Repository navigation
feat(audit): audit supervisor session establishment (connect, relay, tunnel) #3018
Description
Activity
- addedstate:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triage
on Aug 29, 2026 📋 triage-agent
Triage Assessment
Classification: needs-investigation
Summary
The session-lifecycle audit gap is credible, and
ConnectSupervisorandRelayStreamalready expose enough session and sandbox context for incremental instrumentation. The full proposal needs a focused design investigation before implementation, however, because its assumed audit foundation is not yet present and its WebSocket attribution requirement is not implementable at the current upgrade boundary.Investigation
ConnectSupervisorcreates a UUID session id and has the sandbox-scoped principal;RelayStreamclaims a pending relay with the sandbox and channel id. Both currently produce diagnostic lifecycle logs rather than structured gateway audit events.- The related audit-foundation issues feat(audit): emit structured gateway control-plane mutation events #2911 and feat(auth): emit structured gateway authentication and authorization events #2912 remain open. The proposed reusable gateway audit helper and
[openshell.gateway.audit]master toggle are therefore dependencies, not established infrastructure. - The WebSocket tunnel upgrade handler currently receives only gateway state and the upgrade object, then starts a raw multiplex bridge. It does not have a trusted principal or sandbox id, so it cannot truthfully meet the proposed per-tunnel attribution requirement without additional design.
- No direct duplicate was found. Enhance OpenShell's OCSF telemetry and export it off-box via OTLP #2892 is parent audit-taxonomy context; feat(audit): emit structured gateway control-plane mutation events #2911 and feat(auth): emit structured gateway authentication and authorization events #2912 are adjacent prerequisite work.
Impact Signals
- Affected users/scope: Security and compliance operators investigating live gateway-to-sandbox control channels.
- Regression: No demonstrated regression; this is an observability capability gap.
- Workaround: Infer lifetime from diagnostic logs; attribution and stable lifecycle records are unavailable.
- Evidence quality: High for the current lifecycle paths and missing WebSocket context; medium for the final event taxonomy pending the audit-foundation work.
Investigation Needed
Define the event/correlation boundary and teardown outcome taxonomy, including how session supersession is represented. Clarify whether a WebSocket transport opening is itself an audit event; if so, define how trusted user-principal and sandbox attribution reaches its upgrade boundary. Also record the dependency and intended sequencing with #2911 and #2912, including which audit configuration controls this feature until that foundation lands.
Human Decision Required
Decide whether OpenShell should invest in the focused investigation. If yes, apply
state:accepted, associate the issue with a roadmap item, or do both, and decide whether the work remains human-owned. Either action records acceptance; roadmap placement additionally records sequencing.- addedarea:gatewayGateway server and control-plane workGateway server and control-plane worktopic:observabilityLogging, metrics, and observability workLogging, metrics, and observability workand removedstate:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triage
on Aug 31, 2026 Respected Maintainer and Author, I would like to understand about this issue end to end and work on it. Is it open for contributors?
Reacted by natedemoss- added a parent issue
on Sep 2, 2026 Thanks for the interest @Samyra312007, and sorry for the slow reply. This one depends on the gateway audit foundation (#2911, #2912) and still needs the design work @elezar flagged for the WebSocket tunnel, so it isn't ready to pick up yet. We have the foundation built and plan to take it once that lands; happy to have your review then.
Reacted by Sahil Kumar@mattj-monad Thanks for the response. Once ping me again as soon as the foundation built. I will take it on from there.
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsPlanning
User Story
As a security or compliance owner running OpenShell, I want supervisor session establishment — a sandbox connecting its supervisor, a relay stream being claimed, a WebSocket tunnel opening — recorded as structured audit events, so I can see when and by which principal a live control channel into a sandbox was opened and closed, not only what happened over it.
Problem Statement
OpenShell is gaining a structured audit trail for state-changing gateway operations (#2911) and for authentication and authorization outcomes (#2912). Neither covers the establishment of the supervisor↔gateway session and the relay and tunnel channels that ride it.
ConnectSupervisor,RelayStream, and the WebSocket tunnel open and close are the moments a live channel into a sandbox comes up and goes down; today they surface only as ordinary diagnostic logs. Session establishment is not a resource mutation, so it is outside #2911's scope, and a successful, authorized establishment is not an authentication failure, so it is outside #2912. It falls between the two.Impact / Why This Matters
An operator investigating a sandbox cannot reconstruct when its control channel was established, by which principal, or how long it stayed open — the session boundary that frames every exec, forward, and relay that follows. The exec and forward events (from #2911) presuppose a session that is already up; without a record of establishment and teardown, the trail has the actions but not the sessions that carried them, and cannot answer "when did a live channel into this sandbox exist, and who held it?" The current workaround is to infer session lifetime from surrounding diagnostic logs, which is neither stable nor attributable.
Proposed Design
Emit one structured OCSF audit event on establishment and one on teardown for each session-bearing path —
ConnectSupervisor,RelayStream, and the WebSocket tunnel — naming the authenticated principal (sandbox or user), the sandbox, the channel type, the outcome, and a correlation id. The events never carry session input/output or bearer material. They reuse the audit helper, actor model, and master toggle that govern the control-plane audit events. The OCSF class is left to the implementer — an Entity Management (3004) session lifecycle event, in the spirit of the existing ssh-session records, is a natural fit. Emission is governed by the[openshell.gateway.audit]master toggle.Acceptance Criteria
ConnectSupervisor,RelayStream, WebSocket tunnel) emits an establishment record and a teardown record.[openshell.gateway.audit]master toggle.Alternatives Considered
Agent Investigation
ConnectSupervisor,RelayStream, and the WebSocket tunnel in the gateway/supervisor session path, with the authenticated principal available at the boundary.Checklist