Skip to main content
Export any combination of check run logs, code review analytics, and user activity on an hourly or daily schedule. Each window contains gzip-compressed NDJSON parts and a manifest. See the export schema. Setup requires a Macroscope workspace admin and permission to create an AWS bucket and IAM role. Macroscope assumes the role with Google-issued OIDC tokens; it does not store AWS access keys.

IAM trust policy

Settings → Workspace → Log Export provides a trust policy containing your workspace audience and Macroscope’s export service account ID. Use those exact values in a role with a Custom trust policy:
The service account is the same for save-time validation and scheduled exports. The workspace audience prevents cross-workspace role assumption. Each role ARN can belong to only one Macroscope workspace. AWS’s built-in Google provider maps accounts.google.com:oaud to the token’s aud claim; accounts.google.com:aud maps to azp. Do not substitute one for the other or register a separate OIDC provider for this integration.

Bucket permissions

Keep the bucket private. Grant the role bucket-location access and write access to your export prefix:
This example uses the macroscope/ prefix. Match the resource to your configured prefix. For SSE-KMS with a customer-managed key, also grant the role kms:GenerateDataKey and kms:Encrypt on that key and allow access in its key policy. Optional s3:DeleteObject access lets Macroscope clean up stale part files after a re-export. Consumers must ignore unlisted parts regardless.

Export settings

Saving validates role assumption and bucket writes before enabling exports. Settings show the next run, last successful window, and latest failure. Pausing preserves configuration. Resuming starts at the next scheduled window. Deleting configuration stops exports without deleting existing S3 objects.

Read exported data

Read only the parts named in the window’s manifest. Prefix-globbing can include stale parts from a previous export. The manifest is written last; empty windows still produce a manifest. Object layout and record fields document all three export types and the code-review aggregate.

Troubleshooting