Alert on identity projection failures and on refused account creation at first sign-in #326
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#326
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Two identity failure modes are currently unalertable.
A refused identity write is reported through the Actions-enforcement gauge, so the alert that
fires names the wrong subsystem and the wrong fix. Once the reconciler publishes a separate
identity gauge, add an
IdentityProjectionDegradedrule with a description that names the realcauses and points at the identity ownership decision record.
If a name is valid at the identity provider but reserved on the git host, account creation fails
at first sign-in as a 500. Nothing is watching for it: the portal is not in the request, the
reconciler cannot see an account that was never created, and no metric moves. The user simply
cannot use the git host. Add a log-store rule matching account-creation failures in the git
host's logs, severity warning — one occurrence is one locked-out user.
Depends on the reconciler publishing a separate identity gauge; file the alert rule alongside that
version bump.
Part of gitborg/gitborg-docs#66.