Skip to content

sbx: document audit logging as a governance feature#25239

Draft
dvdksn wants to merge 5 commits into
docker:mainfrom
dvdksn:worktree-sbx-audit-logging-docs
Draft

sbx: document audit logging as a governance feature#25239
dvdksn wants to merge 5 commits into
docker:mainfrom
dvdksn:worktree-sbx-audit-logging-docs

Conversation

@dvdksn
Copy link
Copy Markdown
Contributor

@dvdksn dvdksn commented Jun 2, 2026

Summary

Documents sbx audit logging, which records a structured audit event for every policy decision sandboxd makes. The new governance page covers what gets recorded, where the JSONL records land per-OS, how to collect them with a SIEM, and how to override the storage location.

Add a governance page describing how sandboxd records a structured audit
event for every policy decision, where the JSONL records land on disk, how
to collect them with a SIEM, and how to override the storage location. Link
it from the governance index and add Filebeat to the Vale vocabulary.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@netlify
Copy link
Copy Markdown

netlify Bot commented Jun 2, 2026

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 672781d
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6a1fef4cdd3dc900084bdd1c
😎 Deploy Preview https://deploy-preview-25239--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Copy link
Copy Markdown

@docker-agent docker-agent left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟡 NEEDS ATTENTION

Comment thread content/manuals/ai/sandboxes/governance/audit.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/audit.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/audit.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/audit.md Outdated
- Remove bold from concept names in the record-categories list
- Replace semicolons with separate sentences
- Correct the Linux and Windows default audit paths to match the
  storagekit platform namespaces (verified against the implementation)
  and generalize the storage-root override description
- Use the correct CrowdStrike brand casing; update the Vale vocabulary
  and existing networking doc to match

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the area/desktop Issue affects a desktop edition of Docker. E.g docker for mac label Jun 2, 2026
dvdksn and others added 3 commits June 3, 2026 08:28
Add the paid-subscription note used across the governance section so the
audit logging page states that the feature requires Docker AI Governance.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
SANDBOXES_STORAGE_ROOT and DOCKER_SANDBOXES_APP_NAME are undocumented
internals and out of scope for the audit logging page. Remove the
override section; it can be documented separately in a follow-up if
needed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ai area/desktop Issue affects a desktop edition of Docker. E.g docker for mac area/tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants