8.1 Dependencies

eventd needs four subsystems before it can do anything.

SubsystemFor
KMESEvent ingestion. Available as soon as PKM is loaded.
LCS and loregdConfiguration. eventd reads every setting from the registry.
KACSAccess control — the AccessCheck API for query authorization, and kacs_open_peer_token for caller identification.
peinitThe boot ID, and lifecycle management.

eventd is a peinit-managed service, started after loregd is available — it cannot read a single configuration value without the registry, and it has no compiled-in defaults for the six paths it needs (§A).

8.1.1 The dependency that is not one #

KACS is needed to serve queries and not to ingest. The drain, write and retention paths never call it. That asymmetry is what lets eventd keep ingesting through a KACS outage while refusing every query (§9.3), and it is the right way round: losing the ability to read the audit store is recoverable, losing the events is not.

8.1.2 Ordering in the boot #

eventd is one of the platform daemons and is Critical: peinit reboots the system rather than continuing without it. It comes up after loregd and authd, and it stops before them on the way down — it is among the last services shut down, because everything else's shutdown is worth recording.

The window before eventd exists is real and peinit covers it by buffering service output until the log socket appears. Events emitted during that window are not lost either: they sit in the KMES ring buffers, and eventd's first drain after attaching reads them from tail_pos (§2.2).

Edit this page