maqpna audit
Verify, export, stream and tail the audit ledger
Synopsis#
maqpna audit verify FILE [--jwks JWKS.json] [--checkpoints FILE.checkpoints.jws]
maqpna audit export FILE [--session S] [--namespace NS] [--agent A] [--since RFC3339] [--until RFC3339] [--out FILE]
maqpna audit stream FILE --config gateway.json --sink NAME [--from-seq N]
maqpna audit tail --gateway URL [--session S] [-n NS] [--agent A] [--user U] [--trace ID] [--since 1h] [--tail 50] [-f]
maqpna audit verify --gateway URL (the gateway verifies its ledger; exit 3 if broken)
maqpna audit verify --postgres DSN-FILE [--schema maqpna] [--chain audit]
maqpna audit export --gateway URL [--session S] [--namespace NS] [--agent A] [--user U] [--since RFC3339] [--until RFC3339] [--out FILE]
maqpna audit fetch jwks|checkpoints|ledger [--gateway URL] --out FILE
maqpna audit sinks [--gateway URL] [--max-lag N] (exit 3 if a sink lags more than N records or has errors)Subcommands#
maqpna audit verifyVerify the audit ledger's hash chain, signatures and checkpoints
maqpna audit exportExport audit records, filtered by session, namespace, agent or time
maqpna audit streamBackfill a SIEM audit sink from a ledger file
maqpna audit tailPrint recent audit records from the gateway, optionally following new ones
maqpna audit fetchDownload the gateway's JWKS, checkpoints or ledger
maqpna audit sinksShow the state and lag of the gateway's audit sinks
Examples#
maqpna audit tail --gateway "$GW" -n team-a -f
maqpna audit verify audit.jsonl --jwks jwks.json --checkpoints audit.checkpoints.jws
maqpna audit export --gateway "$GW" --session fix-test-7k2 --out evidence.jsonlWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |