Verifiable SSH session recording
Bifröst can record terminal output from SSH shell and command sessions and sign the result for later verification. This example adds an audit journal and recording to the local-account host configuration.
Add auditlog at the top level of /etc/engity/bifroest/configuration.yaml, alongside flows:
1 2 3 4 5 6 7 8 9 10 11 12 13 | |
The existing local flow uses default automatically. Restart the Bifröst service, then run a command through it:
1 | |
After the command ends, look for <recording-uuid>.bcast under /var/lib/engity/bifroest/recordings/sealed/. On the Bifröst host, use that UUID to verify the signed recording and the audit journal:
1 2 | |
To export it as an asciicast v3 file outside the managed repository:
1 2 3 4 | |
Protect the evidence and export: without a configured encryption recipient, signatures protect integrity, not confidentiality. The exported Cast can contain printed secrets and is never redacted. Bifröst does not capture raw keyboard input or SFTP/forwarding payloads; portForwardingAllowed: false prevents forwarding in this example. A local recording failure stops the affected task by default. Decide on storage, retention and optional encryption before production use; see the audit and recording references.