Uploaded image for project: 'OpenShift Virtualization'
  1. OpenShift Virtualization
  2. CNV-50349

[spike] Audit log virtctl requests that allow interaction with VMIs

XMLWordPrintable

    • 0.42
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • ---
    • ---
    • None

      • Since virtctl commands to interact with VMIs do not use kube-apiserver (cluster audit logger), we can use Kubernetes Auditing implementation and use a local volume/webhook to audit log virtctl requests in virt-api.
      • Ensure ‘oc adm node-logs --role=master --path=’ and ‘oc adm must-gather – /usr/bin/gather_audit_logs’ can get audit logs from virt-api

      ref: https://docs.google.com/document/d/1aN_TunfOp6gXhpQU4YAnukfGvtwE3bFbNEQcjKnHvUE/edit

              jvilaca@redhat.com João Vilaça
              jvilaca@redhat.com João Vilaça
              Natalie Gavrielov Natalie Gavrielov
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: