The Kubernetes audit logs are a single source of truth for everything that happened in the cluster: all of the calls made to the API server are recorded along with additional metadata such as username, timestamps, and source IPs.


Audit logs answer questions about performance, security, and compliance, such as What is overloading my control plane? Which sequence of events led to slow performance or a security event? Who made this call? From where was this call made? These are difficult questions to answer — especially in large production clusters.


