mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Premium badging and gating consistency as a OSS user, I want to be upsold to premium, and tastefully Summary Standardize all base-Premium full-page gates and the two named inline notices. Admins see an in-app “Learn about Premium” path; non-admins are told to contact their deployment administrator. * DEVEX-732 * updates for premium docs pages for consistency * updates for premium badging and paywall components * updates implemented uses of premium badge and premiumpaywall | Before | After | | --- | ----------- | | <img width="1271" height="564" alt="Screenshot 2026-08-04 at 3 02 32 PM" src="https://github.com/user-attachments/assets/027d4bca-3e34-40b2-ad69-28dbaa4a004b" /> | <img width="1273" height="600" alt="Screenshot 2026-08-04 at 3 26 37 PM" src="https://github.com/user-attachments/assets/321083c0-7a4c-4c7e-a19c-059807018d3b" /> | | Before | After | | --- | ----------- | | <img width="1084" height="672" alt="image" src="https://github.com/user-attachments/assets/741e6bd9-93b0-4ae0-97df-027e8aba5716" /> | <img width="1289" height="622" alt="Screenshot 2026-08-04 at 3 20 07 PM" src="https://github.com/user-attachments/assets/b3a8c169-ca6e-439b-8752-9209131fc097" /> | | Before | After | | --- | ----------- | | <img width="1091" height="865" alt="image (1)" src="https://github.com/user-attachments/assets/f7cd92dd-a975-4db0-bc2a-af092ba783ce" /> | <img width="1268" height="680" alt="Screenshot 2026-08-04 at 3 37 06 PM" src="https://github.com/user-attachments/assets/8af8081a-0ec9-4fd3-921c-470127f2328b" /> |
151 lines
6.4 KiB
Markdown
151 lines
6.4 KiB
Markdown
# Connection Logs (Premium)
|
|
|
|
> [!NOTE]
|
|
> Connection logs require a
|
|
> [Premium license](https://coder.com/pricing#compare-plans).
|
|
> For more details, [contact your account team](https://coder.com/contact).
|
|
|
|
The **Connection Log** page in the dashboard allows Auditors to monitor workspace agent connections.
|
|
|
|
## Workspace App Connections
|
|
|
|
The connection log contains a complete record of all workspace app connections.
|
|
These originate from within the Coder deployment, and thus the connection log
|
|
is a source of truth for these events.
|
|
|
|
## Browser Port Forwarding
|
|
|
|
The connection log contains a complete record of all workspace port forwarding
|
|
performed via the dashboard.
|
|
|
|
## SSH and IDE Sessions
|
|
|
|
The connection log aims to capture a record of all workspace SSH and IDE sessions.
|
|
These events are reported by workspace agents, and their receipt by the server
|
|
is not guaranteed.
|
|
|
|
Agent-reported events do not identify the Coder user who connected. To
|
|
attribute SSH and IDE activity to a user, correlate them with tunnel
|
|
events for the same workspace and agent.
|
|
|
|
## Tunnel Connections
|
|
|
|
The connection log records a tunnel event each time a client
|
|
establishes a tunnel to a workspace agent, carrying the identity, IP
|
|
address, and user agent of the authenticated user who opened it. Tunnels
|
|
carry SSH and IDE traffic, so these events provide the user attribution
|
|
that agent-reported events lack.
|
|
|
|
Keep the following in mind when interpreting tunnel events:
|
|
|
|
- A tunnel event records that a tunnel was established, not what it was
|
|
used for. Any client that dials a workspace agent produces one,
|
|
including `coder ssh`, `coder port-forward`, `coder ping`,
|
|
`coder speedtest`, and IDE extensions. One tunnel may carry many
|
|
sessions, or none.
|
|
- Tunnel events are deduplicated per user, workspace agent, IP address,
|
|
and client. Clients automatically re-establish tunnels after network
|
|
interruptions or server restarts; reconnections do not produce new
|
|
events while a session is active. A new event is recorded when a
|
|
session has been idle for one hour, or when the user connects from a
|
|
new IP address or client.
|
|
- Connections made through Coder Desktop (Coder Connect) do not
|
|
currently produce tunnel events.
|
|
- Like workspace app connections, tunnel events are point-in-time
|
|
records: they have no close time and are excluded from `status:`
|
|
filter results.
|
|
|
|
## How to Filter Connection Logs
|
|
|
|
You can filter connection logs by the following parameters:
|
|
|
|
- `organization` - The name or ID of the organization of the workspace being
|
|
connected to.
|
|
- `workspace_owner` - The username of the owner of the workspace being connected
|
|
to.
|
|
- `type` - The type of the connection, such as SSH, VS Code, or workspace app.
|
|
For more connection types, refer to the
|
|
[CoderSDK documentation](https://pkg.go.dev/github.com/coder/coder/v2/codersdk#ConnectionType).
|
|
- `username`: The name of the user who initiated the connection.
|
|
Results will not include agent-reported SSH or IDE sessions.
|
|
- `user_email`: The email of the user who initiated the connection.
|
|
Results will not include agent-reported SSH or IDE sessions.
|
|
- `connected_after`: The time after which the connection started.
|
|
Uses the RFC3339Nano format.
|
|
- `connected_before`: The time before which the connection started.
|
|
Uses the RFC3339Nano format.
|
|
- `workspace_id`: The ID of the workspace being connected to.
|
|
- `connection_id`: The ID of the connection.
|
|
- `status`: The status of the connection, either `ongoing` or `completed`.
|
|
Some events are neither ongoing nor completed, such as the opening of a
|
|
workspace app.
|
|
|
|
## Capturing/Exporting Connection Logs
|
|
|
|
In addition to the Coder dashboard, there are multiple ways to consume or query
|
|
connection events.
|
|
|
|
### REST API
|
|
|
|
You can retrieve connection logs via the Coder API.
|
|
Visit the
|
|
[`get-connection-logs` endpoint documentation](../../reference/api/enterprise.md#get-connection-logs)
|
|
for details.
|
|
|
|
### Service Logs
|
|
|
|
Connection events are also dispatched as service logs and can be captured and
|
|
categorized using any log management tool such as [Splunk](https://splunk.com).
|
|
|
|
Example of a [JSON formatted](../../reference/cli/server.md#--log-json)
|
|
connection log entry, when an SSH connection is made:
|
|
|
|
```json
|
|
{
|
|
"ts": "2025-07-03T05:09:41.929840747Z",
|
|
"level": "INFO",
|
|
"msg": "connection_log",
|
|
"caller": "/home/coder/coder/enterprise/audit/backends/slog.go:38",
|
|
"func": "github.com/coder/coder/v2/enterprise/audit/backends.(*SlogExporter).ExportStruct",
|
|
"logger_names": ["coderd"],
|
|
"fields": {
|
|
"request_id": "916ad077-e120-4861-8640-f449d56d2bae",
|
|
"ID": "ca5dfc63-dc43-463a-bb3e-38526866fd4b",
|
|
"OrganizationID": "1a2bb67e-0117-4168-92e0-58138989a7f5",
|
|
"WorkspaceOwnerID": "fe8f4bab-3128-41f1-8fec-1cc0755affe5",
|
|
"WorkspaceID": "05567e23-31e2-4c00-bd05-4d499d437347",
|
|
"WorkspaceName": "dev",
|
|
"AgentName": "main",
|
|
"Type": "ssh",
|
|
"Code": null,
|
|
"Ip": "fd7a:115c:a1e0:4b86:9046:80e:6c70:33b7",
|
|
"UserAgent": "",
|
|
"UserID": null,
|
|
"SlugOrPort": "",
|
|
"ConnectionID": "7a6fafdc-e3d0-43cb-a1b7-1f19802d7908",
|
|
"DisconnectReason": "",
|
|
"Time": "2025-07-10T10:14:38.942776145Z",
|
|
"ConnectionStatus": "connected"
|
|
}
|
|
}
|
|
```
|
|
|
|
Example of a [human readable](../../reference/cli/server.md#--log-human)
|
|
connection log entry, when `code-server` is opened:
|
|
|
|
```console
|
|
[API] 2025-07-03 06:57:16.157 [info] coderd: connection_log request_id=de3f6004-6cc1-4880-a296-d7c6ca1abf75 ID=f0249951-d454-48f6-9504-e73340fa07b7 Time="2025-07-03T06:57:16.144719Z" OrganizationID=0665a54f-0b77-4a58-94aa-59646fa38a74 WorkspaceOwnerID=6dea5f8c-ecec-4cf0-a5bd-bc2c63af2efa WorkspaceID=3c0b37c8-e58c-4980-b9a1-2732410480a5 WorkspaceName=dev AgentName=main Type=workspace_app Code=200 Ip=127.0.0.1 UserAgent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36" UserID=6dea5f8c-ecec-4cf0-a5bd-bc2c63af2efa SlugOrPort=code-server ConnectionID=<nil> DisconnectReason="" ConnectionStatus=connected
|
|
```
|
|
|
|
## Data Retention
|
|
|
|
Coder supports configurable retention policies that automatically purge old
|
|
Connection Logs. To enable automated purging, configure the
|
|
`--connection-logs-retention` flag or `CODER_CONNECTION_LOGS_RETENTION`
|
|
environment variable. For comprehensive configuration options, see
|
|
[Data Retention](../setup/data-retention.md).
|
|
|
|
## How to Enable Connection Logs
|
|
|
|
This feature is only available with a [Premium license](../licensing/index.md).
|