The audit log records every successful mutating command, authentication failures and admin actions. Two gaps:
- Refused commands (exit 4, and not-found on write paths) are not recorded, so probing leaves no trace except SSH auth failures.
Dispatchaudits onlyExitOKwrites (internal/control/control.go). audit_loglives in the same database the daemon writes, so a compromised daemon or host can edit it.
Changes: audit refusals of mutating commands (rate-limited per actor); ship audit rows to an append-only sink (journal, syslog, or a hash chain checked by gitbayd admin).
referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews
2026-09-28 05:43 UTC