diff --git a/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts b/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts index 0e313b59b..723893c52 100644 --- a/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts +++ b/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts @@ -2,6 +2,7 @@ import { ForbiddenError } from "@casl/ability"; import { RawAxiosRequestHeaders } from "axios"; import { SecretKeyEncoding } from "@app/db/schemas"; +import { getConfig } from "@app/lib/config/env"; import { request } from "@app/lib/config/request"; import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption"; import { BadRequestError } from "@app/lib/errors"; @@ -44,6 +45,7 @@ export const auditLogStreamServiceFactory = ({ }: TCreateAuditLogStreamDTO) => { if (!actorOrgId) throw new BadRequestError({ message: "Missing org id from token" }); + const appCfg = getConfig(); const plan = await licenseService.getPlan(actorOrgId); if (!plan.auditLogStreams) throw new BadRequestError({ @@ -59,7 +61,9 @@ export const auditLogStreamServiceFactory = ({ ); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Create, OrgPermissionSubjects.Settings); - validateLocalIps(url); + if (appCfg.isCloud) { + validateLocalIps(url); + } const totalStreams = await auditLogStreamDAL.find({ orgId: actorOrgId }); if (totalStreams.length >= plan.auditLogStreamLimit) { @@ -131,7 +135,8 @@ export const auditLogStreamServiceFactory = ({ const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings); - if (url) validateLocalIps(url); + const appCfg = getConfig(); + if (url && appCfg.isCloud) validateLocalIps(url); // testing connection first const streamHeaders: RawAxiosRequestHeaders = { "Content-Type": "application/json" }; diff --git a/docs/documentation/platform/audit-log-streams/audit-log-streams-with-fluentbit.mdx b/docs/documentation/platform/audit-log-streams/audit-log-streams-with-fluentbit.mdx new file mode 100644 index 000000000..7c0365d7a --- /dev/null +++ b/docs/documentation/platform/audit-log-streams/audit-log-streams-with-fluentbit.mdx @@ -0,0 +1,61 @@ +--- +title: "Stream to Non-HTTP providers" +description: "Learn how to stream Infisical Audit Logs to other Non-HTTP providers" +--- + + + Audit log streams is a paid feature. + + If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical, + then you should contact team@infisical.com to purchase an enterprise license to use it. + + +This guide explains how to store Infisical Audit log streams using a provider that doesn't support HTTP-based streaming, such as AWS S3. We'll use a log collector service to achieve this. + +## Overview + +Log collectors are tools used to collect, analyze, transform, and send logs to storage. In this guide, we'll focus on [Fluent Bit](https://fluentbit.io), a popular and efficient log collector. + +You can deploy Fluent Bit in two ways: +1. As a sidecar to your self-hosted Infisical instance +2. As a standalone service in any deployment service (e.g., AWS EC2, ECS, or GCP Compute Engine) + +For various deployment options, refer to the [Fluent Bit Getting Started guide](https://docs.fluentbit.io/manual/installation/getting-started-with-fluent-bit). + +## Configuration + +To set up Fluent Bit, you'll need to provide a configuration file that establishes an HTTP listener and configures an output to send JSON data to your chosen storage solution (e.g., S3, Elasticsearch). + +### Example Configuration: HTTP to AWS S3 + +The following Fluent Bit configuration sets up an HTTP listener on port `8888` and sends logs to AWS S3: + +```ini +[SERVICE] + Flush 1 + Log_Level info + Daemon off + +[INPUT] + Name http + Listen 0.0.0.0 + Port 8888 + +[OUTPUT] + Name s3 + Match * + bucket my-bucket + region us-west-2 + total_file_size 50M + use_put_object Off + compression gzip + s3_key_format /$TAG/%Y/%m/%d/%H_%M_%S.gz +``` +### Connecting Infisical Audit Log Stream + +Once you have set up and configured Fluent Bit, you can direct the Infisical Audit log stream to the Fluent Bit HTTP listener address. + + +By following this guide, you can effectively store Infisical Audit log streams in AWS S3 or other storage solutions that don't natively support HTTP-based streaming. + +This approach provides flexibility and allows you to leverage the power of log collectors like Fluent Bit to manage and store your audit logs efficiently. diff --git a/docs/documentation/platform/audit-log-streams.mdx b/docs/documentation/platform/audit-log-streams/audit-log-streams.mdx similarity index 100% rename from docs/documentation/platform/audit-log-streams.mdx rename to docs/documentation/platform/audit-log-streams/audit-log-streams.mdx diff --git a/docs/documentation/platform/audit-logs.mdx b/docs/documentation/platform/audit-logs.mdx index be2381da2..594c1f707 100644 --- a/docs/documentation/platform/audit-logs.mdx +++ b/docs/documentation/platform/audit-logs.mdx @@ -1,5 +1,5 @@ --- -title: "Audit Logs" +title: "Overview" description: "Track evert event action performed within Infisical projects." --- diff --git a/docs/mint.json b/docs/mint.json index b56493e01..d22bf9038 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -130,11 +130,18 @@ "documentation/platform/access-controls/temporary-access", "documentation/platform/access-controls/access-requests", "documentation/platform/pr-workflows", - "documentation/platform/audit-logs", "documentation/platform/audit-log-streams", "documentation/platform/groups" ] }, + { + "group": "Audit Logs", + "pages": [ + "documentation/platform/audit-logs", + "documentation/platform/audit-log-streams/audit-log-streams", + "documentation/platform/audit-log-streams/audit-log-streams-with-fluentbit" + ] + }, { "group": "Secret Rotation", "pages": [