maqpna audit tail
Print recent audit records from the gateway, optionally following new ones
Synopsis#
maqpna audit tail --gateway URL [--session S] [-n NS] [--agent A] [--user U] [--trace ID] [--since 1h] [--tail 50] [-f]Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent | string | only this agent | none |
--decision | string | only this decision (allow, deny, require_approval, ...) | none |
-f, --follow | switch | keep printing new records | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--interval | duration | poll interval with -f | 1s |
-n, --namespace | string | only this namespace (namespace-scoped auditors must set it) | none |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--session | string | only this session | none |
--since | string | start: a duration ago (1h) or an RFC3339 time; 0 = the whole ledger | 1h |
--tail | int | print at most the last N records first (-1: all) | 50 |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
--trace | string | only records of this OpenTelemetry trace ID (ext.traceId) | none |
--user | string | only this on-behalf-of user | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna audit tail --gateway "$GW" -n team-a -fWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |