Skip to content

feat(audit): audit supervisor session establishment (connect, relay, tunnel) #3018

Description

@mattj-monad

User Story

As a security or compliance owner running OpenShell, I want supervisor session establishment — a sandbox connecting its supervisor, a relay stream being claimed, a WebSocket tunnel opening — recorded as structured audit events, so I can see when and by which principal a live control channel into a sandbox was opened and closed, not only what happened over it.

Problem Statement

OpenShell is gaining a structured audit trail for state-changing gateway operations (#2911) and for authentication and authorization outcomes (#2912). Neither covers the establishment of the supervisor↔gateway session and the relay and tunnel channels that ride it. ConnectSupervisor, RelayStream, and the WebSocket tunnel open and close are the moments a live channel into a sandbox comes up and goes down; today they surface only as ordinary diagnostic logs. Session establishment is not a resource mutation, so it is outside #2911's scope, and a successful, authorized establishment is not an authentication failure, so it is outside #2912. It falls between the two.

Impact / Why This Matters

An operator investigating a sandbox cannot reconstruct when its control channel was established, by which principal, or how long it stayed open — the session boundary that frames every exec, forward, and relay that follows. The exec and forward events (from #2911) presuppose a session that is already up; without a record of establishment and teardown, the trail has the actions but not the sessions that carried them, and cannot answer "when did a live channel into this sandbox exist, and who held it?" The current workaround is to infer session lifetime from surrounding diagnostic logs, which is neither stable nor attributable.

Proposed Design

Emit one structured OCSF audit event on establishment and one on teardown for each session-bearing path — ConnectSupervisor, RelayStream, and the WebSocket tunnel — naming the authenticated principal (sandbox or user), the sandbox, the channel type, the outcome, and a correlation id. The events never carry session input/output or bearer material. They reuse the audit helper, actor model, and master toggle that govern the control-plane audit events. The OCSF class is left to the implementer — an Entity Management (3004) session lifecycle event, in the spirit of the existing ssh-session records, is a natural fit. Emission is governed by the [openshell.gateway.audit] master toggle.

Acceptance Criteria

  • Each session-bearing path (ConnectSupervisor, RelayStream, WebSocket tunnel) emits an establishment record and a teardown record.
  • Each record names the authenticated principal, the sandbox, the channel type, the outcome, and a correlation id.
  • No session input/output, bearer token, or other secret material appears in any record; automated tests cover representative secret canaries.
  • Emission is governed by the existing [openshell.gateway.audit] master toggle.
  • Establishment and teardown for the same session share a correlation id so a session's lifetime can be reconstructed.
  • The events, their fields, and redaction behavior are documented for operators.

Alternatives Considered

  • Fold into feat(audit): emit structured gateway control-plane mutation events #2911. Rejected: session establishment is not a resource mutation, and modeling a channel's open/close as a CRUD event on a resource distorts the mutation catalog.
  • Infer sessions from exec/forward events. Rejected: those events assume a session is already established, so the session boundary and its lifetime are lost, and a session that carried no exec would leave no trace at all.
  • Accept the gap. Leaves the control-channel lifecycle — a first-order security fact about a sandbox — unrecorded.

Agent Investigation

Checklist

  • I've reviewed existing issues and the architecture docs
  • This is a design proposal, not a "please build this" request

Activity

  1. elezar commented on Aug 31, 2026

    @elezar
    Member

    📋 triage-agent

    Triage Assessment

    Classification: needs-investigation

    Summary

    The session-lifecycle audit gap is credible, and ConnectSupervisor and RelayStream already expose enough session and sandbox context for incremental instrumentation. The full proposal needs a focused design investigation before implementation, however, because its assumed audit foundation is not yet present and its WebSocket attribution requirement is not implementable at the current upgrade boundary.

    Investigation

    Impact Signals

    • Affected users/scope: Security and compliance operators investigating live gateway-to-sandbox control channels.
    • Regression: No demonstrated regression; this is an observability capability gap.
    • Workaround: Infer lifetime from diagnostic logs; attribution and stable lifecycle records are unavailable.
    • Evidence quality: High for the current lifecycle paths and missing WebSocket context; medium for the final event taxonomy pending the audit-foundation work.

    Investigation Needed

    Define the event/correlation boundary and teardown outcome taxonomy, including how session supersession is represented. Clarify whether a WebSocket transport opening is itself an audit event; if so, define how trusted user-principal and sandbox attribution reaches its upgrade boundary. Also record the dependency and intended sequencing with #2911 and #2912, including which audit configuration controls this feature until that foundation lands.

    Human Decision Required

    Decide whether OpenShell should invest in the focused investigation. If yes, apply state:accepted, associate the issue with a roadmap item, or do both, and decide whether the work remains human-owned. Either action records acceptance; roadmap placement additionally records sequencing.

  2. added
    area:gatewayGateway server and control-plane work
    topic:observabilityLogging, metrics, and observability work
    and removed
    state:triage-neededOpened without agent diagnostics and needs triage
    on Aug 31, 2026
  3. Samyra312007 commented on Sep 2, 2026

    @Samyra312007

    Respected Maintainer and Author, I would like to understand about this issue end to end and work on it. Is it open for contributors?

  4. mattj-monad commented on Sep 30, 2026

    @mattj-monad
    Author

    Thanks for the interest @Samyra312007, and sorry for the slow reply. This one depends on the gateway audit foundation (#2911, #2912) and still needs the design work @elezar flagged for the WebSocket tunnel, so it isn't ready to pick up yet. We have the foundation built and plan to take it once that lands; happy to have your review then.

  5. Samyra312007 commented on Sep 30, 2026

    @Samyra312007

    @mattj-monad Thanks for the response. Once ping me again as soon as the foundation built. I will take it on from there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions