For organisations requiring deeper forensic observability, BuildPiper provides an advanced audit logging mechanism that captures backend API activity at the request level — purpose-built for security investigations, root-cause analysis, and compliance evidence collection.
For organisations requiring deeper forensic observability, BuildPiper provides an advanced Deep-Drive Forensic Audit Logging mechanism that goes beyond UI events to capture the underlying API interaction layer.
Important: This feature is not enabled by default and must be explicitly enabled from the BuildPiper UI before logs start accumulating.
Once enabled, the forensic audit mechanism captures backend API activity at the HTTP method level — providing request-level visibility into actions being performed against the platform backend.
POST All POST Requests
Every create/update API call made against the BuildPiper backend, with payload, user, and path.
DELETE All DELETE Requests
Every destructive API call — captured with full attribution for forensic reconstruction.
BP Snapshot: Enabling Deep-Drive Forensic Audit Logging from the BuildPiper UI.
Unlike the standard UI audit logs, which focus primarily on operational events and user actions, this mechanism captures the underlying API interaction layer — making it suitable for forensic and security workflows.
The forensic audit logs are stored on the BuildPiper host at the following file system path:
Log File Path
/home/buildpiper/.log/buildpiper/audit_trail
Server-Level Access Required: These logs are not accessible via the BuildPiper UI. Reviewing or analysing them requires direct server-level access (SSH / file system access) to the BuildPiper host.
BP Snapshot: Forensic audit log directory on the BuildPiper host.
The Forensic Audit Trail is a powerful diagnostic tool for identifying security threats and reconstructing destructive events. The two most common use cases are illustrated below.
CASE 01 Detecting Unauthorised Access Attempts
If you suspect a malicious actor is attempting to compromise BuildPiper or executing a brute-force attack against specific user accounts, these logs provide the necessary telemetry for your analysis. The following log entry illustrates an unauthorised access attempt:
What to look for: A high frequency of User: Anonymous entries against /api/v1/user/login/ with UNAUTHORIZED messages — especially from the same source — is a strong brute-force signal.
BP Snapshot: Unauthorised access attempt log sample.
CASE 02 Root-Cause Analysis for Unauthorised Resource Deletion
Another critical use case is root-cause analysis following unauthorised or accidental resource deletion. If a critical BuildPiper resource like a Kubernetes cluster suddenly disappears from your environment, you can use these logs to pinpoint exactly who initiated the action and when. The audit trail explicitly captures destructive operations.
[2026-05-04 16:14:01,210][136328560115072][audit_trail][INFO]: User: sunny.kumar@mygurukulam.co, Path: /api/v1/project/72/job/template/1374/, Method: DELETE, Payload: {'entity_id': 1374, 'name': 'project_job_templates', 'label': 'job template'}, Message: job_template test with ID 1374 was deleted Successfully.
[2026-05-04 16:16:29,970][136328545178528][audit_trail][INFO]: User: sunny.kumar@mygurukulam.co, Path: /api/v1/job/template/1376/, Method: DELETE, Payload: {'entity_id': '1376', 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template test-V3 with ID 1376 was deleted Successfully.
[2026-05-11 11:08:55,652][136327890554528][audit_trail][INFO]: User: opstree@opstree.com, Path: /api/v1/job/template/1266/, Method: DELETE, Payload: {'entity_id': 1266, 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template Global-GOLANG-EXTENSIVE-CI with ID 1266 was deleted Successfully.
[2026-05-11 15:51:40,616][136327917204352][audit_trail][INFO]: User: aayush.verma@opstree.com, Path: /api/v1/job/template/1399/, Method: DELETE, Payload: {'entity_id': 1399, 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template Global-Global-olly-pr-update-ci with ID 1399 was deleted Successfully.
⚠ Audit Log Entry · ERROR Level
[2026-05-14 15:12:24,166][136328556460320][audit_trail][ERROR]: User: opstree@opstree.com, Path: /api/v1/job/template/1402/, Method: DELETE, Payload: {'entity_id': 1402, 'name': 'project_job_templates', 'label': 'job template'}, Message: global job template Global-Testing with ID 1402 was deleted unsuccessfully.
Note the ERROR level entry: The forensic log preserves both successful and failed destructive attempts. Failed attempts ([ERROR]) are equally important — they may indicate unauthorised users without sufficient permissions probing the system.
BP Snapshot: Job template deletion audit log sample.