Sessions and audit#
A runtime is a shell on your GPUs, so you need to know who used it. Hesperus records every SSH connection and every change of a runtime's state, and makes each an event of the workspace that you can read in the console or stream to your SIEM. It never records what was typed or shown.
SSH sessions#
Each SSH connection to a runtime — a terminal, scp, rsync, an editor's
Remote-SSH — is a session:
| Field | What |
|---|---|
user |
Who (user:<id>): the person whose certificate opened it. Members sharing one login are told apart. |
client |
From what, as the client said: astra for astra ssh |
started_at, ended_at |
When it opened and closed (no ended_at: still open) |
duration_seconds |
How long, once ended |
bytes_in, bytes_out |
Bytes from the person and to them |
port, task |
The SSH port (2222) and the runtime's worker it reached |
The last 50 sessions of each runtime are kept. The environment's page
lists them under SSH sessions — Who, From, Started,
Length (4 min, 1 h 05 min, 12 min, still open) — and
GET /notebook-runtimes/{name}/ssh-sessions returns them, newest first.
Inside the container, the SSH server logs each login with its
certificate's key id, hesperus:<runtime>:<user>, to the runtime's run log.
Events#
Event (notebook_runtime) |
When | Reason, for example |
|---|---|---|
StateChanged |
Every change of state: started, on a machine, ready, stopping, stopped, failed | Started by user:…, Ready on gpu-01 (1 × NVIDIA H100 80GB HBM3), Stopped after 60 minutes idle |
SshSessionStarted (state Open) |
A session opened | SSH session started by user:… from astra |
SshSessionEnded (state Closed) |
A session closed | SSH session of user:… from astra ended after 2m05s |
Deleted |
The runtime was deleted |
A runtime's first event also carries what it was made with: its kind, whether SSH is on, its image, GPUs, other drives, notebook, owner, who made it for them, its members and its idle timeout. Read events under the workspace's Events, or stream them as OCSF to your SIEM (Events, audit and event streams).
What is not recorded#
- What was typed or shown in a terminal, an IDE or an app. The recording says who was connected, never what they did.
- Each request to an IDE or an app. Opening them is checked every time, but only SSH connections are sessions. An open IDE window keeps the runtime from its idle stop.
- Notebook cells. A notebook's content is the
.ipynbfile on its drive; Astralyx keeps who opened it last and when.