feat(reconciler): alert when Actions (CI) enforcement is silently skipped (#183) #202

Sammanfogat
supernaut sammanfogade 1 incheckning från feat/183-reconciler-actions-degraded-alert in i main 2026-07-21 23:19:46 +00:00
Ägare

Closes #183.

Problem

The reconciler's per-repo Actions (has_actions) toggle needs read:user/read:organization + write:repository. When the admin token lacks those, set_repo_actions logs a WARN and returns — the run still succeeds (status 0) while CI tier gating (the grant and the default-deny bypass-prevention, #37/#125 M4) quietly stops being enforced. This was invisible: no metric, no alert, just a WARN nobody reads.

Making it fatal is the wrong fix — it would couple the Actions toggle's failure to the critical quota/org enforcement in the same run (the original cause of the reconciler failing every run). The toggle must remain best-effort.

Fix — make it alertable, not fatal

  • A flag file ($TEXTFILE_DIR/.reconciler-actions-degraded, reset each run) is set whenever the toggle is skipped/failed: list curl error, list non-200 (scope), or PATCH non-2xx (write:repository). Marker file, not a shell global, so it survives any subshell in the owner loops.
  • write_reconciler_metric emits gitborg_reconciler_actions_enforcement_degraded {0,1} alongside the existing status/timestamp — so it's recorded on both the success path and the EXIT-trap failure path.
  • New alert ReconcilerActionsEnforcementDegraded (== 1 for: 1h, warning): a persistent scope problem pages; a one-off transient doesn't.

Fix path when it fires: broaden the reconciler token (runbook Actions-tier token note). Not applied yet — monitoring role change, review + apply via infra-apply.

Closes #183. ## Problem The reconciler's per-repo Actions (`has_actions`) toggle needs `read:user`/`read:organization` + `write:repository`. When the admin token lacks those, `set_repo_actions` logs a WARN and returns — the run **still succeeds (status 0)** while CI tier gating (the grant *and* the default-deny bypass-prevention, #37/#125 M4) quietly stops being enforced. This was invisible: no metric, no alert, just a WARN nobody reads. Making it **fatal** is the wrong fix — it would couple the Actions toggle's failure to the critical quota/org enforcement in the same run (the original cause of the reconciler failing every run). The toggle must remain best-effort. ## Fix — make it alertable, not fatal - A flag file (`$TEXTFILE_DIR/.reconciler-actions-degraded`, reset each run) is set whenever the toggle is skipped/failed: list curl error, list non-200 (scope), or PATCH non-2xx (write:repository). Marker file, not a shell global, so it survives any subshell in the owner loops. - `write_reconciler_metric` emits `gitborg_reconciler_actions_enforcement_degraded {0,1}` alongside the existing status/timestamp — so it's recorded on both the success path and the EXIT-trap failure path. - New alert **ReconcilerActionsEnforcementDegraded** (`== 1` `for: 1h`, warning): a persistent scope problem pages; a one-off transient doesn't. Fix path when it fires: broaden the reconciler token (runbook Actions-tier token note). Not applied yet — monitoring role change, review + apply via infra-apply.
supernaut lade till 1 incheckning 2026-07-21 23:16:08 +00:00
feat(reconciler): alert when Actions enforcement is silently skipped (#183)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m23s
14739238b2
A scope-short admin token makes the per-repo has_actions toggle a no-op: the
reconciler run stays green (status 0) while CI tier gating — both the grant and
the default-deny — quietly stops applying. It was WARN-only (invisible). Making it
fatal is wrong: it would take the critical quota/org enforcement down with it (the
old cause of the reconciler failing every run), so the toggle must stay best-effort.

Instead surface it: set a flag file whenever the Actions toggle is skipped/fails
(list curl error, list non-200, or PATCH non-2xx), and emit
gitborg_reconciler_actions_enforcement_degraded from write_reconciler_metric (so it's
written on both the success path and the failure trap). New ReconcilerActionsEnforcementDegraded
alert fires on ==1 for 1h (persistent scope problem pages; one-off transient doesn't).
Marker-file (not shell global) so it survives any subshell in the owner loops.
supernaut sammanfogade incheckning b60248187b till main 2026-07-21 23:19:46 +00:00
supernaut tog bort grenen feat/183-reconciler-actions-degraded-alert 2026-07-21 23:19:46 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!202
Ingen beskrivning angiven.