AUTO (planned) = security-class updates the staged pipeline will apply automatically (canary → 48h soak → fleet) once pve-auto-update ships.
| Urgency | Kind | Finding | Node | AI reasoning |
|---|
Every resolved update: when it was noticed by a scan, when it was fixed, and how — AUTO = applied by the pve-auto-update pipeline; MANUAL = a scan noticed it was already done, i.e. resolved by a sysadmin. Time-to-fix feeds SLA measurement.
| How | Urgency | Finding | Node/CT | Noticed | Fixed | Time to fix | Detail |
|---|
The alert rail is alert-relay.ha.fiszu.com. Every post it delivers is signed “delivered by alert-relay.ha.fiszu.com” — an alert in Mattermost WITHOUT that line bypassed the rail, and is the migration backlog you can see by scrolling the channel. Nothing here is enforced: the relay never refuses an alert, because a refused alert is a missed one. Producers need no key.
Named daily on the Server Stability board too. Their alerts are delivered in full regardless.
| Producer | Alerts | Non-conforming | What is wrong |
|---|
Every producer must state its destination
explicitly. A payload with no channel is delivered to Server Stability by
the relay, but the destination then depends on the webhook’s own default —
somebody else’s config, with no commit in any repo.
| Producer | Posts with no channel | First seen | Last seen |
|---|
| Producer | Channel it asked for | Rejections |
|---|
How long has this been broken, and who owns it — the view that turns a noisy channel into a backlog somebody can work. Days known is the whole life of the condition, first-ever fire to now, and it spans any days it was quiet; This episode is the run happening right now. When Clears is not zero those two are different questions and the second is the one to react to.
| Days known | This episode | Clears | Condition | Service | Entity | Owner | Fires |
|---|
Who can see and do what. A role can be granted to a Keycloak group or to an individual user; the strongest grant wins. The matrix below edits what each role may do — and a per-user row overrides that person's role entirely.
Ticking a box changes what that role (or person) can do everywhere in this panel. Reset restores the built-in default. An empty row is a valid, saved state — it means "nothing".
Keycloak users and groups with no role here at all. They can log in and will see a "no access" page until granted something.