TSLinkTSLink Docs

Inspect Access History

Check retained app access and authority changes, understand missing records, and choose path privacy.

View as Markdown

Use local access history to see retained activity, denied requests and authority changes. Start with the app you operate:

bash
tslink access log --app photos --since 24h
tslink access log --who alice@example.com --decision denied --limit 50 --json
tslink status --json
tslink doctor --json

--who matches login (ASCII case-insensitive), exact node or tag. --since accepts a positive Go duration or RFC3339; --until is RFC3339. Timestamp bounds are inclusive. Newest events come first; default limit 100, maximum 10,000. Summaries cover all retained matches before list truncation. Denials do not advance last allowed access. TCP open/close, lifecycle and MCP intent/completion records are events, not unique visitors or successful-operation counts.

MCP access_log and access_summary use the same filters. Reduced roles need explicit app grants: inventory access alone does not grant history or app access. Filtering precedes aggregation and truncation; mixed-app receipts require every affected app to be permitted.

Interpret identity and receipts

HTTP/file records, TCP open/close, guest decisions and lifecycle/MCP receipts share the query. WhoIs attests login/node/tags where available; tagged nodes have no human login. Public Funnel uses public, not a verified person; guest link IDs and labels do not identify visitors. Unknown private callers retain only a coarse address prefix. Enrichment can be absent and does not imply fresh WhoIs on every proxy request.

Owner mutation receipts are also readable with:

bash
tslink mcp-audit --json

A persisted intent precedes an MCP mutation; its completion has the same ID. A missing completion means unknown outcome. A failed intent write refuses the mutation; a failed completion write says effects may have occurred. Registry changes and lifecycle receipts are separate commits, so a post-commit receipt failure or crash may leave an authority change without its receipt. Inspect actual state before retrying.

Choose path privacy

bash
tslink access path photos prefix
tslink access path sensitive off
tslink access path photos inherit
tslink config set access-log-path-mode prefix
tslink config set access-log-enabled false

Default prefix records the first sanitized path segment. full opts into all sanitized segments and can retain app-specific sensitive names/bearer paths; use off where necessary. Queries/fragments and known TSLink bearer segments are removed. Headers, cookies, bodies, tokens, PINs and full URLs are not event fields. Global off overrides per-app settings; inherit clears the local override. Turning off daemon recording leaves retained history queryable and mutation receipts independently enabled. Per-app changes hot reload; global settings require a daemon restart.

Retention and missing history

Daemon history lives in ~/.config/tslink/access-log/ with a bounded asynchronous queue. Defaults: 30 UTC calendar days including today, 64 MiB data cap, queue 1,024; oldest segments rotate out. A full queue or disk failure drops events while requests continue serving. Crashes can lose queued events; incomplete headers and tailnet-policy packets rejected before dispatch have no HTTP record. Current status/doctor reports drops, missing-history windows and stable errors; daemon liveness alone is not evidence of complete history.

The independent mutation journal mcp-audit.json rotates at 1,024 entries or 1 MiB and has different retention. Access-log health describes the daemon store, not this journal. History stays local and offers no completeness, compliance or external log-shipping guarantee. tslink logs remains useful for stderr daemon diagnostics, a separate surface.

Related: MCP roles · Guest links · Daemon · Configuration.

Sources: TSLink access-log.md

Table of Contents