curl --request GET \
--url {scheme}://{host}:{port}/{basePath}/audit \
--header 'X-API-Key: <api-key>'import requests
url = "{scheme}://{host}:{port}/{basePath}/audit"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('{scheme}://{host}:{port}/{basePath}/audit', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "62437",
CURLOPT_URL => "{scheme}://{host}:{port}/{basePath}/audit",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "{scheme}://{host}:{port}/{basePath}/audit"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("{scheme}://{host}:{port}/{basePath}/audit")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("{scheme}://{host}:{port}/{basePath}/audit")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"apiVersion": "v1",
"kind": "AuditEventList",
"metadata": {
"totalCount": 2,
"page": 1,
"pageSize": 20
},
"items": [
{
"name": "audit-1773935700123456789-k3m9qz",
"namespace": "production",
"eventType": "approval_approved",
"severity": "info",
"actorType": "user",
"actorName": "sre-oncall",
"resourceKind": "ApprovalRequest",
"resourceName": "approval-checkout-service-oom-kill-1773871200-plan-1",
"resourceNamespace": "production",
"correlationId": "checkout-service-oom-kill-1773871200",
"detail": "approvers=sre-oncall; auto=false; decision=approved; issue=checkout-service-oom-kill-1773871200",
"timestamp": "2026-03-19T15:35:00Z",
"creationTimestamp": "2026-03-19T15:35:00Z"
},
{
"name": "audit-1773935400987654321-p8x2wd",
"namespace": "production",
"eventType": "remediation_started",
"severity": "info",
"actorType": "controller",
"actorName": "RemediationReconciler",
"resourceKind": "RemediationPlan",
"resourceName": "checkout-service-oom-kill-1773871200-plan-1",
"resourceNamespace": "production",
"correlationId": "checkout-service-oom-kill-1773871200",
"timestamp": "2026-03-19T15:30:00Z",
"creationTimestamp": "2026-03-19T15:30:00Z"
}
]
}
Listar Eventos de Auditoria
Retorna os registros AuditEvent gravados pelos controllers do operator
curl --request GET \
--url {scheme}://{host}:{port}/{basePath}/audit \
--header 'X-API-Key: <api-key>'import requests
url = "{scheme}://{host}:{port}/{basePath}/audit"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('{scheme}://{host}:{port}/{basePath}/audit', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "62437",
CURLOPT_URL => "{scheme}://{host}:{port}/{basePath}/audit",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "{scheme}://{host}:{port}/{basePath}/audit"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("{scheme}://{host}:{port}/{basePath}/audit")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("{scheme}://{host}:{port}/{basePath}/audit")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"apiVersion": "v1",
"kind": "AuditEventList",
"metadata": {
"totalCount": 2,
"page": 1,
"pageSize": 20
},
"items": [
{
"name": "audit-1773935700123456789-k3m9qz",
"namespace": "production",
"eventType": "approval_approved",
"severity": "info",
"actorType": "user",
"actorName": "sre-oncall",
"resourceKind": "ApprovalRequest",
"resourceName": "approval-checkout-service-oom-kill-1773871200-plan-1",
"resourceNamespace": "production",
"correlationId": "checkout-service-oom-kill-1773871200",
"detail": "approvers=sre-oncall; auto=false; decision=approved; issue=checkout-service-oom-kill-1773871200",
"timestamp": "2026-03-19T15:35:00Z",
"creationTimestamp": "2026-03-19T15:35:00Z"
},
{
"name": "audit-1773935400987654321-p8x2wd",
"namespace": "production",
"eventType": "remediation_started",
"severity": "info",
"actorType": "controller",
"actorName": "RemediationReconciler",
"resourceKind": "RemediationPlan",
"resourceName": "checkout-service-oom-kill-1773871200-plan-1",
"resourceNamespace": "production",
"correlationId": "checkout-service-oom-kill-1773871200",
"timestamp": "2026-03-19T15:30:00Z",
"creationTimestamp": "2026-03-19T15:30:00Z"
}
]
}
eventType (comparação exata), ex.: issue_created, issue_resolved, issue_escalated, issue_contained, remediation_started, remediation_completed, remediation_failed, approval_requested, approval_approved, approval_rejected, approval_expired, notification_sent, slo_violation, sla_breachinfo, warning, criticalresourceName)spec.timestamp, ou o horário de criação na falta dele)viewer. Os AuditEvents são gravados pelos controllers do operator (reconcilers de Issue, Remediation, Notification, SLO e SLA). O ator é o controller, exceto em approval_approved e approval_rejected depois de uma decisão humana: aà actorType é user e actorName lista os aprovadores registrados em status.decisions da ApprovalRequest (também no detalhe approvers). Uma aprovação automática ou uma expiração traz ApprovalReconciler. Chamadas a esta API REST (acknowledge, approve, edição de runbooks etc.) não viram AuditEvents; o operator apenas as registra como linhas [REST] no próprio log.
