Emit audit event for instance SSH certificate creation

What does this MR do and why?

Emits audit event on instance SSH certificate creation.

References

Contributes to #611324 (closed)

Screenshots or screen recordings

Before After

How to set up and validate locally

  1. In gdk/env.runit, set export GITLAB_SIMULATE_SAAS=0, then gdk restart rails-web.
  2. Enable the flag in rails c: Feature.enable(:instance_ssh_certificates).
  3. Sign in as an admin with admin mode enabled and open http://gdk.test:3000/admin/ssh_certificates.
  4. Select Add certificate authority. The form renders below the card header.
  5. Generate a CA key with ssh-keygen -t ed25519 -f /tmp/ca -N '', enter a title and the contents of /tmp/ca.pub, and submit.
  6. AuditEvents::InstanceAuditEvent.last returns an audit event for the newly created certificate, with the title and fingerprint logged in custom_message.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Fred Reinink

Merge request reports

Loading
Loading