no-mistakes(review): Gate wrapper checks on executed infisical; scope liveness guide

This commit is contained in:
2026-09-10 01:46:06 +00:00
parent c59c9fb174
commit 1974959cc9
4 changed files with 35 additions and 11 deletions
+14 -5
View File
@@ -222,14 +222,23 @@ optional. The 2026-09-09 probe-drift rounds cost three false `DEGRADED` reports
because a stale consumer probed the wrong port and nothing in the report said
where it ran.
Pair it with the **any-HTTP-response liveness rule**: a probe is ALIVE on ANY
HTTP status — including `301` redirects and `401`/`403` auth challenges. A bare
`200` is not required and must never be a pass condition for an auth-gated
endpoint. **DOWN = connection refused (`000`) or timeout only.**
Pair it with the **scoped any-HTTP-response liveness rule**: for unauthenticated
or auth-gated endpoints — where any HTTP answer proves a listener is up (the
PVE API's `401`, LiteLLM health's `301` redirect) — a probe is ALIVE on ANY HTTP
status, including `301` redirects and `401`/`403` auth challenges. **DOWN =
connection refused (`000`) or timeout only.**
Probes whose success condition is specifically a bare `200` are NOT covered by
the any-HTTP rule. On those — authenticated probes such as the Zulip message
POST and the router `/health` — an unexpected status (`401`/`403` from a bad or
missing credential, `5xx`, or anything other than the expected `200`) is an
**ALERT**, not "alive".
```markdown
**Report format**: Begin every report with the absolute execution path
(`pwd -P` / script path). Alive = ANY HTTP status; DOWN = `000`/timeout only.
(`pwd -P` / script path). On auth-gated endpoints, alive = ANY HTTP status and
DOWN = `000`/timeout only; on probes whose expected result is `200`, any other
status is an alert.
```
The lint pipeline enforces the provenance clause: any contract with a