Alert when a first-party owner is not in its expected quota group #423
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#423
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Nothing alerts when a first-party owner loses its expected quota group.
Why
The reconciler logs its decision at INFO, in one shape for every org:
That line is the normal, correct output for a tenant org. It is also the output when the
platform's own org has just been demoted to the tenant cap with Actions switched off. Nothing
in the line distinguishes the routine case from the outage, so nothing fires.
On 2026-08-04 that meant a demotion went unnoticed until pushes started failing, and it stayed
broken for ~90 minutes. The reconciler is authoritative and re-asserts its decision every tick, so
the window between "wrong state" and "someone notices" is the entire outage.
The case-sensitivity defect that caused that specific demotion is fixed in
bitborg-auth-reconciler#42. This issue is the detection gap, which is worth closing regardless —
the fixed bug is one of several ways an owner can end up in the wrong group. A bad exempt-list
edit, a group deleted by hand in the Forgejo admin UI, or a future projection change would all land
the same way and be equally invisible.
What to do
Alert when a declared first-party owner is not in its expected quota group. The declarations
already exist as
reconciler_user_exemptandreconciler_org_exemptinroles/reconciler/defaults/main.yml, so the expected state is known without new configuration.Two candidate shapes, either is fine:
it. Cheapest to reason about, and it reuses the existing
bitborg_*metric pipeline.precise, but needs no metric surface.
Prefer the metric: the log route re-creates the same "is this line normal or not" ambiguity that
caused the gap.
Acceptance