G7.6: fleet canary — probes what a user does, not what is cheap
All checks were successful
check / gate (push) Successful in 19s
All checks were successful
check / gate (push) Successful in 19s
Today's outage is the whole design brief: /health returned 200 for the entire
hour that login was dead. A canary watching /health would have stayed green
while nobody in the ecosystem could sign in. So the login probe is here and it
is the one that matters.
Three rules it obeys:
- never green for something it did not prove (I-8)
- alert on TRANSITIONS, not every run — a canary people filter is a dead
canary, which is how the last one sat 37 days dead unnoticed
- run where the watched thing cannot take it down: Veron 1, never Kit 0
Two independent signals, so losing one still leaves the other: an email via
Resend on state change, and a non-zero exit that turns the CI run red in the
forge itself.
Alerts say what broke in human terms — 'a human can actually sign in' — rather
than only naming an endpoint.
Verified against production: 7/7 green including login at 17.1s; a forced 404
reports DOWN; a 1s threshold reports SLOW at 23.3s.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -504,3 +504,36 @@ def test_g73_every_job_has_a_timeout():
|
||||
for half an hour."""
|
||||
for wf in ROOT.rglob(".gitea/workflows/*.y*ml"):
|
||||
assert "timeout-minutes:" in wf.read_text(), f"{wf.name}: no job timeout"
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# G7.6 — the canary must watch what users do, and must not live on Kit 0
|
||||
# --------------------------------------------------------------------------
|
||||
def test_g76_canary_probes_login_not_just_health():
|
||||
"""/health returned 200 for the entire 2026-08-12 outage while login was
|
||||
dead. A canary that only watches health is decorative."""
|
||||
src = (ROOT / "scripts" / "canary.py").read_text()
|
||||
assert "identity.login" in src
|
||||
assert "/api/v1/auth/login" in src
|
||||
|
||||
|
||||
def test_g76_canary_does_not_run_on_kit_zero():
|
||||
"""A canary hosted on the box it watches dies with that box, and reports
|
||||
nothing at the exact moment it matters."""
|
||||
wf = (ROOT / ".gitea" / "workflows" / "canary.yml").read_text()
|
||||
assert "runs-on: veron-1" in wf
|
||||
assert "72.60.118.54" not in wf
|
||||
|
||||
|
||||
def test_g76_canary_alerts_on_transition_not_every_run():
|
||||
"""A canary that emails every 10 minutes gets filtered, and a filtered
|
||||
canary is a dead canary."""
|
||||
src = (ROOT / "scripts" / "canary.py").read_text()
|
||||
assert "newly_bad" in src and "recovered" in src
|
||||
|
||||
|
||||
def test_g76_canary_has_two_independent_signals():
|
||||
"""Email AND a red CI run. The last fleet canary died silently because it
|
||||
had one signal and nothing watched the watcher."""
|
||||
src = (ROOT / "scripts" / "canary.py").read_text()
|
||||
assert "return 1 if any" in src, "canary must exit non-zero so CI goes red"
|
||||
|
||||
Reference in New Issue
Block a user