detail achata spec.details em pares chave=valor unidos por ; (na ordem do map, então a ordem dos pares não é estável). Os itens vêm ordenados do mais recente para o mais antigo por timestamp (o horário de criação quando ele falta), então cada página é uma fatia estável da trilha.
{
"apiVersion": "v1",
"kind": "AuditEventList",
"metadata": {
"totalCount": 2,
"page": 1,
"pageSize": 20
},
"items": [
{
"name": "audit-1773935700123456789-k3m9qz",
"namespace": "production",
"eventType": "approval_approved",
"severity": "info",
"actorType": "user",
"actorName": "sre-oncall",
"resourceKind": "ApprovalRequest",
"resourceName": "approval-checkout-service-oom-kill-1773871200-plan-1",
"resourceNamespace": "production",
"correlationId": "checkout-service-oom-kill-1773871200",
"detail": "approvers=sre-oncall; auto=false; decision=approved; issue=checkout-service-oom-kill-1773871200",
"timestamp": "2026-03-19T15:35:00Z",
"creationTimestamp": "2026-03-19T15:35:00Z"
},
{
"name": "audit-1773935400987654321-p8x2wd",
"namespace": "production",
"eventType": "remediation_started",
"severity": "info",
"actorType": "controller",
"actorName": "RemediationReconciler",
"resourceKind": "RemediationPlan",
"resourceName": "checkout-service-oom-kill-1773871200-plan-1",
"resourceNamespace": "production",
"correlationId": "checkout-service-oom-kill-1773871200",
"timestamp": "2026-03-19T15:30:00Z",
"creationTimestamp": "2026-03-19T15:30:00Z"
}
]
}
Autorizações
API key sent in the X-API-Key header. Keys are read from the Secret chatcli-operator-secrets, key api-keys (fallback: ConfigMap chatcli-operator-config, key api-keys) in the operator namespace, as a YAML list of {key, role, name, description} (name is the identity recorded on approval decisions); the operator chart creates it only with apiKeys.create: true. Roles: viewer < operator < admin — any other role string is denied everywhere. Changes are picked up within about 30 seconds; deleting both the Secret and the ConfigMap revokes every key. With no keys configured every /api/ call returns 401, unless CHATCLI_OPERATOR_DEV_MODE=true, which grants admin without a key (development only).
Parâmetros de consulta
Kubernetes namespace. Empty means all namespaces.
Exact match on spec.eventType: issue_created, issue_resolved, issue_escalated, issue_contained, remediation_started, remediation_completed, remediation_failed, approval_requested, approval_approved, approval_rejected, approval_expired, notification_sent, slo_violation or sla_breach.
Exact match on spec.severity.
Exact match on spec.resource.name.
Start of the time range (RFC3339). Unparseable values are ignored.
"2026-03-01T00:00:00Z"
End of the time range (RFC3339). Unparseable values are ignored.
"2026-03-19T23:59:59Z"
Page number (1-based). Invalid values fall back to 1.
x >= 1Items per page. Values above 100 are capped at 100.
1 <= x <= 100