Reference
prov.egress
domain: prov
An AUDIT record of a brokered external call โ which run/component, in which tenant, reached (or was DENIED) which host, injecting which NAMED secret. Gives a tenant a verifiable trail of external calls + secret use made in its name. The raw key and the URL query string are NEVER recorded (only host + path).
| Field | Type | Required | Description |
|---|---|---|---|
schema | โ | โ | |
id | string | โ | |
run | string | the run token / run id that made the call | |
tenant | string | ||
component | string | โ | the component id that egressed |
host | string | the external host reached | |
path | string | URL path only โ NEVER the query string (the key lives there) | |
secret | string | the NAME of the secret injected (never the value) | |
outcome | string | โ | |
reason | string | why denied (e.g. egress-not-declared, secret-not-set) | |
upstream_status | string | the external response status, if reached | |
at | string | โ |