Commit 813b219e1a

813b219e1a5546af4bf7820b049f1ce9c43e6954

parent: 31d3d46d46

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-02 01:34 UTC

Admin: audit filters

Ref krz/gitbay#73

Layout: unified · split

Admin.org +7 −2
@@ -149,8 +149,8 @@ auth failures/throttling. Secrets never appear — they travel on stdin,
149never in argv. 149never in argv.
150 150
151#+begin_src sh 151#+begin_src sh
152gitbayd admin audit [--limit n] # host-local 152gitbayd admin audit [--actor u|-] [--action prefix] [--since 24h|7d|date] [--limit n] [--json]
153ssh git@<host> audit [--limit n] # instance admins, SSH only 153ssh git@<host> audit ... # the same, from an admin session (SSH only)
154ssh git@<host> admin user list [--state active|pending|disabled|admin] 154ssh git@<host> admin user list [--state active|pending|disabled|admin]
155ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions 155ssh git@<host> admin user show <name> # keys, emails, orgs, tokens, sessions
156ssh git@<host> admin user promote <name> # grant instance admin 156ssh git@<host> admin user promote <name> # grant instance admin
@@ -165,6 +165,11 @@ gitbayd admin user delete <name> --yes # only for accounts anchoring nothing:
165 # org's only admin 165 # org's only admin
166#+end_src 166#+end_src
167 167
168=--actor= takes a username, or =-= for rows with no actor: host commands
169and auth failures. =--action= is a prefix, so =cmd repo= catches every
170repository command and =admin= every host or admin-session action.
171=--since= is a duration back from now (=30m=, =24h=, =7d=) or a date.
172
168=admin user list= pages by username (=--limit=, =--cursor=) and carries 173=admin user list= pages by username (=--limit=, =--cursor=) and carries
169each account's state and =last_seen=, the newest use of any of its SSH 174each account's state and =last_seen=, the newest use of any of its SSH
170keys or API tokens. =admin user show= adds the keys with their last use, 175keys or API tokens. =admin user show= adds the keys with their last use,