Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 477454ec3c | |||
| 10812606bf | |||
| 94dec19976 | |||
| 9046f6e026 | |||
| 03504b61be |
@@ -59,6 +59,30 @@ jobs:
|
||||
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
||||
fi
|
||||
|
||||
# This exists because `go vet` does not look at import order: the move to
|
||||
# git.ryuvia.com rewrote every import path without re-sorting, the new path sorts
|
||||
# before github.com/..., and both repos sat unformatted through a green CI run and
|
||||
# a release before anyone noticed.
|
||||
#
|
||||
# Both of gofmt's failure modes need handling, and they are not alike. A file that
|
||||
# is merely misformatted is listed on stdout with exit 0 -- so the failure has to
|
||||
# be raised by hand. A file that does not parse is the opposite: nothing on stdout
|
||||
# and exit 2, which a naive `[ -n "$unformatted" ]` reads as success. The first
|
||||
# draft of this step had exactly that hole.
|
||||
- name: Format
|
||||
run: |
|
||||
if ! unformatted=$(gofmt -l .); then
|
||||
echo "::error::gofmt could not parse the tree"
|
||||
gofmt -l . # re-run unredirected so the parse errors reach the log
|
||||
exit 1
|
||||
fi
|
||||
if [ -n "$unformatted" ]; then
|
||||
echo "::error::not gofmt'd:"
|
||||
echo "$unformatted"
|
||||
gofmt -d .
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Vet
|
||||
run: go vet ./...
|
||||
|
||||
|
||||
@@ -41,6 +41,30 @@ jobs:
|
||||
REF_NAME: ${{ github.ref_name }}
|
||||
run: git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
||||
|
||||
# This exists because `go vet` does not look at import order: the move to
|
||||
# git.ryuvia.com rewrote every import path without re-sorting, the new path sorts
|
||||
# before github.com/..., and both repos sat unformatted through a green CI run and
|
||||
# a release before anyone noticed.
|
||||
#
|
||||
# Both of gofmt's failure modes need handling, and they are not alike. A file that
|
||||
# is merely misformatted is listed on stdout with exit 0 -- so the failure has to
|
||||
# be raised by hand. A file that does not parse is the opposite: nothing on stdout
|
||||
# and exit 2, which a naive `[ -n "$unformatted" ]` reads as success. The first
|
||||
# draft of this step had exactly that hole.
|
||||
- name: Format
|
||||
run: |
|
||||
if ! unformatted=$(gofmt -l .); then
|
||||
echo "::error::gofmt could not parse the tree"
|
||||
gofmt -l . # re-run unredirected so the parse errors reach the log
|
||||
exit 1
|
||||
fi
|
||||
if [ -n "$unformatted" ]; then
|
||||
echo "::error::not gofmt'd:"
|
||||
echo "$unformatted"
|
||||
gofmt -d .
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Vet
|
||||
run: go vet ./...
