Skip to content

Sessions and audit#

A runtime is a shell on your GPUs, so you need to know who used it. Hesperus records every SSH connection and every change of a runtime's state, and makes each an event of the workspace that you can read in the console or stream to your SIEM. It never records what was typed or shown.

SSH sessions#

Each SSH connection to a runtime — a terminal, scp, rsync, an editor's Remote-SSH — is a session:

Field What
user Who (user:<id>): the person whose certificate opened it. Members sharing one login are told apart.
client From what, as the client said: astra for astra ssh
started_at, ended_at When it opened and closed (no ended_at: still open)
duration_seconds How long, once ended
bytes_in, bytes_out Bytes from the person and to them
port, task The SSH port (2222) and the runtime's worker it reached

The last 50 sessions of each runtime are kept. The environment's page lists them under SSH sessions — Who, From, Started, Length (4 min, 1 h 05 min, 12 min, still open) — and GET /notebook-runtimes/{name}/ssh-sessions returns them, newest first.

Inside the container, the SSH server logs each login with its certificate's key id, hesperus:<runtime>:<user>, to the runtime's run log.

Events#

Event (notebook_runtime) When Reason, for example
StateChanged Every change of state: started, on a machine, ready, stopping, stopped, failed Started by user:…, Ready on gpu-01 (1 × NVIDIA H100 80GB HBM3), Stopped after 60 minutes idle
SshSessionStarted (state Open) A session opened SSH session started by user:… from astra
SshSessionEnded (state Closed) A session closed SSH session of user:… from astra ended after 2m05s
Deleted The runtime was deleted

A runtime's first event also carries what it was made with: its kind, whether SSH is on, its image, GPUs, other drives, notebook, owner, who made it for them, its members and its idle timeout. Read events under the workspace's Events, or stream them as OCSF to your SIEM (Events, audit and event streams).

What is not recorded#

  • What was typed or shown in a terminal, an IDE or an app. The recording says who was connected, never what they did.
  • Each request to an IDE or an app. Opening them is checked every time, but only SSH connections are sessions. An open IDE window keeps the runtime from its idle stop.
  • Notebook cells. A notebook's content is the .ipynb file on its drive; Astralyx keeps who opened it last and when.