Swisscom应用云:能否获取UAA服务器生成的事件以实现审计追踪?
Absolutely! In the Swisscom Application Cloud—built on Cloud Foundry—you can capture events generated by the User Account and Authentication (UAA) server to build the audit trail you need, serving as a direct alternative to AWS CloudTrail for IAM-related operations. Here's how it works:
1. UAA's Built-In Audit Capabilities
Cloud Foundry's UAA natively logs all authentication and authorization-related actions, and this functionality is fully available in the Swisscom Application Cloud. These logs cover every operator action across API, CLI, and the web portal, including:
- User creation, deletion, and attribute updates
- Role and permission changes (e.g., assigning
adminaccess to an Org/Space) - Login/logout events and failed authentication attempts
- OAuth2 token issuance and revocation
2. Accessing UAA Audit Logs
You have two primary ways to retrieve these logs in the Swisscom environment:
- Platform-Managed Log Routing: Swisscom lets you route UAA audit logs to centralized logging systems (either their native log service or external tools you integrate). You can configure this via the cloud portal or CF CLI commands to ensure logs are sent to a system where you can store, search, and analyze them long-term.
- UAA Audit API: With the appropriate permissions (like the
uaa.adminscope), you can query UAA's dedicated audit API endpoints to fetch historical events or set up real-time event streaming. This gives you direct programmatic access to audit data for custom workflows.
3. Granular Scope Configuration (Like VPC/Region in CloudTrail)
Similar to enabling CloudTrail for specific AWS regions/VPCs, you can narrow down the audit log scope in Cloud Foundry (and thus Swisscom Application Cloud):
- Filter logs by Org or Space to focus on actions within specific environments
- Target specific UAA tenants or user groups if your setup requires it
- Use log routing rules to exclude non-critical events and focus only on high-impact operator actions
4. Key Considerations for Your Audit Trail
- Permission Lockdown: Ensure only authorized audit personnel have access to UAA logs—restrict API and portal access to audit-related roles to prevent sensitive data exposure.
- Log Retention: Align your log retention policy with compliance requirements. You can either rely on Swisscom's default retention or export logs to your own storage system for long-term archiving.
- Event Detail: UAA audit logs include critical metadata like timestamp, operator ID, source IP address, action type, and target resource—everything you need to trace and verify operator actions.
内容的提问来源于stack exchange,提问作者Lukas Futera