|
||||
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
# Read by the `release` skill (~/.claude/skills/release).
|
||||
#
|
||||
# Only what the Makefile cannot already say. IMAGE, HELM_CHART and HELM_REPO come from
|
||||
# `make release-vars`, so they have one definition and cannot drift from what is built.
|
||||
#
|
||||
# Defaults, set here only where this repo differs:
|
||||
# CHARTS_REPO=$HOME/git/charts CHARTS_DIR=<image basename>
|
||||
# GITEA_LOGIN=Ryuvia APPVERSION_PREFIX=
|
||||
|
||||
# Same as the image basename, so this is only stated to be read rather than derived.
|
||||
CHARTS_DIR=terdut-server
|
||||
|
||||
# riksdata writes appVersion: "v0.3.1", rd-web writes a bare 0.5.0; this repo writes the
|
||||
# v, like riksdata. Nothing reads the field -- .gitea/workflows/release.yaml stamps both
|
||||
# version and appVersion from the tag when it publishes -- but people read it, and until
|
||||
# 2026-09-01 it said "latest" while the tree headed for a numbered release.
|
||||
APPVERSION_PREFIX=v
|
||||
@@ -0,0 +1,84 @@
|
||||
REGISTRY := git.ryuvia.com
|
||||
# The personal namespace, not ryuvia — deliberately, and for one reason: Gitea
|
||||
# scopes package visibility to the owner with no per-package override, so
|
||||
# ryuvia/* is private because the org is. Publishing here keeps the image and
|
||||
# chart anonymously pullable, so no pull secret is needed in the cluster and
|
||||
# Flux needs no registry credentials. Same choice riksdata and rd-web made.
|
||||
OWNER := niklas
|
||||
|
||||
IMAGE := $(REGISTRY)/$(OWNER)/terdut-server
|
||||
HELM_CHART := charts/terdut-server
|
||||
HELM_REPO := oci://$(REGISTRY)/$(OWNER)
|
||||
|
||||
# go.mod pins an exact patch release so nobody builds the shipped binary with a
|
||||
# toolchain carrying known stdlib CVEs. Fedora's Go package overrides the
|
||||
# upstream GOTOOLCHAIN default to `local`, which turns that pin into a hard
|
||||
# failure on a dev box one patch behind, so restore the upstream default here.
|
||||
export GOTOOLCHAIN ?= auto
|
||||
|
||||
.PHONY: help
|
||||
help: ## Show this help
|
||||
@grep -hE '^[a-zA-Z_-]+:.*?## ' $(MAKEFILE_LIST) | \
|
||||
awk 'BEGIN {FS = ":.*?## "}; {printf " \033[36m%-22s\033[0m %s\n", $$1, $$2}'
|
||||
|
||||
## --- checks ---
|
||||
#
|
||||
# These three mirror .gitea/workflows/ci.yaml step for step, so a green `make fmt
|
||||
# lint test` here means the same thing CI means. The one deliberate difference is
|
||||
# -race below.
|
||||
|
||||
.PHONY: test
|
||||
test: ## Run the test suite
|
||||
go test -race ./...
|
||||
|
||||
# CI runs a bare `go test ./...`. This is stricter on purpose: the sweeper, the
|
||||
# notifier goroutine and the deadman sweep all touch the same single-connection
|
||||
# database, and a race there would surface as a flaky production incident rather
|
||||
# than a failed build. It passes today; if it ever costs more than it catches,
|
||||
# the honest fix is to teach CI -race too, not to quietly drop it here.
|
||||
.PHONY: lint
|
||||
lint: ## go vet
|
||||
go vet ./...
|
||||
|
||||
# Copied from ci.yaml rather than simplified, because both of gofmt's failure
|
||||
# modes need handling and they are not alike. A file that is merely misformatted
|
||||
# is listed on stdout with exit 0 — so the failure has to be raised by hand. A
|
||||
# file that does not parse is the opposite: nothing on stdout and exit 2, which a
|
||||
# naive `[ -n "$$out" ]` reads as success. See 9046f6e.
|
||||
.PHONY: fmt
|
||||
fmt: ## Report unformatted files
|
||||
@if ! unformatted=$$(gofmt -l .); then \
|
||||
echo "gofmt could not parse the tree:"; gofmt -l .; exit 1; \
|
||||
fi; \
|
||||
if [ -n "$$unformatted" ]; then \
|
||||
echo "gofmt needed:"; echo "$$unformatted"; gofmt -d .; exit 1; \
|
||||
fi
|
||||
|
||||
.PHONY: helm-lint
|
||||
helm-lint: ## Lint and render the chart
|
||||
helm lint $(HELM_CHART) --set image.tag=v0.0.0
|
||||
helm template terdut-server $(HELM_CHART) --namespace terdut-server \
|
||||
--set image.tag=v0.0.0 >/dev/null
|
||||
@# networking.listener defaults to "", which attaches the route to every
|
||||
@# matching listener including plaintext HTTP. Production sets it, so the
|
||||
@# default render proves nothing about the path that actually ships.
