附加服务管理器 (ADD)
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
数据更改(CRUD 操作)
包含审核信息的日志条目中的字段 |
审核元数据 |
审核字段名称 |
值 |
用户或服务身份 |
user.username |
例如,
"user":{
"username":"system:serviceaccount:kube-system:
addon-manager-controller-sa"
}
|
目标
(调用 API 的字段和值)
|
requestURI |
"requestURI":"/apis/addon.private.gdc.goog/VERSION/
namespaces/root/addonsets/root-admin/status"
|
操作
(包含所执行操作的字段)
|
verb |
"verb":"patch"
|
活动时间戳 |
requestReceivedTimestamp
|
例如,
"requestReceivedTimestamp":2022-11-18T23:15:22.882546Z
|
操作来源 |
sourceIPs |
例如,
"sourceIPs":["10.253.132.107"]
|
结果 |
stage |
例如,
"stage":"RequestReceived"
|
其他字段 |
不适用 |
不适用 |
日志示例
{
"kind": "Event",
"apiVersion": "audit.k8s.io/v1",
"level": "Metadata",
"auditID": "8c604d8d-368c-4294-9cfa-e361b4cbbefa",
"stage": "RequestReceived",
"requestURI": "/apis/addon.private.gdc.goog/VERSION/namespaces/root/addonsets/root-admin/status",
"verb": "patch",
"user": {
"username": "system:serviceaccount:kube-system:addon-manager-controller-sa",
"uid": "43ee00d0-fd9a-48ff-9e74-da11e39144fe",
"groups": [
"system:serviceaccounts",
"system:serviceaccounts:kube-system",
"system:authenticated"
],
"extra": {
"authentication.kubernetes.io/pod-name": [
"addon-manager-controller-55cc67bf8f-dr7z7"
],
"authentication.kubernetes.io/pod-uid": [
"735fc26e-a94a-4c10-a90a-86948cda9eeb"
]
}
},
"sourceIPs": [
"10.253.132.107"
],
"userAgent": "addon-manager-cm/v0.0.0 (linux/amd64) kubernetes/$Format",
"objectRef": {
"resource": "addonsets",
"namespace": "root",
"name": "root-admin",
"apiGroup": "addon.private.gdc.goog",
"apiVersion": "VERSION",
"subresource": "status"
},
"requestReceivedTimestamp": "2022-11-18T23:15:22.882546Z",
"stageTimestamp": "2022-11-18T23:15:22.882546Z"
}
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-09-04。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[[["\u003cp\u003eThis content outlines the audit logging specifics for root-only workloads, utilizing Kubernetes audit logs as the source.\u003c/p\u003e\n"],["\u003cp\u003eThe audited operations focus on data changes, specifically Create, Read, Update, and Delete (CRUD) operations, within the Kubernetes environment.\u003c/p\u003e\n"],["\u003cp\u003eKey audit log fields include the user or service identity (\u003ccode\u003euser.username\u003c/code\u003e), the target resource (\u003ccode\u003erequestURI\u003c/code\u003e), the action performed (\u003ccode\u003everb\u003c/code\u003e), the event timestamp (\u003ccode\u003erequestReceivedTimestamp\u003c/code\u003e), the source of the action (\u003ccode\u003esourceIPs\u003c/code\u003e), and the outcome (\u003ccode\u003estage\u003c/code\u003e).\u003c/p\u003e\n"],["\u003cp\u003eAn example log entry demonstrates the structure and content of an audit event, including details about the user, action, timestamp, and source IP.\u003c/p\u003e\n"]]],[],null,["# Add-on manager (ADD)\n\nData changes (CRUD operations)\n------------------------------\n\n**Example log** \n\n {\n \"kind\": \"Event\",\n \"apiVersion\": \"audit.k8s.io/v1\",\n \"level\": \"Metadata\",\n \"auditID\": \"8c604d8d-368c-4294-9cfa-e361b4cbbefa\",\n \"stage\": \"RequestReceived\",\n \n \"requestURI\": \"/apis/addon.private.gdc.goog/VERSION/namespaces/root/addonsets/root-admin/status\",\n \n \"verb\": \"patch\",\n \"user\": {\n \"username\": \"system:serviceaccount:kube-system:addon-manager-controller-sa\",\n \"uid\": \"43ee00d0-fd9a-48ff-9e74-da11e39144fe\",\n \"groups\": [\n \"system:serviceaccounts\",\n \"system:serviceaccounts:kube-system\",\n \"system:authenticated\"\n ],\n \"extra\": {\n \"authentication.kubernetes.io/pod-name\": [\n \"addon-manager-controller-55cc67bf8f-dr7z7\"\n ],\n \"authentication.kubernetes.io/pod-uid\": [\n \"735fc26e-a94a-4c10-a90a-86948cda9eeb\"\n ]\n }\n },\n \"sourceIPs\": [\n \"10.253.132.107\"\n ],\n \"userAgent\": \"addon-manager-cm/v0.0.0 (linux/amd64) kubernetes/$Format\",\n \"objectRef\": {\n \"resource\": \"addonsets\",\n \"namespace\": \"root\",\n \"name\": \"root-admin\",\n \"apiGroup\": \"addon.private.gdc.goog\",\n \"apiVersion\": \"VERSION\",\n \"subresource\": \"status\"\n },\n \"requestReceivedTimestamp\": \"2022-11-18T23:15:22.882546Z\",\n \"stageTimestamp\": \"2022-11-18T23:15:22.882546Z\"\n }"]]