Light Mode

Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Security] Add external append-only audit trail integrity #72

Closed
Closed
[Security] Add external append-only audit trail integrity#72
Labels
enhancementNew feature or requestsecuritySecurity-related issues

Description

Problem

The current hash-chain audit trail runs in-process. A compromised agent sharing the same process space could tamper with the audit chain before it is persisted.

Proposed Solution

  • Write audit logs to an external append-only sink
  • Support multiple backends: local file with O_APPEND semantics, Azure Monitor, write-once S3, Merkle-tree log (Trillian)
  • Add cryptographic signatures per audit entry with an external key
  • Provide verification tooling to validate chain integrity

Current State

Community edition uses basic append-only in-memory log with SHA-256 hashes. No tamper-evidence against in-process adversaries.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsecuritySecurity-related issues

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions