Skip to main content

audit-log

audit-log — ɳSelf documentation.

Audit Log Plugin

Append-only audit log for security-relevant events. Free: MIT licensed. Always free per Security-Always-Free Doctrine.

Install

nself plugin install audit-log

What It Does

Records security-relevant events (authentication, privilege changes, secrets access, admin actions) to an append-only Postgres table. No data is deleted from the log, it is a sidecar that reads events from other services and writes structured log rows. No fixed port; runs as an internal sidecar with no external routes.

Configuration

Env Var Default Description
AUDIT_LOG_RETENTION_DAYS 365 Days to retain log entries (0 = forever)
AUDIT_LOG_LEVEL info Minimum event level to record (debug, info, warn, error)

Ports

No fixed port. The audit-log plugin runs as an internal sidecar; it has no externally exposed service port.

Database Tables

1 table added to your Postgres database:

  • np_audit_log: append-only security event log

Schema:

Column Type Notes
id UUID Primary key
event_type TEXT e.g. auth.login, secrets.read, privilege.grant
actor_id UUID User or service that triggered the event
resource TEXT Affected resource identifier
meta JSONB Additional context
created_at TIMESTAMPTZ Event timestamp (immutable)

Nginx Routes

None. Internal only.

Security Doctrine

This plugin is always free per the Security-Always-Free Doctrine. No paywall on audit logging.

Source