Commit Graph

4498 Commits

Author SHA1 Message Date
pulse-triage[bot] 6a7ac88aea Repair Docker action governance proof
Recognize the focused Docker action API tests as backend payload proofs and record the explicit container-health boundary in the dependent storage/recovery contract.

Change-source: pulse-maintainer
2026-08-27 21:01:07 +01:00
rcourtman a9076de15a fix(patrol): require Docker health recovery 2026-08-27 20:43:54 +01:00
rcourtman 13ceeffe7d Converge remaining drawer detail rows 2026-08-27 20:41:43 +01:00
rcourtman b0c1eca4cd Add predictive storage capacity alerts 2026-08-27 20:41:08 +01:00
pulse-triage[bot] f9340e3334 Complete Docker action verification proof
Change-source: pulse-maintainer
2026-08-27 20:19:17 +01:00
rcourtman 6163a2a564 feat(patrol): verify Docker actions independently 2026-08-27 20:14:38 +01:00
pulse-triage[bot] 7e1dbd91eb Bound alert escalation schedule delays
Change-source: pulse-maintainer
2026-08-27 20:12:36 +01:00
rcourtman 636367e96e Fix desktop drawer detail alignment 2026-08-27 20:00:01 +01:00
rcourtman e0baecc418 Make alert escalations destination-specific and repeatable 2026-08-27 19:51:12 +01:00
pulse-triage[bot] 5f6bfefa56 Make notification destination updates durable 2026-08-27 19:46:40 +01:00
rcourtman 1164d37302 feat(patrol): reconcile actionable findings on activation 2026-08-27 19:44:02 +01:00
rcourtman 329e701de9 Converge investigation drawer detail layout 2026-08-27 19:28:09 +01:00
rcourtman 8df9db7ab1 feat(alerts): add destination severity routing 2026-08-27 19:13:32 +01:00
pulse-triage[bot] cbcd27b4a8 Govern deploy enrollment durability
Record the bootstrap-to-runtime credential replacement as one durable transition across API, agent lifecycle, security, and storage contracts. Document rollback, replay, and no-secret-on-failure guarantees proved by the deploy handler suite.\n\nChange-source: pulse-maintainer
2026-08-27 19:02:03 +01:00
rcourtman 3d4c43162a feat(alerts): add recurring scoped maintenance 2026-08-27 18:20:03 +01:00
pulse-triage[bot] d48e70da15 docs(governance): record launchd mode invariant
Change-source: pulse-maintainer
2026-08-27 18:00:28 +01:00
rcourtman ff507a6e44 feat(alerts): add per-alert snooze 2026-08-27 17:20:32 +01:00
pulse-triage[bot] 735acbb05a fix(dockeragent): bound image storage computation
Keep live image identity fresh without recomputing shared layer sizes on every report. Reuse the throttled storage snapshot and qualify the reported Synology inventory shape.

Change-source: pulse-maintainer
2026-08-27 16:33:14 +01:00
rcourtman f4e1e47e74 feat(alerts): add external dead-man monitoring 2026-08-27 16:27:46 +01:00
rcourtman f6773f262a fix(alerts): make active restart state durable
Contract-Neutral: monitor construction only moves alerts-owned durable-store initialization before alert workers; monitoring and host-agent behavior are unchanged
2026-08-27 15:21:18 +01:00
pulse-triage[bot] 6bbf814548 fix(proxmox): govern overview PBS health 2026-08-27 15:15:35 +01:00
rcourtman b6babd0b4b fix(alerts): make incident timelines lifecycle-driven
Contract-Neutral: monitor startup wiring changes only alert lifecycle projection behavior; agent-lifecycle deletion and reenrollment contracts are unchanged
2026-08-27 14:45:36 +01:00
rcourtman 1e75423116 fix(release): enforce plain changelog punctuation 2026-08-27 13:56:35 +01:00
rcourtman 9e17122713 fix(release): keep changelog synthesis model-led 2026-08-27 13:39:16 +01:00
pulse-triage[bot] 9622f89fe6 feat(alerts): configure SMART disk thresholds
Expose host disk SMART health, counter, endurance, spare, and CRC-growth rules in alert settings while preserving existing defaults and supporting explicit disable values.

Change-source: pulse-maintainer
2026-08-27 13:20:36 +01:00
pulse-triage[bot] 3d91709eba docs(proxmox): govern PBS host history correlation
Record the unique PBS-to-Agent presentation boundary and the desktop and phone browser proof for Agent-backed host History.

Change-source: pulse-maintainer
2026-08-27 12:19:01 +01:00
rcourtman 73499d7161 feat(alerts): migrate persisted alert identities 2026-08-27 12:04:49 +01:00
rcourtman ff27c3881f fix(release): make changelog ranges channel-aware 2026-08-27 11:56:06 +01:00
rcourtman 248b242034 test(alerts): automate operator qualification 2026-08-27 11:06:26 +01:00
rcourtman 96add5d57a fix(alerts): harden event history recovery 2026-08-27 10:05:37 +01:00
pulse-triage[bot] fc55a1e3f2 Govern alert history authority changes
Record event-log history ownership, migration and tombstone semantics in the canonical alerts contract. Register the schema, migration and projection proofs so future runtime changes satisfy the explicit alerts verification policy.

Change-source: pulse-maintainer
2026-08-27 09:26:52 +01:00
rcourtman 276a9baa2b chore(release-control): release alert-lifecycle-contract-coverage claim 2026-08-27 09:24:48 +01:00
rcourtman 0d381ee24f docs(alerts): record the contract gate, history authority, and the registered identity migration 2026-08-27 09:24:35 +01:00
pulse-triage[bot] 0fd9171ff7 Prevent host identity forks during install handoff
Allow one retiring-agent health window after a trusted replacement install token is minted, while preserving clone-safe forks for ambiguous, conflicting, or longer-lived identities. Retire superseded token bindings and document the remaining migration gap for identities already forked.

Change-source: pulse-maintainer
2026-08-27 08:47:42 +01:00
pulse-triage[bot] 8fde82b8a2 Keep LXC filesystem paths native-proof
Join Proxmox config paths with Linux semantics across native test platforms, add the regression proof, and update the canonical agent lifecycle contract for the new namespace-statfs collector.

Change-source: pulse-maintainer
2026-08-27 06:51:36 +01:00
pulse-triage[bot] c045c0451d Align rc.6 packet with LXC filesystem fix
Include the host-agent filesystem collection correction that landed after the initial rc.6 preparation, and keep the release metadata proof aligned with the new main head.

Change-source: pulse-maintainer
2026-08-27 06:46:57 +01:00
pulse-triage[bot] 1f28d950c3 Prepare v6.4.0-rc.6 release
Package the standalone PBS detail restoration, SMART CRC growth alerts, consolidated alert policy, bounded event queries, and Go 1.26.7 toolchain for the next prerelease.

Change-source: pulse-maintainer
2026-08-27 05:47:17 +01:00
pulse-triage[bot] aa50087c08 security(build): advance release toolchain to Go 1.26.7
Use the current supported Go 1.26 security patch across source, release, dev, and production container build surfaces. Keep the immutable official builder pin and governance proofs aligned with the exact toolchain.

Change-source: pulse-maintainer
2026-08-27 05:04:03 +01:00
pulse-triage[bot] 5859f49817 security(build): upgrade release toolchain to Go 1.26.6
Advance local, release, and container build surfaces together so reachable standard-library advisories cannot re-enter shipped binaries. Pin the official amd64 builder manifest and govern the updated floor with installability and dev-runtime proofs.

Change-source: pulse-maintainer
2026-08-27 04:24:10 +01:00
pulse-triage[bot] 1dc5ee4942 docs(alerts): govern SMART counter growth
Change-source: pulse-maintainer
2026-08-27 03:30:44 +01:00
pulse-triage[bot] e89bca00a0 security(alerts): decouple event query allocation
Change-source: pulse-maintainer
2026-08-27 02:13:42 +01:00
pulse-triage[bot] 1b4b8ae1dc Repair standalone PBS detail governance proof
Change-source: pulse-maintainer
2026-08-27 01:42:38 +01:00
rcourtman 479cce1d73 docs(alerts): record Phase 3 engine completion and the demand-gated UI decision 2026-08-27 01:13:04 +01:00
rcourtman 90cd0a57af docs(alerts): record Phase 2 completion and the reconciler scope-out 2026-08-27 01:01:19 +01:00
pulse-triage[bot] 3b21d4c257 Prepare v6.4.0-rc.5 release
Package the atomic API-token deletion fix, alert delivery evidence, reducer-backed lifecycle cutover, separated agent install tokens, and filesystem history feedback for the next release candidate.

Change-source: pulse-maintainer
2026-08-27 00:55:23 +01:00
pulse-triage[bot] 2a317cbd6b docs(alerts): govern stateful reducer cutover
Document reducer ownership for stateful alert transitions, timestamping, manual clears, acknowledgement retention, and refire history. Register the purpose-built stateful regression suite as canonical runtime and runtime-support proof.

Change-source: pulse-maintainer
2026-08-27 00:37:23 +01:00
pulse-triage[bot] df709db7a5 docs(alerts): govern reducer runtime cutover
Record the reducer as transition truth for canonical lifecycle and shared metric thresholds, including intent grace and activation-event ownership. Add a focused proof that metric intent remains pending until activation and emits one fired event.

Change-source: pulse-maintainer
2026-08-27 00:29:46 +01:00
rcourtman ee35d178b5 feat(alerts): backup-offline deferral in the reducer intent gate, completing Phase 1 characterization
The last uncharacterized behavior: while Pulse has fresh evidence a
Proxmox backup caused an offline state, activation defers — bounded by
the max-deferral cap on total condition-active time — and after the
backup ends the grace extends to the backup's end plus the post-grace,
still capped. The discrete activation path is unified so the gate always
operates on a tracked pending incident, and the shadow feed now models
the deferral independently from the manager's decision instead of
echoing its hold as operator suppression.

Unit tests cover deferral, post-grace release, the never-ending-backup
cap, and post-grace capping; parity runs the real
LoadIntentPolicies/IntentBackup composition with simulated clocks.
Fourth consecutive parity slice with no manager defect. Every
discrete-family and metric-family behavior is now pinned.
2026-08-26 23:54:12 +01:00
rcourtman bfc1a81867 feat(alerts): shadow-mode reducer feed with always-on divergence telemetry
Phase 1 capstone of docs/ALERT_ENGINE_EVOLUTION.md. The deterministic
reducer now runs continuously inside the live manager against the same
production observations: the canonical lifecycle path (connectivity,
powered-state, discrete-state kinds) via a deferred hook that replays
each evaluation — including the resolved intent context — through the
reducer; the poll-driven recovery paths (PBS/PMG/storage, node,
connection-degraded); and manual acknowledge/unacknowledge/clear. The
feed seeds from active canonical alerts at enable so restarts do not
read as mass divergence.

Every state disagreement is counted (Manager.ShadowDivergences) and
recorded in the alert event log as a shadow_divergence event with both
engines' states, rate-limited to one report per key per ten minutes.
After each divergence the reducer resyncs to the manager, so one
divergence yields one event — including divergences caused by manager
mutations the feed does not observe. Appends never block evaluation and
a disabled feed is a nil-check no-op.

This converts the parity harnesses' test-time guarantee into an
always-on invariant; the production divergence rate becomes the
go/no-go evidence for each Phase 2 family cutover. The full
activation/ack/recovery/re-fire cycle runs divergence-free in tests.
2026-08-26 23:49:12 +01:00
rcourtman 9043f9fb9f docs: mark March alert-engine migration doc superseded in scope
The input-layer direction stands; the transition-core and suppression
freezes do not (docs/ALERT_ENGINE_EVOLUTION.md). The stable-behaviors
list is a characterization inventory pinned by the reducer parity
harnesses, not a freeze — so a future session cannot mistake the frozen
scoping for current direction.
2026-08-26 23:37:34 +01:00