Organization · Web and Desktop

Audit log: who did what, where and when

The Kubepier audit log shows who did what, on which client, cluster and resource, when, and whether it worked. On the web, entries live in the organization database and show up in the Audit log menu; on desktop, they live in the kubepier-audit.log file on your machine and show up in Preferences › TR › Audit. Metadata only: never the content.

Where
Web and Desktop
Plans
Web: Free (7-day preview), Pro and Team. Desktop: Free, Pro and Team
Role
Web: admins see the organization; members, their own entries. Desktop: whoever uses the computer

What it does

  • Web: lists the actions recorded in the organization database, newest first, with filters, the details of each row and CSV export.
  • Desktop: lists what was done from this computer, read from kubepier-audit.log and kubepier-audit.log.1, with filters and CSV export.
  • Web and desktop share the same action codes, groups and labels (Edited YAML, Purged queue, Opened shell…).

Where to find it

  • Web: the Audit log item in the app sidebar, right above Plans. Everyone in the organization sees it, admin or member, on any plan.
  • Desktop: Preferences › TR › Audit. The viewer arrived in 2.5.0; kubepier-audit.log has been written since 2.2.0.

Who sees what

Plan and roleWhat shows upPeriodExport CSV
Web, FreeA preview: only your own entries, with a notice and a See plans buttonToday or 7 days (at most the last 7 days)No (the button shows a lock)
Web, Pro and Team, adminThe whole organization, with a user filterToday, 7 days, 30 days or Custom, up to 90 days per queryYes
Web, Team, memberOnly your own entries, on the clients granted to youToday, 7 days, 30 days or Custom, up to 90 days per queryYes
Desktop, any planWhat was done on this computer, under your Kubepier account (email in the Who column)Today, 7 days, 30 days or CustomYes

On the web, the API enforces the rule, not just the screen: a member cannot request someone else’s entries or those of a client not granted to them.

On desktop, the recorded actions mostly belong to paid plans (edit, shell, tunnel, service actions, AI); from 2.7.0, port-forward, which is free on Free, is recorded too. On Free, the list only shows what was done while the organization had a paid plan.

Filters (web)

  • Period: Today, 7 days (the default), 30 days or Custom, with From and To dates. Custom accepts up to 90 days; beyond that, the screen says "Up to 90 days per query." and does not search. On Free, only Today and 7 days.
  • User: everyone or one person on the team. Admins only, on Pro and Team.
  • Client and cluster: the cluster list follows the chosen client.
  • Actions: a menu of checkboxes grouped by area (Cluster, Terminals, Cluster route, Data services, AI, Team and Setup and billing). You can tick several.
  • Result: All, ok or error.
  • Search: by target, namespace or cluster name, up to 100 characters.
  • Clear filters resets user, client, cluster, actions, result and search; the period stays.

List and details (web)

  • Columns: When (how long ago, with the full date and time on hover), Who (name and GitHub username), Action, Client, Cluster / namespace / target, Result and Duration (on shell and bastion close).
  • 50 entries at a time; the Load more button brings the next 50.
  • Click a row to see its details: date and time, kind, namespace and the action metadata, such as replicas, container, image, messages before and removed, queue threshold, TTL, size in bytes, field, new name, key count and names, AI provider and whether events and logs were sent, route before and after, role and granted clients. When it failed, the error message shows below.
  • Someone who left the organization shows as Removed user; their entries stay.

Export CSV (web)

  • Export CSV downloads the entries matching the current filters, up to 10,000 rows, as kubepier-auditoria-YYYYMMDD.csv.
  • Columns: criado_em, usuario, github, acao, resultado, cliente, cluster, namespace, tipo, alvo, duracao_segundos and erro. The action is written as its code (for example, purgar_dlq).
  • UTF-8 with a BOM, so Excel opens accented characters correctly.
  • Spreadsheet-safe: every field is quoted, and a value starting with =, +, -, @, tab or carriage return gets a leading apostrophe so it is not read as a formula.
  • Pro and Team only. Admins export the organization; members, their own entries.

What is recorded

AreaActions, as the screen shows themWhere
ClusterEdited YAML, Scaled, Restarted, Deleted resourceWeb and desktop
ClusterApplied YAML, Cordoned node, Uncordoned node, Drained nodeDesktop
TerminalsOpened shell, Closed shellWeb and desktop (pod and node shells)
TerminalsOpened bastion, Closed bastionWeb
Cluster routeCreated relay, Removed relayWeb (cluster route relay) and desktop (Secure tunnel relay pod)
Cluster routeChanged connection routeWeb
Cluster routeOpened secure tunnel, Closed secure tunnelDesktop
Data servicesPurged queue, Purged DLQ, Wrote Redis value, Wrote Redis hash field, Deleted Redis hash field, Set Redis TTL, Renamed Redis key, Deleted Redis keysWeb and desktop
Data servicesSet queue threshold, Removed queue threshold, Removed Redis TTLWeb
AIRequested AI diagnosisWeb and desktop
TeamInvited to the team, Canceled invitation, Accepted invitation, Changed member, Removed memberWeb
Setup and billingAdd, edit and remove a cluster; create, edit and remove a Client; save and remove a credential; add, edit, remove and sync a cloud account; subscribe to and cancel a planWeb

Each entry carries who, when, client, cluster, namespace, kind and target name, the result and, when present, the error and the action metadata.

On the web, every attempt to edit, scale, restart or delete is recorded, even a failed one. On desktop, cordon, uncordon and drain record that the command was sent, not its result.

Setup and billing keeps metadata only: who, when, the cluster, Client or account name and the result. Never the credential, the kubeconfig or payment data.

From desktop 2.7.0, kubepier-audit.log also records Helm (install, upgrade, rollback and uninstall), port-forward (Free included) and opening and closing the local terminal.

What is never recorded

  • Content: the applied YAML, manifest or patch, what is typed in a terminal and its output, queue message bodies, Redis key values, the text sent to the AI and its answer.
  • Credentials: passwords, keys, tokens, connection strings and certificates.
  • Reads: opening lists, viewing logs, peeking messages and browsing Redis are not audited.
  • On the web, the screen and the CSV go through a fixed list of metadata fields: any other field is dropped before leaving the server, and long texts are cut at 300 characters.
  • On desktop, the viewer reads only who, when, action, cluster or client, target, result and duration; the rest of the line stays out of the screen and the CSV.

What is accepted

  • Periods Today, 7 days, 30 days and Custom. On the web, up to 90 days per query; with Custom you can query any window of up to 90 days in the past (Pro and Team).
  • Several actions at once in the filter (up to 40, on the web).
  • Search of up to 100 characters (web).

What is not accepted

  • More than 90 days in a web query, or a From date after the To date.
  • On Free: entries older than 7 days (the period starts at most 7 days ago), other people’s entries and CSV export.
  • A member seeing what other people did, or entries of clients not granted to them.
  • Editing or deleting entries: the web audit log is insert-only, and not even an admin deletes a row.

Limits and timeouts

LimitValue
Entries at a time (web)50, with Load more
Default period7 days
Period per query (web)up to 90 days
Free preview (web)your own entries from the last 7 days, no CSV
Export CSV (web)up to 10,000 rows, on Pro and Team
Search (web)up to 100 characters
Entries per page (desktop)100, with Previous and Next
Local file (desktop)kubepier-audit.log; past 5 MB it becomes kubepier-audit.log.1, replacing the previous one

How long it is kept

  • Web: the audit table is insert-only and nothing deletes it automatically. Entries are kept while the organization exists; the screen queries up to 90 days at a time, and Custom reaches older periods.
  • Web: someone who leaves the organization stays in the entries as Removed user, and a removed cluster keeps its name in the entry.
  • Desktop: there is no time limit; the limit is size. When kubepier-audit.log passes 5 MB it becomes kubepier-audit.log.1 (replacing the previous .1) and a new file starts. The viewer reads both; whatever was in the old .1 is lost.
  • Desktop: the file stays in the app data folder on your machine and is not sent to the Kubepier server.

Desktop: Preferences › TR › Audit

  • The viewer reads kubepier-audit.log and kubepier-audit.log.1 in the app data folder. A log under the old name (tr99-data-audit.log) is renamed on the first write, so its history stays in the same file.
  • Columns: When, Who (the email of the signed-in Kubepier account; "—" when signed out), Action, Cluster/client, Target, Result and Duration.
  • Filters: Period (Today, 7 days, 30 days or Custom, with From and To), Action (grouped by the same areas as the web), Cluster/client and a name search (who, cluster, target).
  • 100 entries per page, with Previous and Next. Refresh reads the file again.
  • Export CSV saves every filtered entry, not just the page, in UTF-8 with a BOM and the same formula protection as the web, as kubepier-auditoria-YYYY-MM-DD.csv.
  • Open folder reveals the file in your file manager. If there is no log yet, the screen says "There is no audit log on this computer yet."
  • Lines that cannot be read are skipped, and the screen says how many.

Presentation mode

  • With presentation mode on, the desktop viewer blurs the Cluster/client column, the Cluster/client filter and the Target column.
  • From 2.6.0, it also blurs the Who column and hides the user folder path. Before 2.6.0, the account email in the Who column and that path are visible: check the screen before recording.
  • The web has no presentation mode.

Confirmations

None: the audit log only reads. Export CSV downloads the file on the web and opens the save dialog on desktop.

Permissions you need on your side

None on the cluster or the services: the web reads the Kubepier database and the desktop reads the local file. On the web, the plan and the role decide what shows up.

Common errors

  • "Up to 90 days per query.": the Custom period is longer than 90 days; shorten the dates.
  • Export CSV shows a lock: the organization is on Free; export is on Pro and Team.
  • "Nothing recorded in this period": nobody did a recorded action matching these filters; change the period or clear the filters. On Free and as a member, only your own entries show.
  • No User filter: it is for admins only, on Pro and Team.
  • An action shows as a raw code: it was recorded by a newer version than the one reading it; update the desktop app.
  • "There is no audit log on this computer yet." (desktop): nothing has been recorded on this machine yet.
  • "Could not read the audit log." (desktop): the app could not read the file; check the permissions of the app data folder and click Refresh.