fix(token-audit): make token-audit.prom world-readable + group metric families (#75) #108
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!108
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/token-audit-prom-readable"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Hotfix for #96 (already applied to prod; landing on
mainso it isn't re-broken on the next apply).Symptom
The token-audit ran clean (
last_run_status=0) but its metrics never reached VictoriaMetrics —node_textfile_scrape_error{host=gitborg-prod}=1, soForgejoTokenRotationDuewas silently blind.Root cause
The script wrote the file with
mktemp(mode 0600) thenmv'd it into place, sotoken-audit.promwas 0600 while every other textfile metric is 0644. node_exporter reads the textfile dir as a non-root user inside the rootless container and couldn't open the 0600 file (that's exactly whatnode_textfile_scrape_errorreports — 'error opening or reading a file'). The backup/reconciler scripts avoid this by using plain>redirection (umask 0644).Fix
chmod 0644the temp file beforemv(the actual fix).Verified on prod (after apply)
node_textfile_scrape_error=0.gitborg_forgejo_token_count/_created_timestamp_secondspresent in VM for all 6 accounts;last_run_status=0.ForgejoTokenRotationDuecorrectly quiet (newest token per account ~10–12 days, under the 80-day threshold).Note
Both this and the caddy #102 bug are exactly the failure class a Tier-0/Tier-1 smoke test (bitborg-docs#37 → bitborg-infra#104) would catch — a check asserting
node_textfile_scrape_error==0and containers actually up. Reinforces the staging epic.