Skip to content

ops: add scheduled uptime and origin cert monitor - #4

Open
jalexspringer wants to merge 3 commits into
mainfrom
ops/uptime-monitor
Open

jalexspringer wants to merge 3 commits into
mainfrom
ops/uptime-monitor

Conversation

@jalexspringer

@jalexspringer jalexspringer commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

The hosted API (policycheck.openattribution.org) returned Cloudflare 525 for about four months. The Fly certificate couldn't renew while the hostname was proxied. Nothing alerted. The DNS side is fixed (_fly-ownership TXT plus the _acme-challenge CNAME). This PR adds the missing alerting.

Runs every 15 minutes:

  • API: POST /analyze for openattribution.org against the Fly origin. Fails on non-200 or on a result status other than success. Retries cover cold starts. On failure it logs headers and body.
  • CORS: preflight must return Access-Control-Allow-Origin. Without it, the page shows "Failed to fetch".
  • Origin certificate: reads the Fly certificate for policycheck.openattribution.org directly. Fails when fewer than 21 days are left. Fly renews at 30 days, so this catches a failed renewal about three weeks before it becomes a 525.
  • Keepalive: re-enables the workflow through the API. Without this, GitHub disables schedules in public repos after 60 days with no activity.

Why the origin and not the proxied hostname: Cloudflare returns 403 with cf-mitigated: challenge to GitHub runners, and a monitor can't solve a managed challenge. Once the proxied hostname stops challenging API traffic, add a check against it too.

Alerting: a failed scheduled run emails whoever last changed the cron line. During an outage that's one email per run. That's noisy, and deliberately so.

🤖 Generated with Claude Code

jalexspringer and others added 3 commits September 28, 2026 16:39
The hosted API returned Cloudflare 525 for about four months after
the Fly certificate failed to renew behind the proxy, and nothing
alerted. Check the API, CORS preflight and origin cert expiry every
15 minutes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Cloudflare serves a managed challenge to GitHub runners, so the
proxied hostname can't be checked from Actions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant