Orkestia
Blog
Vault

Audit log and keys

See every Vault access and refusal, and rotate your organization's encryption key

Audit log

Every action in the Vault is recorded: writes, reveals, API calls, policy changes, key rotations and every refusal. Each entry shows what happened, on which secret, by whom, when, and whether it was allowed or refused and why. Secret values never appear in the log.

In the Console: Vault → Audit log (owners and admins). From the API: vault.audit.list, newest first.

InputMeaning
pathOnly entries for this secret
outcomeallowed, denied or error
sinceOnly entries from this time (ISO-8601)
limitDefault 100, at most 500

Encryption

Every value is encrypted with a key unique to your organization. That key is itself protected by a hardware-backed master key. Values are never stored in plain text.

Rotate the key

Rotating creates a new key for your organization. New values use it. Existing versions keep working. The rotation is recorded in the audit log.

In the Console: Vault → Encryption key → Rotate data key (owners and admins). From the API: vault.key.rotate.

To move an existing secret onto the new key, write a new version of it.