Registry audit log
What the registry records about pushes, token requests and deletions, how long it keeps it, and how to query it.
Requires: registry/audit/read
The Registry module keeps its own audit log, separate from the platform's activity log. Reading
it needs registry/audit/read at the platform root: Platform Owner, Platform Contributor and
Platform Reader have it.
Events
| Action | Recorded when |
|---|---|
push |
An image is pushed to an app, function or static web app repository. Carries the repository, tag, digest and size |
token.issue |
The registry's token service answers a request for access — clients, both builds and the cluster, ask for one before they pull or push. resourceScope holds the access that was asked for |
delete |
The retention sweep deleted an image |
delete.dryrun |
A dry-run sweep would have deleted an image |
token.issue events always have status 200, also when some or all of the requested access
was refused. A request with a credential the registry does not accept is answered with 401 and
not recorded. The registry records no separate pull or credential.mint events, even though
the portal's filter hint names them.
Important
The Registry module holds
pushandtoken.issueevents in memory and writes them to the log only when a retention run finishes — the nightly one at 03:00 UTC, or one you start yourself. Until then they do not appear in queries. At most 1,024 events wait at a time; further events are dropped, and waiting events are lost when the module restarts. With the nightly sweep turned off, events are written only by runs started by hand. The log is therefore not a complete record of pushes and token requests.
Events are kept for 90 days unless your platform is configured otherwise (see Settings).
Fields
| Field | Meaning |
|---|---|
timestampUtc |
When it happened, in UTC |
action |
See Events |
boundary |
The boundary id the repository or the credential belongs to |
repository, tag, digest, sizeBytes |
The image, where the event is about one |
resourceScope |
The access requested, or the image the event is about |
statusCode |
The outcome |
correlationId |
Ties the event to the request that caused it, when the caller sent one |
Query it
stsh api GET "/resources/registries/audit?action=push&repository=apps/<boundary-id>/<namespace>/<app-name>&limit=50"| Parameter | Meaning |
|---|---|
from, to |
A time window, ISO 8601 |
boundary, action, repository |
Exact matches |
correlation_id |
Events of one request |
limit |
1 to 500; 100 by default |
Events come newest first. When there are more, nextCursor holds a time: pass it as to to get
the next, older page. to includes that time, so the last event of one page is the first of the
next.
In the portal
The portal has a Registry audit page over the same log, at the address /audit, with the
filters From, To, Boundary, Action, Repository and Correlation ID. It shows the time, action,
boundary, repository, tag and status of each event; Load older → fetches the next page, and
choosing a row shows the whole event. No menu or admin page links to it.