|
||||
helm template terdut-server $(HELM_CHART) --namespace terdut-server \
|
||||
--set image.tag=v0.0.0 --set networking.listener=https-terdut >/dev/null
|
||||
|
||||
## --- release ---
|
||||
|
||||
# The release process (~/.claude/skills/release) reads these rather than restating them.
|
||||
# One definition, so the version that gets tagged, the image that gets pushed and the chart
|
||||
# the wrapper pins cannot drift apart in a second copy.
|
||||
.PHONY: release-vars
|
||||
release-vars: ## Print the variables the release process reads
|
||||
@printf 'IMAGE=%s\nHELM_CHART=%s\nHELM_REPO=%s\n' '$(IMAGE)' '$(HELM_CHART)' '$(HELM_REPO)'
|
||||
|
||||
# There is deliberately no build/push/helm-package/helm-push/release here, unlike
|
||||
# riksdata and rd-web. .gitea/workflows/release.yaml owns publishing for this repo,
|
||||
# and it does two things a local make cannot: it builds linux/amd64 and linux/arm64
|
||||
# through buildx, and it stamps the chart's version and appVersion from the tag. A
|
||||
# `docker build && docker push` target would push a single-architecture image over
|
||||
# the multi-arch tag, which is both easy to do by accident and invisible afterwards
|
||||
# — the tag would still resolve, just not on arm64. Publishing happens by pushing a
|
||||
# tag; nothing else.
|
||||
@@ -4,8 +4,15 @@ description: A Helm chart for Terminal Duty — on-call alert management server
|
||||
type: application
|
||||
# These two are placeholders for a local `helm install ./charts/terdut-server`, not the
|
||||
# released values. .gitea/workflows/release.yaml rewrites both from the git tag when it
|
||||
# publishes, so the chart version always equals the app version. Bumping them by hand
|
||||
# does nothing for a release and is not needed before tagging.
|
||||
# "latest" is honest here: it matches image.tag in values.yaml.
|
||||
version: 0.9.0
|
||||
appVersion: "latest"
|
||||
# publishes, so the chart version always equals the app version.
|
||||
#
|
||||
# They are kept in step with the tag anyway. Being read is the only thing these two
|
||||
# lines do -- nothing that publishes looks at them -- and a tree heading for v0.9.2 that
|
||||
# says 0.9.0 tells its reader something false. That is what they said until 2026-09-01,
|
||||
# through two releases.
|
||||
#
|
||||
# appVersion and image.tag in values.yaml no longer agree, and that is not an oversight:
|
||||
# image.tag stays "latest", which is what a local install actually pulls. appVersion is
|
||||
# metadata and drives nothing.
|
||||
version: 0.9.2
|
||||
appVersion: "v0.9.2"
|
||||
|
||||
@@ -10,8 +10,8 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"git.ryuvia.com/niklas/terdut-server/internal/models"
|
||||
"github.com/go-chi/chi/v5"
|
||||
)
|
||||
|
||||
// alertSelectFrom is the shared SELECT … FROM … clause used by all alert queries.
|
||||
|
||||
@@ -8,8 +8,8 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"git.ryuvia.com/niklas/terdut-server/internal/models"
|
||||
"github.com/go-chi/chi/v5"
|
||||
)
|
||||
|
||||
func handleListIncidents(db *sql.DB) http.HandlerFunc {
|
||||
|
||||
@@ -653,6 +653,61 @@ func TestStats_Incidents(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// An empty window is a report of zero, not a failure. SUM over no rows is NULL
|
||||
// in SQLite, which used to come back as a 500 the moment every incident was
|
||||
// archived — the state a quiet installation settles into.
|
||||
func TestStats_IncidentsEmptyWindowIsZeroNotAnError(t *testing.T) {
|
||||
s := newTS(t)
|
||||
|
||||
// No incidents at all.
|
||||
resp := s.req(t, http.MethodGet, "/api/stats/incidents", nil)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
resp.Body.Close()
|
||||
t.Fatalf("expected 200 on an empty database, got %d", resp.StatusCode)
|
||||
}
|
||||
var stats map[string]any
|
||||
decode(t, resp, &stats)
|
||||
for _, k := range []string{"total", "triggered", "acknowledged", "resolved"} {
|
||||
if stats[k].(float64) != 0 {
|
||||
t.Errorf("expected %s 0, got %v", k, stats[k])
|
||||
}
|
||||
}
|
||||
|
||||
// And with every incident archived out of the window.
|
||||
postWebhook(t, s, []map[string]any{
|
||||
amAlert("fp-s4", "Gone", "firing", "2026-05-20T10:00:00Z", zeroTime, nil),
|
||||
})
|
||||
s.req(t, http.MethodPost, "/api/incidents/1/archive", nil).Body.Close()
|
||||
|
||||
resp = s.req(t, http.MethodGet, "/api/stats/incidents", nil)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
resp.Body.Close()
|
||||
t.Fatalf("expected 200 when every incident is archived, got %d", resp.StatusCode)
|
||||
}
|
||||
stats = nil
|
||||
decode(t, resp, &stats)
|
||||
if stats["total"].(float64) != 0 {
|
||||
t.Errorf("expected total 0, got %v", stats["total"])
|
||||
}
|
||||
}
|
||||
|
||||
// The alert stats share the same aggregate, and the same empty-window trap.
