Files
cairnobs/alerting
dependabot[bot] 82cfe1fa0a Bump the go-minor-and-patch group across 5 directories with 9 updates
Bumps the go-minor-and-patch group with 1 update in the /alerting directory: [golang.org/x/sync](https://github.com/golang/sync).
Bumps the go-minor-and-patch group with 1 update in the /api directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go-minor-and-patch group with 3 updates in the /deploy/operator directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery), [k8s.io/client-go](https://github.com/kubernetes/client-go) and [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime).
Bumps the go-minor-and-patch group with 6 updates in the /enterprise directory:

| Package | From | To |
| --- | --- | --- |
| [golang.org/x/sync](https://github.com/golang/sync) | `0.22.0` | `0.23.0` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.31.0` | `0.37.0` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.31.0` | `0.37.0` |
| [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc) | `3.20.0` | `3.21.0` |
| [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) | `4.1.4` | `4.1.5` |
| [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.36.0` | `0.37.0` |

Bumps the go-minor-and-patch group with 1 update in the /ingest directory: [golang.org/x/sync](https://github.com/golang/sync).


Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `golang.org/x/crypto` from 0.55.0 to 0.56.0
- [Commits](https://github.com/golang/crypto/compare/v0.55.0...v0.56.0)

Updates `k8s.io/apimachinery` from 0.31.0 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.31.0...v0.37.0)

Updates `k8s.io/client-go` from 0.31.0 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.31.0...v0.37.0)

Updates `sigs.k8s.io/controller-runtime` from 0.19.3 to 0.25.0
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](https://github.com/kubernetes-sigs/controller-runtime/compare/v0.19.3...v0.25.0)

Updates `k8s.io/api` from 0.31.0 to 0.37.0
- [Commits](https://github.com/kubernetes/api/compare/v0.31.0...v0.37.0)

Updates `k8s.io/apimachinery` from 0.31.0 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.31.0...v0.37.0)

Updates `k8s.io/client-go` from 0.31.0 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.31.0...v0.37.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `k8s.io/apimachinery` from 0.31.0 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.31.0...v0.37.0)

Updates `k8s.io/client-go` from 0.31.0 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.31.0...v0.37.0)

Updates `github.com/coreos/go-oidc/v3` from 3.20.0 to 3.21.0
- [Release notes](https://github.com/coreos/go-oidc/releases)
- [Commits](https://github.com/coreos/go-oidc/compare/v3.20.0...v3.21.0)

Updates `github.com/go-jose/go-jose/v4` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/go-jose/go-jose/releases)
- [Commits](https://github.com/go-jose/go-jose/compare/v4.1.4...v4.1.5)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](https://github.com/golang/oauth2/compare/v0.36.0...v0.37.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `k8s.io/api` from 0.31.0 to 0.37.0
- [Commits](https://github.com/kubernetes/api/compare/v0.31.0...v0.37.0)

Updates `k8s.io/apimachinery` from 0.31.0 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.31.0...v0.37.0)

Updates `k8s.io/client-go` from 0.31.0 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.31.0...v0.37.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/crypto
  dependency-version: 0.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/client-go
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/api
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/client-go
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/client-go
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/coreos/go-oidc/v3
  dependency-version: 3.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: github.com/go-jose/go-jose/v4
  dependency-version: 4.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/api
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: k8s.io/client-go
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
2026-09-10 17:00:23 +00:00
..
2026-08-21 20:53:32 -07:00

alerting

Alert rule CRUD, the ticker-driven evaluator, and webhook/Slack/PagerDuty delivery. See /docs/phase-3-alerting-design.md for the full design (data model, the ok/pending/firing state machine, and the four correctness properties this implementation follows exactly).

Running

POSTGRES_PASSWORD=cairnobs-dev-only API_QUERY_URL=http://localhost:8080 go run ./cmd/alerting

Talks to the same cairnobs_metadata Postgres database as /api (different tables — see /metadata/README.md), and to /api's POST /query over plain HTTP for rule evaluation. Never connects to ClickHouse or Tantivy directly.

HTTP API

POST   /rules                    create a rule
GET    /rules                    list rules (with current state)
GET    /rules/{id}               get a rule (with current state)
DELETE /rules/{id}
GET    /rules/{id}/deliveries    delivery log for a rule, most recent first

POST   /targets                  create a notification target
GET    /targets
GET    /targets/{id}
DELETE /targets/{id}

GET    /healthz

A rule's condition_type is "threshold" (requires comparator + threshold_value, and the query must resolve to exactly one row) or "absence" (fires when the query returns zero rows in its own earliest=/latest= window — no separate window field). A notification target's kind is "webhook", "slack", or "pagerduty" — all three deliver via the same HTTP POST + retry/backoff mechanism (internal/delivery/webhook.go); slack/pagerduty are payload formatters only, not separate delivery paths.

Environment variables

Var Default
HTTP_LISTEN_ADDR :8081
POSTGRES_ADDR localhost:5432
POSTGRES_DATABASE cairnobs_metadata
POSTGRES_USERNAME cairnobs
POSTGRES_PASSWORD (empty — must be set)
API_QUERY_URL http://localhost:8080
CORS_ALLOWED_ORIGIN *
EVALUATOR_TICK_SECONDS 5 — how often the scheduler checks for due rules
EVALUATOR_CLAIM_BATCH_SIZE 1000 — how many due rules one tick can pull off the queue
EVALUATOR_WORKER_POOL_SIZE 20 — bounded concurrency for /query calls within a claimed batch
EVALUATOR_QUERY_TIMEOUT_SECONDS 30 — per-evaluation POST /query timeout

EVALUATOR_CLAIM_BATCH_SIZE and EVALUATOR_WORKER_POOL_SIZE are deliberately separate knobs, not the same number — see internal/config/config.go's doc comment for the real bug this separation fixes (found by hack/alert-load-test, see /docs/phase-3-runbook.md): with both capped at 20, 500 rules due at once took 125s to cycle through instead of the configured 60s.

Package layout

cmd/alerting/          wires config, Postgres pool, api client; runs the
                        HTTP server + evaluator + delivery worker concurrently (errgroup)
internal/httpapi/      REST handlers -- Handler/RegisterRoutes, same shape as api/internal/dashboards
internal/rulestore/    pgx CRUD for alert_rules + alert_state; ClaimDueRules
                        (fix 1's atomic claim) and ApplyTransition (fix 2's transactional outbox)
internal/notifystore/  pgx CRUD for notification_targets
internal/queryclient/  thin HTTP client to api's POST /query -- no querylang import here
internal/evaluator/    the ticker + worker pool; transitions.go is the pure,
                        exhaustively-tested ok/pending/firing state machine;
                        condition.go implements fixes 3/4 (errors never
                        coerced to "condition false"; threshold zero-rows
                        is an error, not a 0)
internal/delivery/     webhook.go is the claim-and-send worker (all three
                        kinds go through it); slack.go/pagerduty.go are
                        payload formatters only

Building & testing

go build ./...
go vet ./...
go test ./...
docker build -f Dockerfile -t cairnobs-alerting .   # context is alerting/, not the repo root -- no /proto needed