AAPM Agent Logs
This document explains how the Kron PAM AAPM Agent processes password requests, manages its local cache, performs regular and intensive status checks, and reacts to password rotation events.
The objective is to help administrators interpret AAPM Agent logs precisely and understand the internal state transitions during password retrieval and cache lifecycle events.
Verifying Kron PAM AAPM Agent Installation
During the initial installation of the Kron PAM AAPM Agent, check the logs to confirm the following:
- Agent Registration: The logs should indicate that the AAPM Agent has successfully registered with Kron PAM. (doRegisterCall started... and doRegisterCall result: OK)
- gRPC over SSL (if enabled): If the feature is enabled, the logs will show that gRPC over SSL has been activated for the AAPM Agent. (RPC Server started with SSL)
- Heartbeat Confirmation: After a successful installation and startup, the logs will display a heartbeat (ping) sent to the Kron PAM servers, confirming active communication. (Ping successful...)
2026-02-27 12:52:31,869 INFO c.k.a.c.RegistrationController [main] Agent registration required
2026-02-27 12:52:31,894 INFO c.k.a.c.RegistrationController [main] doRegisterCall started...
2026-02-27 12:53:30,518 INFO c.k.a.c.RegistrationController [main] doRegisterCall result: OK
2026-02-27 12:53:30,731 INFO c.k.a.c.ClientCredentialsConfig [main] Security credentials and paths successfully encrypted.
2026-02-27 12:53:33,202 INFO c.k.a.c.RegistrationController [main] createJwtRefreshSchedule created for 3595 seconds
2026-02-27 12:53:33,207 INFO c.k.a.c.SystemController [main] Agent initialization...
2026-02-27 12:53:33,207 INFO c.k.a.c.SystemController [main] Agent registration policy OS = linux , service mode = false
2026-02-27 12:53:33,216 INFO j.u.prefs [main] Created user preferences directory.
2026-02-27 12:53:33,217 WARN j.u.prefs [main] Prefs file removed in background /opt/KronAAPM/agent/.java/.userPrefs/.java/.userPrefs/prefs.xml
2026-02-27 12:53:33,963 INFO o.l.s.g.GRpcServerRunner [main] Starting gRPC Server ...
2026-02-27 12:53:33,980 INFO o.l.s.g.GRpcServerRunner [main] 'org.lognet.springboot.grpc.health.DefaultHealthStatusService$$SpringCGLIB$$0' service has be
en registered.
2026-02-27 12:53:33,981 INFO o.l.s.g.GRpcServerRunner [main] 'com.kron.aapm.controller.ToolServiceController' service has been registered.
2026-02-27 12:53:33,982 INFO o.l.s.g.GRpcServerRunner [main] 'com.kron.aapm.controller.AccessServiceController' service has been registered.
2026-02-27 12:53:34,345 INFO c.k.a.c.GrpcSecurityConfig [main] >>> gRPC Server started with SSL (PEM MODE)
2026-02-27 12:53:34,454 INFO o.l.s.g.GRpcServerRunner [main] gRPC Server started, listening on port 6301.
2026-02-27 12:53:34,492 INFO c.k.a.CoreApplication [main] Started CoreApplication in 67.174 seconds (process running for 69.435)
2026-02-27 12:54:12,550 INFO c.k.a.c.HeartbeatController [scheduling-1] Ping successful...
2026-02-27 12:55:19,590 INFO c.k.a.c.HeartbeatController [scheduling-1] Ping successful...Initial Password Retrieval from Kron PAM
The lifecycle begins when the SDK invokes the agent’s getPassword method. At this stage, the agent evaluates whether a valid cache entry exists for the requested vault account.
This log indicates that the AAPM Agent received a password request from the SDK and successfully fetched the credential from the Kron PAM server.
2026-02-19 20:48:07,919 INFO c.k.a.s.AgentStatus
[FETCH_SUCCESS] Password successfully retrieved from PAM.
PAM URL: 10.20.30.40
Vault Account: dynamicTestaccount
Vault Account Path: /TestVaultPathAt this point:
- The password was not served from cache (or cache was empty/expired).
- A live fetch operation occurred.
- The agent will now populate its local cache with the retrieved credential.
Cache Entry Creation and Expiration Registration
Immediately after successful retrieval, the agent creates an internal cache entry. The expiration timestamp indicates the calculated expiration time for the cached password. This value is derived from the account’s nextChange time returned by Kron PAM.
2026-02-19 20:48:07,919 INFO c.k.a.c.ExpiringSet
Key = /TestVaultPath|dynamicTestaccount| expire at 2026-02-19 21:18:07This expiration is not arbitrary. It aligns with the next scheduled password change in Kron PAM.
Cache Registration in ExpiringCacheManager
This confirms that the password is now stored in memory and managed by the cache lifecycle component.
ExpiringCacheManager
/TestVaultPath|dynamicTestaccount| Cache add to expiringSetStatus Check Task Scheduling
After caching, the agent schedules a REGULAR status check task. This is proactive validation. The agent does not wait passively for expiration.
StatusCheckTaskManager
[REGULAR] Task Scheduled For Key: /TestVaultPath|dynamicTestaccount|The REGULAR mode periodically verifies:
- Whether the password has been rotated in Kron PAM
- Whether the cached password is still valid
- Whether nextChange time has been modified
Regular Status Check (No Rotation Detected)
The agent compares lastChange and nextChange timestamps retrieved from Kron PAM. Action Required confirms that the cache remains synchronized with the vault.
2026-02-19 20:48:24,148 INFO c.k.a.c.AccessServiceController [scheduling-1] [REGULAR] Time Status [/TestVaultPath|dynamicTestaccount|] checking...
2026-02-19 20:48:24,190 INFO c.k.a.c.AccessServiceController [scheduling-1]
No Action Required for /TestVaultPath|dynamicTestaccount| [lastChange: 2026-02-19 20:43:35] [nextChange: 2026-02-19 21:18:09]The agent determines:
- Cached password matches Kron PAM state
- No new rotation has occurred
- Cache remains valid
Intensive Mode Checking
This mode reduces the validation interval compared to REGULAR mode.
INTENSIVE mode is triggered when:
- Password rotation time approaches
- System transitions near expiration window
2026-02-19 20:48:56,795 INFO c.k.a.c.AccessServiceController [scheduling-1]
[INTENSIVE] Time Status [/TestVaultPath|dynamicTestaccount|] checking...Password Rotation Detected – Cache Refresh
This log indicates that:
- Kron PAM rotated the password
- statusTime reflects updated state from PAM
- lastChange no longer matches cached metadata
2026-02-19 20:48:54,359 INFO c.k.a.c.AccessServiceController [scheduling-1] [REGULAR] Time Status [/PAM_Agent_Response|dynamicuserwithdevice|] checking...
2026-02-19 20:48:56,795 INFO c.k.a.c.AccessServiceController [scheduling-1] Cache should be updated! [lastChange: 2026-02-19 20:43:35] [statusTime: 2026-02-19 20:48:44]
2026-02-19 20:48:56,795 INFO c.k.a.s.AgentStatus [scheduling-1] [AGENT_CACHE_EXPIRED] Agent cache expired. Cache will be refreshed. PAM URL: 10.20.30.40 Vault Account: dynamicTestaccount Vault Account Path: /TestVaultPath