Repository navigation
4xx alerts against a baseline, the failing request and response in every alert - #2
Merged
Merged
Conversation
…default; 4xx against each API's own baseline
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
--client-errors baseline, the default). Each API learns its normal share of 4xx answers over its first five minutes (and at least 50 requests), then alerts when the last minute is at least 3x that share and 10 points higher, with at least 5 4xx answers. The baseline is frozen while the alert is firing.--client-errors all|off,--client-codes 401,403,429,--min-client-errors 5.src/lib/bodies.js). Bodies are decompressed throughyeet:compression(gzip, deflate, brotli) and cut to about 1000 characters each; binary bodies are shown as a size.--bodies redacted(default) blanks values under secret-looking keys in JSON, form and query strings (password, token, api_key, authorization, card, cvv, ssn and similar) plus bearer tokens, JWTs and Luhn-valid card numbers anywhere.rawandoffare the alternatives. Headers other than the content type are never shown. Email addresses and other personal data are not redacted (decided).--watch, so anyone reading the log sees one within a minute./logroute (yeet service unit add apiwatch/web -W http://127.0.0.1:9470andyeet service mount apiwatch/web -L /log -t watch -p console) and the privacy note that alert bodies travel through yeet's servers to Slack.package.json(ES modules) andtest/: 16 tests for redaction and the 4xx baseline,npm test.How it was tested
npm test: 16 of 16 pass.yeet run github:yeet-src/apiwatch@alerts-bodies-4xx:card_numberandpasswordand anaccess_tokenquery parameter came out[redacted].api_keyblanked), reported back to normal at 13%./logroute, which returned 403 as expected while signed out. A real outage under the agent-installed service produced the batched alert.Not yet tested: the live Slack post
Every Slack-side behavior so far is a dry-run. To close it, on a Linux box with yeet installed:
yeet loginand approve the link, then connect Slack at https://yeet.cx/settings. Invite the yeet app to the channel if it is private.yeet run -y github:yeet-src/apiwatch@alerts-bodies-4xx -- --test-alert --slack "#your-channel" --name test-box: one message should arrive.--watch --slack "#your-channel"against something you can break (stop an upstream behind a proxy) and check that the batched message renders, request and response included, with nothing redacted that shouldn't be.yeet.alertcan set Slack'susername/icon_url(to say "apiwatch") depends on the platform forwarding them and the Slack app havingchat:write.customize.