Skip to main content

lium audit

Since lium 0.0.37

lium audit and Lium.events() shipped in lium 0.0.37. The API serves GET /users/me/events to API keys, so the command works with the key lium init saved.

Show who did what to the account's pods, and when.

lium audit [OPTIONS] # since 0.0.37

Every rent, reboot, edit and delete names the session or API key that requested it; entries the platform wrote by itself (a node reply, a balance stop, a TTL) say platform. The log is the account's event log (GET /users/me/events); there is no dashboard screen for it yet — see Who did what on the account.

Options​

FlagEffect
--pod PODOnly this pod: id, huid, name or index from the last lium ps; a deleted pod's history is reachable by its full id
--since WHENOnly events after this: a duration (24h, 30m, 7d) or an ISO-8601 timestamp (read as UTC unless it carries an offset or Z); anything else exits 2 with the accepted forms
--key API_KEY_IDOnly actions made with this API key id — the full id (lium audit --json shows it as actor.api_key_id); the eight characters the By column prints exit 2 locally
--limit NNewest events to fetch, 1–1000 (default 200); out of range exits 2 locally, before any request
--jsonPrint the events as the API returns them (newest first)

Output​

The table has four columns — When (UTC), Pod, What, By — oldest first, so the log reads top-down.

  • What is a short phrase per event type: rent requested, created, delete requested, reboot failed, API key created, …; lifecycle entries read → <status> (<reason>), with the recorded detail or error appended when there is one.
  • By is key <name> (<first 8 chars of the id>) for an API key, session for the browser, platform when no actor made the request.

Examples​

lium audit # last 200 events, oldest first
lium audit --since 24h # what happened today
lium audit --pod my-pod # one pod's history, also after it was deleted (full id then)
lium audit --key 3f2a... # everything one API key did
lium audit --json | jq '.[] | select(.actor.api_key_name == "ci")'

Exit codes​

CodeWhen
0Events printed (an empty log prints a one-line message)
2--since is neither a duration nor an ISO timestamp; --limit outside 1–1000; --key is not a full key id
3The API refused or failed the call (401, 404, 429, 5xx) — the same code every command uses. On a 401: if the same key works for lium ps, the backend predates API-key access to /users/me/events — the hint says so, and with --json the envelope is {"error": {"code": "auth_error", "message": …}, "ok": false}
5--pod names no listed pod (for a deleted pod give its full id)

See also​