Repository navigation
Conversation
Emit sanitized scalar auth_scheme/user bindings for valid attachments and actual authentication outcomes. Preserve C1 feature gates, mode snapshots and best-effort reporting; account explicitly for setup bindings in write-focused tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Document that the pinned local JOBS parser rejects unknown fields and staging quarantines those records. Require updating and validating the consumer before enabling additive v2 producer fields; leave runtime behavior unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Add session and authentication context to enhanced audit logging so consumers can follow valid connection attachments, reconnects, and authentication changes without rewriting the identity recorded on earlier writes.
Two operations are emitted:
sessionEstablishedauthenticationEach record pairs one sanitized scalar
userwith itsauth_scheme. Distinct bindings are emitted separately; duplicate sanitized pairs within one hook are collapsed.These records are binding observations, not unique authentication-attempt or new-session counters. X509 or super identity is not evidence of TLS.
Tests
Validated
SessionAuthAuditTesttogether with existing audit, auth, X509, SASL, TTL, DataTree, and metrics regression tests on JDK 11 targeting Java 8 APIs:Coverage includes real standalone/quorum session movement, real DIGEST-MD5 exchanges, synthetic X509/provider cases, scalar escaping, feature gates, mode changes, identity changes after attachment, and failing audit/reporting backends.
Live TLS transport, a Kerberos KDC, and production log delivery were not qualified by these tests.
Changes that Break Backward Compatibility (Optional)
Bindings require both
zookeeper.audit.enable=trueandzookeeper.audit.enhanced.enable=true; default and legacy-mode behavior are unchanged.No authentication/TLS policy, ACL decision, or client protocol change. Consumers must handle per-identity event cardinality and unknown attribution. Strict schema consumers need updating before additive producer fields are enabled.
Documentation (Optional)
Updated
zookeeper-docs/src/main/resources/markdown/zookeeperAuditLogs.mdwith binding fields, examples, identity/cardinality semantics, privacy, and consumer compatibility requirements.🤖 Generated with GitHub Copilot CLI