edge-control: append-only audit log for register/deregister operations #1095
Labels
No labels
action
backlog
blocked
bug-report
cannot-reproduce
in-progress
in-triage
needs-triage
prediction/actioned
prediction/dismissed
prediction/unreviewed
priority
rejected
reproduced
tech-debt
underspecified
vision
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: disinto-admin/disinto#1095
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Mirrored from johba/disinto#836
---## Problem
tools/edge-control/register.shmutatesregistry.json,authorized_keys, and Caddy routes, but records nothing beyond the final state in the registry. If a bad register/deregister happens (squatting, ownership-check bypass, operator mistake), there is no trail to reconstruct when the change happened or what it replaced.Proposal
Every successful
do_register/do_deregisterappends one line to/var/log/disinto/edge-register.log:install.sh:/var/log/disinto/ownedroot:disinto-register,0750.chattr +aon ext4, optional — call out in docs)./etc/logrotate.d/disinto-edge(new file installed byinstall.sh).Acceptance
key=valuepairs) so it is greppable.