Skip to content

Audit: Support audit log file rotation - #31213

Open
t0x01 wants to merge 1 commit into
hashicorp:mainfrom
t0x01:pr/t0x01/audit-file-rotation
Open

t0x01 wants to merge 1 commit into
hashicorp:mainfrom
t0x01:pr/t0x01/audit-file-rotation

Conversation

@t0x01

@t0x01 t0x01 commented Jul 4, 2025 •

Copy link
Copy Markdown

Description

Allow to natively configure Vault file audit device log file rotation with the audit enable command by adding 3 new options to the file backend. These 3 new options and their default values are as follows:

  • max_files : (int: 0) - The maximum number of older audit log file archives to keep. Defaults to 0 (no files are ever deleted). Set to -1 to discard old audit log files when a new one is created.
  • max_bytes : (int: 0) - The number of bytes that should be written to an audit log file before it needs to be rotated. Unless specified, there is no limit to the number of bytes that can be written to a log file.
  • max_duration : (string: "24h") - The maximum duration an audit log file should be written to before it needs to be rotated. Must be a duration value such as "30s". Defaults to "24h". If no time unit is specified, the time duration number is assumed to be in seconds. Set to 0 to disable time-based log file rotation.

By default, audit log file rotation is set to occur every 24 hours, with no older log file ever removed. New behavior, as well as the new options, are reflected in the documentation.

In order to revert to previous behavior, where log rotation was not handled by the Vault, the max_duration option must be set to 0, as all other new options are already set to 0 by default.

Resolves #21847

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.
  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.
  • If applicable, I've documented the impact of any changes to security controls.

Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

@hashicorp-cla-app

hashicorp-cla-app Bot commented Jul 4, 2025 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@t0x01
t0x01 force-pushed the pr/t0x01/audit-file-rotation branch from 6d45736 to 977840a Compare July 7, 2025 08:56
@t0x01
t0x01 marked this pull request as ready for review July 7, 2025 09:19
@t0x01
t0x01 requested review from a team as code owners July 7, 2025 09:19
@t0x01
t0x01 requested review from anwittin and brewgator July 7, 2025 09:19
@t0x01
t0x01 force-pushed the pr/t0x01/audit-file-rotation branch from 977840a to 5bbebdf Compare July 15, 2025 20:39
@schavis

schavis commented Jul 17, 2025

Copy link
Copy Markdown
Contributor

We are migrating Vault content to a different repo. Please recreate the content portion of this PR against the hashicorp/web-unified-docs repo on or after Monday, July 21, 2025.

@t0x01

t0x01 commented Aug 27, 2025

Copy link
Copy Markdown
Author

Hello.

Could you please clarify if i need to completely remove all documentation changes from this PR? I have already recreated them in the hashicorp/web-unified-docs repo (PR 600).

Also, could you please tell me if there is anything else i need to do for this PR to be reviewed?

Thanks.

@t0x01
t0x01 force-pushed the pr/t0x01/audit-file-rotation branch from 5bbebdf to 8e2d3de Compare September 3, 2025 12:07
@vercel

vercel Bot commented Sep 3, 2025

Copy link
Copy Markdown

@t0x01 is attempting to deploy a commit to the HashiCorp Team on Vercel.

A member of the Team first needs to authorize it.

@brewgator
brewgator removed request for a team, anwittin and brewgator September 18, 2025 16:27
@t0x01

t0x01 commented Jun 10, 2026

Copy link
Copy Markdown
Author

@schavis Sorry for pinging. Is there anything else you need me to do in this PR? Not sure how to interpret removal of requests for review. I am aware that some HashiCorp operations were transitioned to IBM around that time but couldn't find any related changes in contributing documentation. I would appreciate it if you could tell me if i need to do something else now to get a review for this PR.

Allow to natively configure Vault file audit device log file rotation with the `audit enable` command by adding 3 new options to the file backend:

- `max_files`
- `max_bytes`
- `max_duration`

By default, audit log file rotation is set to occur every 24 hours, with no older log file ever removed.

Signed-off-by: t0x01 <T0x01@protonmail.ch>
@t0x01
t0x01 force-pushed the pr/t0x01/audit-file-rotation branch from 8e2d3de to c9b02b6 Compare July 16, 2026 12:58
@dosubot dosubot Bot added the size:L This PR changes 100-499 lines, ignoring generated files. label Jul 16, 2026
@vercel

vercel Bot commented Jul 16, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
vault-ui Error Error Jul 16, 2026 12:58pm

Request Review

@vercel

vercel Bot commented Jul 16, 2026

Copy link
Copy Markdown

Deployment failed with the following error:

The `vercel.json` schema validation failed with the following message: should NOT have additional property `public`

Learn More: https://vercel.com/docs/concepts/projects/project-configuration

This branch had an error being deployed

1 failed deployment
Preview — c9b02b6e Deployed Jul 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core/audit need-to-move-docs size:L This PR changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support audit file rotation in Vault

3 participants