G7.6: fleet canary — probes what a user does, not what is cheap
All checks were successful
check / gate (push) Successful in 19s

Today's outage is the whole design brief: /health returned 200 for the entire
hour that login was dead. A canary watching /health would have stayed green
while nobody in the ecosystem could sign in. So the login probe is here and it
is the one that matters.

Three rules it obeys:
  - never green for something it did not prove (I-8)
  - alert on TRANSITIONS, not every run — a canary people filter is a dead
    canary, which is how the last one sat 37 days dead unnoticed
  - run where the watched thing cannot take it down: Veron 1, never Kit 0

Two independent signals, so losing one still leaves the other: an email via
Resend on state change, and a non-zero exit that turns the CI run red in the
forge itself.

Alerts say what broke in human terms — 'a human can actually sign in' — rather
than only naming an endpoint.

Verified against production: 7/7 green including login at 17.1s; a forced 404
reports DOWN; a 1s threshold reports SLOW at 23.3s.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-12 13:41:37 -04:00
parent 211a48187f
commit 9a7030351b
3 changed files with 318 additions and 0 deletions

View File

@@ -504,3 +504,36 @@ def test_g73_every_job_has_a_timeout():
for half an hour."""
for wf in ROOT.rglob(".gitea/workflows/*.y*ml"):
assert "timeout-minutes:" in wf.read_text(), f"{wf.name}: no job timeout"
# --------------------------------------------------------------------------
# G7.6 — the canary must watch what users do, and must not live on Kit 0
# --------------------------------------------------------------------------
def test_g76_canary_probes_login_not_just_health():
"""/health returned 200 for the entire 2026-08-12 outage while login was
dead. A canary that only watches health is decorative."""
src = (ROOT / "scripts" / "canary.py").read_text()
assert "identity.login" in src
assert "/api/v1/auth/login" in src
def test_g76_canary_does_not_run_on_kit_zero():
"""A canary hosted on the box it watches dies with that box, and reports
nothing at the exact moment it matters."""
wf = (ROOT / ".gitea" / "workflows" / "canary.yml").read_text()
assert "runs-on: veron-1" in wf
assert "72.60.118.54" not in wf
def test_g76_canary_alerts_on_transition_not_every_run():
"""A canary that emails every 10 minutes gets filtered, and a filtered
canary is a dead canary."""
src = (ROOT / "scripts" / "canary.py").read_text()
assert "newly_bad" in src and "recovered" in src
def test_g76_canary_has_two_independent_signals():
"""Email AND a red CI run. The last fleet canary died silently because it
had one signal and nothing watched the watcher."""
src = (ROOT / "scripts" / "canary.py").read_text()
assert "return 1 if any" in src, "canary must exit non-zero so CI goes red"