Skip to content
Stackship documentation Svenska

Container registryAdministrators

Registry audit log

What the registry records about pushes, token requests and deletions, how long it keeps it, and how to query it.

Requires: registry/audit/read

The Registry module keeps its own audit log, separate from the platform's activity log. Reading it needs registry/audit/read at the platform root: Platform Owner, Platform Contributor and Platform Reader have it.

Events

Action Recorded when
push An image is pushed to an app, function or static web app repository. Carries the repository, tag, digest and size
token.issue The registry's token service answers a request for access — clients, both builds and the cluster, ask for one before they pull or push. resourceScope holds the access that was asked for
delete The retention sweep deleted an image
delete.dryrun A dry-run sweep would have deleted an image

token.issue events always have status 200, also when some or all of the requested access was refused. A request with a credential the registry does not accept is answered with 401 and not recorded. The registry records no separate pull or credential.mint events, even though the portal's filter hint names them.

Important

The Registry module holds push and token.issue events in memory and writes them to the log only when a retention run finishes — the nightly one at 03:00 UTC, or one you start yourself. Until then they do not appear in queries. At most 1,024 events wait at a time; further events are dropped, and waiting events are lost when the module restarts. With the nightly sweep turned off, events are written only by runs started by hand. The log is therefore not a complete record of pushes and token requests.

Events are kept for 90 days unless your platform is configured otherwise (see Settings).

Fields

Field Meaning
timestampUtc When it happened, in UTC
action See Events
boundary The boundary id the repository or the credential belongs to
repository, tag, digest, sizeBytes The image, where the event is about one
resourceScope The access requested, or the image the event is about
statusCode The outcome
correlationId Ties the event to the request that caused it, when the caller sent one

Query it

bash
stsh api GET "/resources/registries/audit?action=push&repository=apps/<boundary-id>/<namespace>/<app-name>&limit=50"
Parameter Meaning
from, to A time window, ISO 8601
boundary, action, repository Exact matches
correlation_id Events of one request
limit 1 to 500; 100 by default

Events come newest first. When there are more, nextCursor holds a time: pass it as to to get the next, older page. to includes that time, so the last event of one page is the first of the next.

In the portal

The portal has a Registry audit page over the same log, at the address /audit, with the filters From, To, Boundary, Action, Repository and Correlation ID. It shows the time, action, boundary, repository, tag and status of each event; Load older → fetches the next page, and choosing a row shows the whole event. No menu or admin page links to it.