Skip to content

docs: document sandbox and OCSF log retention, rotation and on-disk location per driver #4297

Description

@anthonychung

Version. OpenShell 0.1.2. Observed 2026-09-29.

Observed. Retention, rotation and on-disk location of sandbox logs and the OCSF audit stream are not documented for either the Docker or the Kubernetes driver.

Why it matters. Any compliance statement about an agent platform ("every tool call is audited") rests on knowing how long the audit record lives and where. Without this page an integrator cannot write the retention clause, and a SIEM integration has to be built by observation.

Ask. A reference page stating, per driver: where sandbox and OCSF logs are written, how long they are kept, when they rotate, and how to forward them.

Related: #4295 reports that --no-keep discards the logs entirely.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions