Conversation
6d45736 to
977840a
Compare
977840a to
5bbebdf
Compare
|
We are migrating Vault content to a different repo. Please recreate the content portion of this PR against the hashicorp/web-unified-docs repo on or after Monday, July 21, 2025. |
|
Hello. Could you please clarify if i need to completely remove all documentation changes from this PR? I have already recreated them in the hashicorp/web-unified-docs repo (PR 600). Also, could you please tell me if there is anything else i need to do for this PR to be reviewed? Thanks. |
5bbebdf to
8e2d3de
Compare
|
@t0x01 is attempting to deploy a commit to the HashiCorp Team on Vercel. A member of the Team first needs to authorize it. |
|
@schavis Sorry for pinging. Is there anything else you need me to do in this PR? Not sure how to interpret removal of requests for review. I am aware that some HashiCorp operations were transitioned to IBM around that time but couldn't find any related changes in contributing documentation. I would appreciate it if you could tell me if i need to do something else now to get a review for this PR. |
Allow to natively configure Vault file audit device log file rotation with the `audit enable` command by adding 3 new options to the file backend: - `max_files` - `max_bytes` - `max_duration` By default, audit log file rotation is set to occur every 24 hours, with no older log file ever removed. Signed-off-by: t0x01 <T0x01@protonmail.ch>
8e2d3de to
c9b02b6
Compare
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Deployment failed with the following error: Learn More: https://vercel.com/docs/concepts/projects/project-configuration |
Description
Allow to natively configure Vault file audit device log file rotation with the
audit enablecommand by adding 3 new options to the file backend. These 3 new options and their default values are as follows:max_files:(int: 0)- The maximum number of older audit log file archives to keep. Defaults to0(no files are ever deleted). Set to-1to discard old audit log files when a new one is created.max_bytes:(int: 0)- The number of bytes that should be written to an audit log file before it needs to be rotated. Unless specified, there is no limit to the number of bytes that can be written to a log file.max_duration:(string: "24h")- The maximum duration an audit log file should be written to before it needs to be rotated. Must be a duration value such as"30s". Defaults to"24h". If no time unit is specified, the time duration number is assumed to be in seconds. Set to0to disable time-based log file rotation.By default, audit log file rotation is set to occur every 24 hours, with no older log file ever removed. New behavior, as well as the new options, are reflected in the documentation.
In order to revert to previous behavior, where log rotation was not handled by the Vault, the
max_durationoption must be set to0, as all other new options are already set to0by default.Resolves #21847
PCI review checklist
Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.