MAQPNADocs

maqpna audit

Verify, export, stream and tail the audit ledger

Observe-o json | yaml

Synopsis#

maqpna audit verify FILE [--jwks JWKS.json] [--checkpoints FILE.checkpoints.jws]
maqpna audit export FILE [--session S] [--namespace NS] [--agent A] [--since RFC3339] [--until RFC3339] [--out FILE]
maqpna audit stream FILE --config gateway.json --sink NAME [--from-seq N]
maqpna audit tail --gateway URL [--session S] [-n NS] [--agent A] [--user U] [--trace ID] [--since 1h] [--tail 50] [-f]
maqpna audit verify --gateway URL                  (the gateway verifies its ledger; exit 3 if broken)
maqpna audit verify --postgres DSN-FILE [--schema maqpna] [--chain audit]
maqpna audit export --gateway URL [--session S] [--namespace NS] [--agent A] [--user U] [--since RFC3339] [--until RFC3339] [--out FILE]
maqpna audit fetch jwks|checkpoints|ledger [--gateway URL] --out FILE
maqpna audit sinks [--gateway URL] [--max-lag N]     (exit 3 if a sink lags more than N records or has errors)

Subcommands#

Examples#

maqpna audit tail --gateway "$GW" -n team-a -f
maqpna audit verify audit.jsonl --jwks jwks.json --checkpoints audit.checkpoints.jws
maqpna audit export --gateway "$GW" --session fix-test-7k2 --out evidence.jsonl

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna audit.cast