Version. OpenShell 0.1.2. Observed 2026-09-29.
Observed. Retention, rotation and on-disk location of sandbox logs and the OCSF audit stream are not documented for either the Docker or the Kubernetes driver.
Why it matters. Any compliance statement about an agent platform ("every tool call is audited") rests on knowing how long the audit record lives and where. Without this page an integrator cannot write the retention clause, and a SIEM integration has to be built by observation.
Ask. A reference page stating, per driver: where sandbox and OCSF logs are written, how long they are kept, when they rotate, and how to forward them.
Related: #4295 reports that --no-keep discards the logs entirely.
Version. OpenShell 0.1.2. Observed 2026-09-29.
Observed. Retention, rotation and on-disk location of sandbox logs and the OCSF audit stream are not documented for either the Docker or the Kubernetes driver.
Why it matters. Any compliance statement about an agent platform ("every tool call is audited") rests on knowing how long the audit record lives and where. Without this page an integrator cannot write the retention clause, and a SIEM integration has to be built by observation.
Ask. A reference page stating, per driver: where sandbox and OCSF logs are written, how long they are kept, when they rotate, and how to forward them.
Related: #4295 reports that
--no-keepdiscards the logs entirely.