Alert on identity projection failures and on refused account creation at first sign-in #326

Stängd
öppnade 2026-08-02 12:30:45 +00:00 av supernaut · 0 kommentarer
Ägare

Two identity failure modes are currently unalertable.

  1. A refused identity write is reported through the Actions-enforcement gauge, so the alert that
    fires names the wrong subsystem and the wrong fix. Once the reconciler publishes a separate
    identity gauge, add an IdentityProjectionDegraded rule with a description that names the real
    causes and points at the identity ownership decision record.

  2. If a name is valid at the identity provider but reserved on the git host, account creation fails
    at first sign-in as a 500. Nothing is watching for it: the portal is not in the request, the
    reconciler cannot see an account that was never created, and no metric moves. The user simply
    cannot use the git host. Add a log-store rule matching account-creation failures in the git
    host's logs, severity warning — one occurrence is one locked-out user.

Depends on the reconciler publishing a separate identity gauge; file the alert rule alongside that
version bump.

Part of gitborg/gitborg-docs#66.

Two identity failure modes are currently unalertable. 1. A refused identity write is reported through the Actions-enforcement gauge, so the alert that fires names the wrong subsystem and the wrong fix. Once the reconciler publishes a separate identity gauge, add an `IdentityProjectionDegraded` rule with a description that names the real causes and points at the identity ownership decision record. 2. If a name is valid at the identity provider but reserved on the git host, account creation fails at first sign-in as a 500. Nothing is watching for it: the portal is not in the request, the reconciler cannot see an account that was never created, and no metric moves. The user simply cannot use the git host. Add a log-store rule matching account-creation failures in the git host's logs, severity warning — one occurrence is one locked-out user. Depends on the reconciler publishing a separate identity gauge; file the alert rule alongside that version bump. Part of gitborg/gitborg-docs#66.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#326
Ingen beskrivning angiven.