#16·algo

Rewrite auditd role to use go-audit

Author: dguidoCreated Jul 19, 2016Updated Nov 28, 2025
Labelssecurity_enhancementansible_server_deployneeds_triageenhancement

auditd is the best security feature that no one uses. As an optional feature, we should have Algo configured to log security-critical information and email it out of the VM on a regular basis. The role should use go-audit to get its job done.

There's a lot of sample auditd configuration from CI Security that we copied over to this repo. We should verify that these rules are appropriate:

https://github.com/trailofbits/algo/blob/master/templates/audit.rules.j2 https://github.com/trailofbits/algo/blob/master/templates/auditd.conf.j2 https://github.com/trailofbits/algo/blob/master/templates/CIS.conf.j2 https://github.com/trailofbits/algo/blob/master/security.yml#L44-L52

Here's a short guide for installing and configuring go-audit: https://summitroute.com/blog/2016/12/25/Catching_attackers_with_go-audit_and_a_logging_pipeline/