Skip to content

Logs and audit trail

Every check and deploy creates logs/<stamp>_<command>/:

File Content
run.log everything printed on screen
<server>.log one server, timestamped
summary.json per server: status, error, changed files, each phase with duration; plus the certificate deployed
sslsync logs          # history with ok/failed counts
sslsync last-log      # newest run.log
jq '.servers[] | {server, status, error}' logs/<run>/summary.json

On the servers: - <file>.bak-<stamp>: the previous file, kept unless _BACKUP=false - /root/ssl-secret-backup/<stamp>/: Kubernetes secrets before the update

<stamp> is the same in the log folder name and in every backup of that run.

Logs never contain passwords or private keys. They do contain host names and paths, so they are git-ignored.