envoyproxy / envoyproxy/envoy

Add audit log for configuration updates

Open
#6,936 2 comments 0 reactions 0 assignees View on GitHub
design proposal help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 20h
Merged PRs (30d)
428

Description

*Title*: Add audit log for configuration updates

*Context*:

In enterprise environment it is often necessary to track compliance with internal policies. E.g.,
- support a particular TLS cipher suite
- enforce a particular SSO method
- enforce RBAC consistently
- etc

If a violation is detected, it is usually important to be able to answer for how long the issue has been in place.

*Proposal*:
- Add audit log for configuration updates (to record snapshots of applied xDS configuration)

*Example use cases*:
- Maintain a log of all LDS changes (open ports, TLS settings, filters chain, AuthN settings, AuthZ settings)
- Sink audit log into a tool that automates policy checks (i.e., [Falco)](https://falco.org/docs/event-sources/kubernetes-audit/)

*Anticipated scope of changes*:
- Add `AuditLog` API for use by system components to record audit events
- Instrument system components to record audit events, e.g. ListenerManager, ClusterManager, etc
- Define a configuration schema to govern Audit Log
- Which xDS resources to record ?
- What to do with recorded audit events ?
- Add a new extension kind - `Audit Log Sink`
- Define a schema for gRPC/HTTP service to send recorded audit events to
- Add an implementation of `Audit Log Sink` that streams recorded audit events to a gRPC/HTTP service
- Support dynamic changes to Audit Log configuration

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.