module

Secrets::Audit

Append-only audit log of mutations on a vault. One file per vault under ${CONFIG_DIR}/audit/<vault>.log, mode 0600. Each line is tab-separated:

<RFC3339 UTC timestamp> \t <user> \t <op> \t <key|->

Operations recorded: set, delete, edit, rotation, create. key is - for whole-vault operations (edit, rotation, create).

The log is append-only in spirit (we never rewrite existing lines) but not tamper-proof — an attacker with write access to the log can edit it. The intent is operator-side audit ("when did I last touch this vault?"), not security boundary.

Constants

AUDIT_DIR = "#{Secrets::CONFIG_DIR}/audit"

Instance methods

log(vault : String, op : String, key : String | Nil = nil) : Nil

Append a single audit line for op on vault. key is the specific entry touched, or nil for a vault-wide operation.

Source
log_path(vault : String) : String

Absolute path to the per-vault audit log file.

Source
read(vault : String) : Array(String)

Read the full audit log for vault. Returns an empty array if no operation has ever been recorded.

Source