feat(ci): Tier-0 textfile-metric safety guard (#104) #111
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!111
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/104-textfile-smoke"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Second increment of the pre-prod validation epic (bitborg-docs#37) — closes the #96 failure class in CI.
The bug it catches
token-audit.promwas created bymktemp(mode 0600) thenmv'd into the textfile dir, so node_exporter (non-root inside the rootless container) couldn't open it —node_textfile_scrape_error=1, metrics silently never reached VictoriaMetrics, despite a green apply and a status-0 run.What it does
scripts/smoke-textfile.py(pure stdlib, runs anywhere): for each script that publishes a.prominto the node_exporter textfile dir, fail if the temp itmv's to the.promcomes frommktempwith no world-readablechmod. It traces the actual mv source, so scripts that publish via>(0644 via umask) and usemktemponly for unrelated work files are not flagged.Why static, not behavioural
The 9 metric scripts call live
curl/jq/GNU-date/podman/skopeo/openstackand rely on GNUdate -d— a faithful stubbed run is more fragile than the deterministic file-mode bug it would catch (and can't be self-validated on the macOS control node). The faithful behavioural check — assertnode_textfile_scrape_error==0after a real converge — is Tier-1 / the post-apply health gate (#105 / #107), which is exactly what I ran by hand during the #96 incident.Validated both directions
>; I verified each and tightened the check to trace the realmvsource.)chmod 0644makes the guard FAIL with a non-zero exit.Together with #110 (container-start smoke), Tier-0 now covers both prod incident classes this week. Remaining #104 note: the full multi-service converge stays Tier-1 (#105).
Refs #104.
0b37bc6f7fd0097d2d39Superseded by #112 — no action needed. #112 was stacked on this branch, so its squash-merge carried this commit's content into
mainalong with it. Verified:git diff main feat/104-textfile-smokeis empty — the textfile smoke (scripts/smoke-textfile.py), thesmoke:textfilepnpm script, and the CI step are all present inmain(via #112 /d0097d2). Closing without merging so it doesn't re-apply an empty change.Ändringsförfrågan stängd