Query audit
Requests
HTTP request
GET /v1/kubernetes-audits
List audits based on user specified conditions
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
| start_time | number | True | timestamp of start time range |
| end_time | number | True | timestamp of end time range |
| size | number | True | page size |
| pageno | number | True | request page number |
| cluster | string | True | name of cluster |
| scope | string | False | scope of audit, choices: all, user, system |
| user_name | string | False | Username of audit creator |
| resource_name | string | False | name of audit target object |
| resourcce_type | string | False | kind of audit target object |
| operation_type | string | False | operation types, create, update, delete and so on |
| scope | string | False | scope of audit, choices: all, user, system |
| source_ip | string | False | ip address of source audit request |
| response_status | string | False | response status, choices: Success, Failure |
Responses
Content-Type
application/json
Status code: 200
OK
Sample response
List of audit objects
{
"Items": [
{
"Annotations": null,
"AuditID": "4f7f7b44-2b0c-471c-940b-e8bf19ec893e",
"Cluster": "global",
"ImpersonatedUser": null,
"Level": "RequestResponse",
"ObjectRef": {
"APIGroup": "auth.alauda.io",
"APIVersion": "v1",
"Name": "admin@cpaas.io",
"Namespace": "",
"Resource": "users",
"ResourceVersion": "",
"Subresource": "",
"UID": ""
},
"ReferObject": "admin@cpaas.io",
"RequestObject": {},
"RequestReceivedTimestamp": "2022-02-07T09:48:05.342650Z",
"RequestURI": "/api/v1/token/callback?code=hsq2jd345albkglro4uxsdevji2dk6w5wimkljir7aedsga4wtm\u0026state=alauda-console",
"ResponseObject": {
"Access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImU4N2QzY2I5MmRmOTQzZTY1MThmODk3ODljMGVlZWJiOTA2MjQxZjgifQ.eyJpc3MiOiJodHRwczovLzE5Mi4xNjguMTMwLjEzNi9kZXgiLCJzdWIiOiJDaVF3T0dFNE5qZzBZaTFrWWpnNExUUmlOek10T1RCaE9TMHpZMlF4TmpZeFpqVTBOallTQld4dlkyRnMiLCJhdWQiOiJhbGF1ZGEtYXV0aCIsImV4cCI6MTY0NDMxMzY4NSwiaWF0IjoxNjQ0MjI3Mjg1LCJub25jZSI6ImFsYXVkYS1jb25zb2xlIiwiYXRfaGFzaCI6Ik0yUVV5WnIzUGlsZkY4SFAtTHlfdUEiLCJlbWFpbCI6ImFkbWluQGNwYWFzLmlvIiwiZW1haWxfdmVyaWZpZWQiOnRydWUsIm5hbWUiOiJhZG1pbiIsInByZWZlcnJlZF91c2VybmFtZSI6ImFkbWluQGNwYWFzLmlvIiwiZXh0Ijp7ImlzX2FkbWluIjp0cnVlLCJjb25uX2lkIjoibG9jYWwifX0.e9DCAu8kDUPfyUSidmEwU77kfyXl7bD3qDLUPcUKgyrEyTAXk51Az23234x9HVaY3fJQPtcDvexCch5T0WbYWcrVvvk5L0ipWPH5RV1G4HT4zJcSemAPSI3t16t9RGeaOW8se5D2BNhiTEt11KXW6Ybs2wTBSrF6nlkb8t0Nz2pqOEvrB5D05jLftaBpEzQ6PgdjZfL_p0UeHnXh-cw1_fq5P1BSIi8VQbha0cDMV9yOaTk4hhMELeYZB8rGY526_IZcJJWwp7liHngWanx9FSK7oXlvttPXp2zc27YyecHLotm0XrE-EhWD6iWTsCEM_SL5BuXisJgItUzFdImr2A",
"Expire_at": "2022-02-08T09:48:05Z",
"Id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImU4N2QzY2I5MmRmOTQzZTY1MThmODk3ODljMGVlZWJiOTA2MjQxZjgifQ.eyJpc3MiOiJodHRwczovLzE5Mi4xNjguMTMwLjEzNi9kZXgiLCJzdWIiOiJDaVF3T0dFNE5qZzBZaTFrWWpnNExUUmlOek10T1RCaE9TMHpZMlF4TmpZeFpqVTBOallTQld4dlkyRnMiLCJhdWQiOiJhbGF1ZGEtYXV0aCIsImV4cCI6MTY0NDMxMzY4NSwiaWF0IjoxNjQ0MjI3Mjg1LCJub25jZSI6ImFsYXVkYS1jb25zb2xlIiwiYXRfaGFzaCI6IlFIc0Z4UDZ1Z3ljV2R1dDlOcFU4UUEiLCJjX2hhc2giOiJkVUZIRVFsalNsaG5tZXBjOVhoU1FnIiwiZW1haWwiOiJhZG1pbkBjcGFhcy5pbyIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJuYW1lIjoiYWRtaW4iLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJhZG1pbkBjcGFhcy5pbyIsImV4dCI6eyJpc19hZG1pbiI6dHJ1ZSwiY29ubl9pZCI6ImxvY2FsIn19.x4wnB15BtFJCl6ncV8Ddp164xOlhMcZOTmU75Rr077yPJWUt9U6XYycJEPRLDNhtw5usB-67R4TNL9ydAqD54a8fJRh_YUtnjQAqoNGNnwH-bw-zepfS88B0ENUHrwbKfGvUe7btk29aJW_II3gSDwCcM1YArxHD6vFzbHtVKlfHM4vL5_9k0Z4TM49sli6ZNKbIKD_cp7EbxJ_1miRJrywk4Tv99HqA17vVIIEKX8ybQL0gSiAek8spBDKN3ar8ZNRr0Kerse219wgHNTLBcCvwobsaIvIDVyf-Dw9Oj8yZg95veYqeLtnJtRGH8XAe1kmgpDmNrr6JV9p8OkSjXg",
"Issued_at": "2022-02-07T09:48:05Z",
"Refresh_token": "CjNvbnhyd280cXRqa2w2M2dsNnRldHd6YTdtNmhhcTJyNGM1empscHFwbmp5bDdlbmpiYzQSM3VnbWk3Y2d3eG1tc2ZwZHB5ZDV6a282YnIyank2aHozNGlia2xtNWZ6anJ6aGY0ZWFoZQ",
"Token_type": "bearer"
},
"ResponseStatus": {
"code": 200,
"metadata": {},
"status": "Success"
},
"SourceIPs": [
"60.9.140.26",
"10.0.128.88"
],
"Stage": "ResponseComplete",
"StageTimestamp": "2022-02-07T09:48:05.612652Z",
"User": {
"username": "admin@cpaas.io"
},
"UserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.15.776.507 Safari/537.36",
"Verb": "login"
}
],
"apiVersion": "audit.k8s.io/v1",
"kind": "EventList",
"total_items": 1,
"total_page": 1
}Parameters
| Name | Type | Description |
|---|---|---|
| Items | array |
items
Path: Items |
| Items[] | object |
Audit object holding the info
Path: Items[] |
| Items[].Annotations | object |
Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects. More info: http://kubernetes.io/docs/user-guide/annotations
Path: Items[].Annotations |
| Items[].AuditID | string |
Unique audit ID, generated for each request.
Path: Items[].AuditID |
| Items[].Cluster | string |
The name of the cluster which the object belongs to.
Path: Items[].Cluster |
| Items[].ImpersonatedUser | object |
UserInfo holds the information about the user needed to implement the user.Info interface.
Path: Items[].ImpersonatedUser |
| Items[].Level | string |
Level defines the amount of information logged during auditing.
Path: Items[].Level |
| Items[].ObjectRef | object |
ObjectReference contains enough information to let you inspect or modify the referred object.
Path: Items[].ObjectRef |
| Items[].ReferObject | string |
The name of ObjectRef.
Path: Items[].ReferObject |
| Items[].RequestReceivedTimestamp | string (date-time) |
Time is a wrapper around time.Time which supports correct marshaling to YAML and JSON. Wrappers are provided for many of the factory methods that the time package offers.
Path: Items[].RequestReceivedTimestamp |
| Items[].RequestURI | string |
RequestURI is the request URI as sent by the client to a server.
Path: Items[].RequestURI |
| Items[].ResponseStatus | object |
Status is a return value for calls that don't return other objects.
Path: Items[].ResponseStatus |
| ResponseStatus.code | integer (int32) |
Suggested HTTP return code for this status, 0 if not set.
Path: Items[].ResponseStatus.code |
| ResponseStatus.metadata | object |
ListMeta describes metadata that synthetic resources must have, including lists and various status objects. A resource may have only one of {ObjectMeta, ListMeta}.
Path: Items[].ResponseStatus.metadata |
| ResponseStatus.status | string |
Status of the operation. One of: "Success" or "Failure". More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
Path: Items[].ResponseStatus.status |
| Items[].Stage | string |
Stage of the request handling when this event instance was generated.
Path: Items[].Stage |
| Items[].StageTimestamp | string (date-time) |
Time is a wrapper around time.Time which supports correct marshaling to YAML and JSON. Wrappers are provided for many of the factory methods that the time package offers.
Path: Items[].StageTimestamp |
| Items[].User | object |
UserInfo holds the information about the user needed to implement the user.Info interface.
Path: Items[].User |
| User.username | string |
The name that uniquely identifies this user among all active users.
Path: Items[].User.username |
| Items[].UserAgent | string |
UserAgent records the user agent string reported by the client.
Path: Items[].UserAgent |
| Items[].Verb | string |
Verb is the kubernetes verb associated with the request.
Path: Items[].Verb |