|
||||
func TestStats_AlertsEmptyWindowIsZeroNotAnError(t *testing.T) {
|
||||
s := newTS(t)
|
||||
resp := s.req(t, http.MethodGet, "/api/stats/alerts", nil)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
resp.Body.Close()
|
||||
t.Fatalf("expected 200 on an empty database, got %d", resp.StatusCode)
|
||||
}
|
||||
var stats map[string]any
|
||||
decode(t, resp, &stats)
|
||||
for _, k := range []string{"total", "firing", "resolved"} {
|
||||
if stats[k].(float64) != 0 {
|
||||
t.Errorf("expected %s 0, got %v", k, stats[k])
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Nothing acknowledged yet means "no data", which is not the same claim as zero.
|
||||
func TestStats_IncidentsNullMTTAWhenNothingAcknowledged(t *testing.T) {
|
||||
s := newTS(t)
|
||||
|
||||
@@ -8,8 +8,8 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"git.ryuvia.com/niklas/terdut-server/internal/models"
|
||||
"github.com/go-chi/chi/v5"
|
||||
)
|
||||
|
||||
func handleCreateSchedule(db *sql.DB) http.HandlerFunc {
|
||||
|
||||
+11
-5
@@ -13,11 +13,14 @@ func handleStatsAlerts(db *sql.DB) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
where, args := statsFilter(r.URL.Query(), "received_at")
|
||||
|
||||
// COALESCE because SUM over zero rows is NULL, not 0, and a count of
|
||||
// nothing is 0 — without it an empty window is a 500 rather than a
|
||||
// legitimately empty report.
|
||||
var total, firing, resolved int64
|
||||
err := db.QueryRowContext(r.Context(), fmt.Sprintf(`
|
||||
SELECT COUNT(*),
|
||||
SUM(CASE WHEN status = 'firing' THEN 1 ELSE 0 END),
|
||||
SUM(CASE WHEN status = 'resolved' THEN 1 ELSE 0 END)
|
||||
COALESCE(SUM(CASE WHEN status = 'firing' THEN 1 ELSE 0 END), 0),
|
||||
COALESCE(SUM(CASE WHEN status = 'resolved' THEN 1 ELSE 0 END), 0)
|
||||
FROM alerts WHERE %s`, where), args...,
|
||||
).Scan(&total, &firing, &resolved)
|
||||
if err != nil {
|
||||
@@ -167,13 +170,16 @@ func handleStatsIncidents(db *sql.DB) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
where, args := statsFilter(r.URL.Query(), "triggered_at")
|
||||
|
||||
// The counts are COALESCEd because SUM over zero rows is NULL, not 0.
|
||||
// The averages are not: mtta and mttr stay null on purpose, since zero
|
||||
// would read as "instant" rather than "nothing to measure yet".
|
||||
var total, triggered, acknowledged, resolved int64
|
||||
var mtta, mttr *float64
|
||||
err := db.QueryRowContext(r.Context(), fmt.Sprintf(`
|
||||
SELECT COUNT(*),
|
||||
SUM(CASE WHEN status = 'triggered' THEN 1 ELSE 0 END),
|
||||
SUM(CASE WHEN status = 'acknowledged' THEN 1 ELSE 0 END),
|
||||
SUM(CASE WHEN status = 'resolved' THEN 1 ELSE 0 END),
|
||||
COALESCE(SUM(CASE WHEN status = 'triggered' THEN 1 ELSE 0 END), 0),
|
||||
COALESCE(SUM(CASE WHEN status = 'acknowledged' THEN 1 ELSE 0 END), 0),
|
||||
COALESCE(SUM(CASE WHEN status = 'resolved' THEN 1 ELSE 0 END), 0),
|
||||
AVG(CASE WHEN acknowledged_at IS NOT NULL
|
||||
THEN acknowledged_at - triggered_at END),
|
||||
AVG(CASE WHEN resolved_at IS NOT NULL
|
||||
|
||||
@@ -11,8 +11,8 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"git.ryuvia.com/niklas/terdut-server/internal/models"
|
||||
"github.com/go-chi/chi/v5"
|
||||
)
|
||||
|
||||
func handleBootstrap(db *sql.DB) http.HandlerFunc {
|
||||
|
||||
Reference in New Issue
Block a user