days per query; with Custom you can query any window of up to 90 days in the past (Pro and Team).
- Several actions at once in the filter (up to 40, on the web).
- Search of up to 100 characters (web).
What is not accepted
- More than 90 days in a web query, or a From date after the To date.
- On Free: entries older than 7 days (the period starts at most 7 days ago), other people’s entries and CSV export.
- A member seeing what other people did, or entries of clients not granted to them.
- Editing or deleting entries: the web audit log is insert-only, and not even an admin deletes a row.
Limits and timeouts
| Limit | Value |
|---|---|
| Entries at a time (web) | 50, with Load more |
| Default period | 7 days |
| Period per query (web) | up to 90 days |
| Free preview (web) | your own entries from the last 7 days, no CSV |
| Export CSV (web) | up to 10,000 rows, on Pro and Team |
| Search (web) | up to 100 characters |
| Entries per page (desktop) | 100, with Previous and Next |
| Local file (desktop) | kubepier-audit.log; past 5 MB it becomes kubepier-audit.log.1, replacing the previous one |
How long it is kept
- Web: the audit table is insert-only and nothing deletes it automatically. Entries are kept while the organization exists; the screen queries up to 90 days at a time, and Custom reaches older periods.
- Web: someone who leaves the organization stays in the entries as Removed user, and a removed cluster keeps its name in the entry.
- Desktop: there is no time limit; the limit is size. When kubepier-audit.log passes 5 MB it becomes kubepier-audit.log.1 (replacing the previous .1) and a new file starts. The viewer reads both; whatever was in the old .1 is lost.
- Desktop: the file stays in the app data folder on your machine and is not sent to the Kubepier server.
Desktop: Preferences › TR › Audit
- The viewer reads kubepier-audit.log and kubepier-audit.log.1 in the app data folder. A log under the old name (tr99-data-audit.log) is renamed on the first write, so its history stays in the same file.
- Columns: When, Who (the email of the signed-in Kubepier account; "—" when signed out), Action, Cluster/client, Target, Result and Duration.
- Filters: Period (Today, 7 days, 30 days or Custom, with From and To), Action (grouped by the same areas as the web), Cluster/client and a name search (who, cluster, target).
- 100 entries per page, with Previous and Next. Refresh reads the file again.
- Export CSV saves every filtered entry, not just the page, in UTF-8 with a BOM and the same formula protection as the web, as kubepier-auditoria-YYYY-MM-DD.csv.
- Open folder reveals the file in your file manager. If there is no log yet, the screen says "There is no audit log on this computer yet."
- Lines that cannot be read are skipped, and the screen says how many.
Presentation mode
- With presentation mode on, the desktop viewer blurs the Cluster/client column, the Cluster/client filter and the Target column.
- From 2.6.0, it also blurs the Who column and hides the user folder path. Before 2.6.0, the account email in the Who column and that path are visible: check the screen before recording.
- The web has no presentation mode.
Confirmations
None: the audit log only reads. Export CSV downloads the file on the web and opens the save dialog on desktop.
Permissions you need on your side
None on the cluster or the services: the web reads the Kubepier database and the desktop reads the local file. On the web, the plan and the role decide what shows up.
Common errors
- "Up to 90 days per query.": the Custom period is longer than 90 days; shorten the dates.
- Export CSV shows a lock: the organization is on Free; export is on Pro and Team.
- "Nothing recorded in this period": nobody did a recorded action matching these filters; change the period or clear the filters. On Free and as a member, only your own entries show.
- No User filter: it is for admins only, on Pro and Team.
- An action shows as a raw code: it was recorded by a newer version than the one reading it; update the desktop app.
- "There is no audit log on this computer yet." (desktop): nothing has been recorded on this machine yet.
- "Could not read the audit log." (desktop): the app could not read the file; check the permissions of the app data folder and click Refresh.