Skip to main content
GET
List Audit Events
string
Filtrar pelo namespace do AuditEvent. Sem ele, lista todos os namespaces.
string
Filtrar por eventType (comparação exata), ex.: issue_created, issue_resolved, issue_escalated, issue_contained, remediation_started, remediation_completed, remediation_failed, approval_requested, approval_approved, approval_rejected, approval_expired, notification_sent, slo_violation, sla_breach
string
Filtrar por severidade: info, warning, critical
string
Filtrar pelo nome do recurso afetado (comparação exata com resourceName)
string
Apenas eventos a partir deste timestamp RFC 3339 (spec.timestamp, ou o horário de criação na falta dele)
string
Apenas eventos até este timestamp RFC 3339
integer
padrão:"1"
Número da página
integer
padrão:"20"
Itens por página (máximo 100)
Role mínima: viewer. Os AuditEvents são gravados pelos controllers do operator (reconcilers de Issue, Remediation, Notification, SLO e SLA). O ator é o controller, exceto em approval_approved e approval_rejected depois de uma decisão humana: aí actorType é user e actorName lista os aprovadores registrados em status.decisions da ApprovalRequest (também no detalhe approvers). Uma aprovação automática ou uma expiração traz ApprovalReconciler. Chamadas a esta API REST (acknowledge, approve, edição de runbooks etc.) não viram AuditEvents; o operator apenas as registra como linhas [REST] no próprio log. detail achata spec.details em pares chave=valor unidos por ; (na ordem do map, então a ordem dos pares não é estável). Os itens vêm ordenados do mais recente para o mais antigo por timestamp (o horário de criação quando ele falta), então cada página é uma fatia estável da trilha.

Autorizações

X-API-Key
string
header
obrigatório

API key sent in the X-API-Key header. Keys are read from the Secret chatcli-operator-secrets, key api-keys (fallback: ConfigMap chatcli-operator-config, key api-keys) in the operator namespace, as a YAML list of {key, role, name, description} (name is the identity recorded on approval decisions); the operator chart creates it only with apiKeys.create: true. Roles: viewer < operator < admin — any other role string is denied everywhere. Changes are picked up within about 30 seconds; deleting both the Secret and the ConfigMap revokes every key. With no keys configured every /api/ call returns 401, unless CHATCLI_OPERATOR_DEV_MODE=true, which grants admin without a key (development only).

Parâmetros de consulta

namespace
string

Kubernetes namespace. Empty means all namespaces.

type
string

Exact match on spec.eventType: issue_created, issue_resolved, issue_escalated, issue_contained, remediation_started, remediation_completed, remediation_failed, approval_requested, approval_approved, approval_rejected, approval_expired, notification_sent, slo_violation or sla_breach.

severity
string

Exact match on spec.severity.

resource
string

Exact match on spec.resource.name.

from
string<date-time>

Start of the time range (RFC3339). Unparseable values are ignored.

Exemplo:

"2026-03-01T00:00:00Z"

to
string<date-time>

End of the time range (RFC3339). Unparseable values are ignored.

Exemplo:

"2026-03-19T23:59:59Z"

page
integer
padrão:1

Page number (1-based). Invalid values fall back to 1.

Intervalo obrigatório: x >= 1
pageSize
integer
padrão:20

Items per page. Values above 100 are capped at 100.

Intervalo obrigatório: 1 <= x <= 100

Resposta

Paginated audit events

apiVersion
string
Exemplo:

"v1"

kind
string
Exemplo:

"AuditEventList"

metadata
object
items
object[]