Secrets::Audit
Append-only audit log of mutations on a vault. One file per vault
under ${CONFIG_DIR}/audit/<vault>.log, mode 0600. Each line is
tab-separated:
<RFC3339 UTC timestamp> \t <user> \t <op> \t <key|->
Operations recorded: set, delete, edit, rotation, create.
key is - for whole-vault operations (edit, rotation, create).
The log is append-only in spirit (we never rewrite existing lines) but not tamper-proof — an attacker with write access to the log can edit it. The intent is operator-side audit ("when did I last touch this vault?"), not security boundary.
Constants
AUDIT_DIR = "#{Secrets::CONFIG_DIR}/audit"
Instance methods
Append a single audit line for op on vault. key is the
specific entry touched, or nil for a vault-wide operation.