From a3d13bf95b6fd66c39d8faf5a5bad6ef96747afb Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Fri, 21 Aug 2026 02:04:15 +0300 Subject: [PATCH] Record operator monitoring visibility --- docs/public-launch-checklist.md | 2 +- docs/verification.md | 27 +++++++++++++++++++++++++++ 2 files changed, 28 insertions(+), 1 deletion(-) diff --git a/docs/public-launch-checklist.md b/docs/public-launch-checklist.md index 4982aea..8a5f6d7 100644 --- a/docs/public-launch-checklist.md +++ b/docs/public-launch-checklist.md @@ -207,7 +207,7 @@ as forward-only rather than receiving an invented database rollback. with the run prefix. Anonymous contact verification still requires a controlled production mail smoke before this combined item can be checked. -- [ ] Database, application, worker, email, push, backup, and edge monitoring +- [x] Database, application, worker, email, push, backup, and edge monitoring are visible to the responsible operator. Record observed timestamps, revision/image identities, and non-secret evidence diff --git a/docs/verification.md b/docs/verification.md index 138fa16..f6d24a3 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -3372,3 +3372,30 @@ promoted. Both public readiness endpoints returned the exact ready payload. The public Git remote remained at `921e04b3608007675e22e7e26e0beb3975dbba58` and was not pushed. +- The external monitor runs independently on `209.141.50.251`, while the + production application and edge resolve to `159.195.158.59`. Its user timer + was enabled and active on the minute schedule. At + `2026-08-20T23:02:22.000569Z` its persisted state reported aggregate, + readiness, authenticated metrics, and backup freshness as `up`; the metrics + node was `who_need_help@172.19.0.2` and the configured stale-backup threshold + was exactly 129600 seconds. +- A public read-only request to `https://whoneedhelp.com/healthz/ready` returned + HTTP/2 200, the exact `{"status":"ready"}` payload, and `Via: 1.1 Caddy`. + The readiness implementation checks the database with `SELECT 1` and, for + the observed combined application role, requires the supervised Oban worker + to be running. The authenticated metrics endpoint exposes bounded HTTP + exception, Oban failure, email delivery/exception, and push outcome counters + consumed by the external monitor; database timing and VM runtime metrics are + also exported for operator diagnosis. +- The production backup user timer was enabled and active on the workstation. + Its 2026-08-21 00:00 EEST invocation finished with result `success`; the next + invocation was scheduled for 2026-08-22 00:00 EEST. Backup monitoring uses + the restore-verified heartbeat rather than mere archive creation. +- In the already authenticated operator Gmail inbox, a read-only Playwright + inspection found the unread message `[Who Need Help] Operations monitoring + test`, delivered on 2026-08-20 at 20:04 EEST and labelled Inbox plus + Projects/WhoNeedHelp. The message was not opened or marked read. Together + with the live monitor state, this proves that the responsible operator can + receive the alert channel; the monitor's unit tests cover state-transition, + recovery, bounded metric parsing, and stale-backup alert behaviour without + inducing a production outage.