Skip to main content
Version: Next (Private Preview)

Audit Log

Status: Unavailable end to end: the NexoAudit CRD fields are not aligned with the runtime audit configuration in the current release.

:::caution No supported deployment contract

This capability is documented for catalog completeness, but the selected release does not publish a supported end-to-end deployment contract.

:::

Always confirm availability in the release bundle selected for deployment.

At a glance

PropertyValue
Pipeline phaseRequest + response
CategorySecurity
Canonical minimum tierPro
Canonical entitlementYes
Supported deployment contractNo
Release statusUnavailable end to end: the NexoAudit CRD fields are not aligned with the runtime audit configuration in the current release.

Release accuracy

  • Current documentation: Unavailable end to end: the NexoAudit CRD fields are not aligned with the runtime audit configuration in the current release.

Where any detail below conflicts with the release status above, the release status is authoritative. Field names and examples describe the current dashboard and CRD surface; always confirm behavior against the selected release bundle before relying on it operationally.

Audit Log current release feature flow. Unavailable end to end: the NexoAudit CRD fields are not aligned with the runtime audit configuration in the current release.

Release-aware feature flow. The diagram is explanatory; the release status on this page is authoritative.

Diagram resources: Open the SVG full screen · Download the editable Excalidraw source

Performance impact

:::warning Unverified performance figures

These figures are illustrative only. They are not current benchmarks or service guarantees and have not been verified by the current test suite.

:::

PercentileReported figure
P500.10ms
P950.40ms
P990.90ms

Note: Buffered mode amortizes writes; HMAC signing and redaction add small per-entry overhead.

Overview

The current NexoAudit CRD accepts a sink plus request- and response-body flags, but those field names are not translated into the runtime audit step's configuration contract. The runtime contains additional audit capabilities, but they are not a supported deployable surface through the current Operator.

When to use

  • Do not rely on this component in the current release
  • Use the page to understand the known contract gap before planning an audit rollout

How it works

  1. The Operator validates and serializes the NexoAudit CRD.
  2. The CRD currently emits sink, includeRequestBody, and includeResponseBody.
  3. The runtime audit step expects a different configuration shape, including output and include_body.
  4. Because the Operator does not translate between those contracts, the release does not provide a supported end-to-end audit deployment path.

Configuration

“Not specified” means required semantics were not declared for that field.

FieldTypeDefaultRequiredDescription
sinkstringNoCRD field accepted by the Operator; not translated to the runtime output field
includeRequestBodyboolfalseNoCRD flag accepted by the Operator; not translated to the runtime include_body field
includeResponseBodyboolfalseNoCRD flag accepted by the Operator; the current runtime has no matching response-body field

Settings reference

No additional settings reference is documented for this component.

Examples

No example is documented for this component.

Best practices

  • Do not claim audit integrity, redaction, retention, or compliance evidence from this release
  • Do not enable request or response body capture until the end-to-end contract and redaction behavior are verified
  • Use an independently governed database or platform audit source for current compliance requirements

Limitations

  • The current CRD-to-runtime configuration contract is not aligned
  • Runtime HMAC signing, redaction, retention, webhook, and compliance-template fields are not exposed by the current NexoAudit CRD
  • No current Operator example should be treated as deployable until this gap is fixed and tested

Security and operational guidance

  • Audit bodies and metadata may be sensitive
  • Review every compliance preset before enabling it because presets can change body-capture behavior
  • Enable body capture only when required
  • Protect destinations with encryption, access control, retention, and integrity monitoring
  • The preserved ${AUDIT_HMAC_SECRET} example is not runtime substitution syntax. Do not deploy it literally; supply a strong secret through the bundle-supported secret delivery mechanism.

Release availability

  • Current documentation: Unavailable end to end: the NexoAudit CRD fields are not aligned with the runtime audit configuration in the current release.

See the component catalog for the complete comparison matrix.

Search Nexo documentation

Type to search titles, headings, and page content.