NexoAudit
:::danger Ineffective contract
The Operator accepts this Kind, but its fields are not translated into the current runtime audit configuration.
:::
This page documents the current development contract. Schema acceptance, Operator reconciliation, and runtime enforcement are separate claims; the status above is authoritative.
API identity
| Property | Value |
|---|---|
| Kind | NexoAudit |
| API group | nexo.io |
| Version | v1alpha1 |
| Resource | nexoaudits |
| Short name | naudit |
| Scope | Namespaced |
| Operator support | Ineffective contract |
Purpose and relationships
Exposes a schema for audit sink and body-capture intent; it does not provide supported audit output in the current release.
A NexoPipeline can reference this object, but the CRD emits sink and includeRequestBody/includeResponseBody while the runtime expects a different configuration shape.
Spec field reference
The table is derived from the installed Nexo Edge CRD OpenAPI schema. “Not declared” means the schema publishes no default. A missing schema description is reported explicitly rather than inferred from implementation.
| Field | Type | Required | Default | Schema description |
|---|---|---|---|---|
spec.sink | string | No | Not declared | No description is declared in the CRD schema. |
spec.includeRequestBody | boolean | No | Not declared | No description is declared in the CRD schema. |
spec.includeResponseBody | boolean | No | Not declared | No description is declared in the CRD schema. |
Status fields and conditions
| Field | Type | Required | Default | Schema description |
|---|---|---|---|---|
status.ready | boolean | No | Not declared | No description is declared in the CRD schema. |
status.observedGeneration | integer (int64) | No | Not declared | No description is declared in the CRD schema. |
status.configHash | string | No | Not declared | No description is declared in the CRD schema. |
status.conditions | array<object> | No | Not declared | No description is declared in the CRD schema. |
status.conditions[].type | string | No | Not declared | No description is declared in the CRD schema. |
status.conditions[].status | string | No | Not declared | No description is declared in the CRD schema. |
status.conditions[].reason | string | No | Not declared | No description is declared in the CRD schema. |
status.conditions[].message | string | No | Not declared | No description is declared in the CRD schema. |
status.conditions[].lastTransitionTime | string (date-time) | No | Not declared | No description is declared in the CRD schema. |
status.conditions[].observedGeneration | integer (int64) | No | Not declared | No description is declared in the CRD schema. |
A Ready or configHash value proves that the Operator accepted/hashed the object; it does not by itself prove runtime execution or policy enforcement.
Reconciliation and watch behavior
The registered controller validates the resource and records status. Data-path changes are applied only when the relevant NexoProxy controller rebuilds or reloads the owning graph.
At startup, the current NexoProxy controller installs a typed watch when the CRD is discoverable. A CRD installed after Operator startup requires an Operator restart before that reference watch is added.
Runtime execution effect
None through the current Operator contract. Do not rely on this Kind for audit records, redaction, integrity, retention, or compliance evidence.
Example
Use placeholders and validate in a non-production namespace first. For schema-only or ineffective kinds, this example is for schema inspection only and must not be used as evidence of enforcement.
# No deployable example is available until the CRD and runtime audit fields are aligned.
Update and reconciliation caveats
- Apply component and pipeline changes before expecting the owning NexoProxy graph to change.
- Check metadata.generation, status.observedGeneration when present, and the owning Proxy graphRevision/appliedRevision after every update.
- A successful kubectl apply proves only schema admission; inspect Operator conditions, generated configuration, rollout state, and runtime behavior separately.
Release-specific limitations
- The API is v1alpha1 and has no conversion webhook or second served version.
- The CRD schema is retained by Helm and can outlive the Operator release that installed it.
- Current documentation can describe unreleased development behavior; verify the exact deployed bundle and image digests.
Inspect with kubectl
kubectl get nexoaudits --namespace <namespace>
kubectl describe nexoaudits <name> --namespace <namespace>
kubectl get nexoaudits <name> --namespace <namespace> -o yaml
kubectl get crd nexoaudits.nexo.io -o yaml
For resources participating in a Proxy graph, also inspect:
kubectl get nexoproxy <proxy-name> --namespace <namespace> \
-o jsonpath='{.status.phase}{" graph="}{.status.graphRevision}{" applied="}{.status.appliedRevision}{"\n"}'
kubectl get nexopipeline <pipeline-name> --namespace <namespace> -o yaml