MAQPNADocs

maqpna audit tail

Print recent audit records from the gateway, optionally following new ones

Observe-o json | yaml

Synopsis#

maqpna audit tail --gateway URL [--session S] [-n NS] [--agent A] [--user U] [--trace ID] [--since 1h] [--tail 50] [-f]

Flags#

FlagTypeDescriptionDefault
--agentstringonly this agentnone
--decisionstringonly this decision (allow, deny, require_approval, ...)none
-f, --followswitchkeep printing new recordsnone
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--intervaldurationpoll interval with -f1s
-n, --namespacestringonly this namespace (namespace-scoped auditors must set it)none
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--sessionstringonly this sessionnone
--sincestringstart: a duration ago (1h) or an RFC3339 time; 0 = the whole ledger1h
--tailintprint at most the last N records first (-1: all)50
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none
--tracestringonly records of this OpenTelemetry trace ID (ext.traceId)none
--userstringonly this on-behalf-of usernone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna audit tail --gateway "$GW" -n team-a -f

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna audit tail.cast