Skip to content

trim: reduce Liveboard to its core observability pipeline - #10

Merged
ryzrr merged 9 commits into
mainfrom
trim/slim-feature-set
Sep 8, 2026
Merged

ryzrr merged 9 commits into
mainfrom
trim/slim-feature-set

Conversation

@ryzrr

@ryzrr ryzrr commented Sep 7, 2026

Copy link
Copy Markdown
Owner

What this does

Cuts ~37% of the codebase (5,039 lines, 34 files) so the project's surface area matches its core story: ingest → Redis Streams → TimescaleDB → live dashboard, with anomaly detection and multi-tenancy on top.

Removed

Feature What went
Distributed tracing /traces page, flame graph, span detail, service map, POST /v1/spans, GET /v1/traces, the spans table and its RLS policy. Events keep trace_id as a plain correlation id the SDKs still propagate via x-trace-id.
Alert rules + delivery channels /alerts page, rule list, /v1/alert-rules, /v1/alert-history, /v1/channels, the alert-evaluator worker loop, the Slack/Discord/PagerDuty/webhook delivery module, and the alert_rules / alert_history / alert_channels tables.
Public status pages + email /status/[slug] and its authenticated preview, the five status components, /v1/public/status/*, the /v1/services uptime query, the Resend email module, status_subscribers, and the status-page toggle in project settings.
Endpoint explorer extras Detail drawer, two-endpoint comparison mode, latency histogram, and the approximate status-range/latency filters.
Extra SDK adapters Fastify plugin, Django middleware, Flask extension — plus the sync (threaded) buffer and sender only they used.
Dead dependencies python-jose, passlib (never imported — API-key auth uses hashlib + hmac.compare_digest).

Kept

  • Ingest pipeline: XADD / consumer groups, aggregation worker bulk-writing to TimescaleDB via asyncpg COPY
  • Realtime: Socket.io for metrics/incidents, SSE with Last-Event-ID resume
  • Rolling z-score anomaly detector — rate limit, dedup, and Cerebras llama-3.3-70b incident summaries
  • Multi-tenancy: organizations, memberships, per-project API keys, Postgres Row-Level Security
  • Session-scoped BFF proxy — the browser never holds a raw ingest key
  • Live dashboard (stat cards, charts, tailing request log, incident panel) and the endpoint table with p50/p95/p99

Notes

  • Migrations are renumbered into a gapless 001 → 004 chain (multitenancy / api_keys / rls keep their content). The schema changed, so a self-hosted instance should start from a fresh volume: docker compose down -v.
  • Removed features are listed on the README roadmap and remain in main's history — each is restorable with git checkout main -- <paths>.
  • Verified: next build, tsc --noEmit, eslint --max-warnings 0, ruff check on the API and Python SDK, and tsc --noEmit on the JS SDK all pass.

Drops the whole tracing feature: the /traces dashboard page and its three
components, the /v1/spans ingest route, the /v1/traces query route, the
spans table and its RLS policy, and the span buffer/wire types in the JS
SDK. Request events keep their trace_id as a plain correlation id that the
SDKs still propagate via the x-trace-id header.
Removes the Fastify plugin, the Django middleware and the Flask extension,
along with the machinery only they used: the SDK's sync (threaded) event
buffer, the sync HTTP sender, and the Django/Flask route-pattern
normalisers. Package manifests drop the corresponding extras and peer deps.
Drops the /alerts dashboard page and rule list, the /v1/alert-rules,
/v1/alert-history and /v1/channels routes, the alert-evaluator worker loop
and its Slack/Discord/PagerDuty/webhook delivery module, and the
alert_rules, alert_history and alert_channels tables. Incidents are
untouched: the z-score anomaly detector still writes them and the overview
panel still renders them. The worker now runs three loops instead of four.
Drops /status/[slug] and its preview page, the five status components, the
/v1/public/status/* routes, the /v1/services uptime query, the Resend email
module and the double opt-in subscriber table, plus the status-page toggle
in project settings and the slug-minting internal route. The anomaly
detector still creates and publishes incidents; it just no longer emails
status-page subscribers about them.
Keeps the sortable per-route table with p50/p95/p99, error rate and health
score, plus route search and the method filter. Drops the detail drawer,
the two-endpoint comparison mode, the latency histogram, and the
approximate status-range/latency-threshold filters that went with them.
The /v1/endpoints query is unchanged.
The alert-rules, alert-channels and status-page migrations are gone, so
multitenancy/api_keys/rls move down to 002/003/004 and their revision
pointers follow. Single head, no gaps: 001 -> 002 -> 003 -> 004.
python-jose and passlib were never imported — API-key auth uses hashlib +
hmac.compare_digest, and browser sessions are NextAuth's job — so they only
inflated the image.
Features table, screenshots, SDK section, architecture diagram and project
tree now describe what actually ships: live dashboard, endpoint explorer,
z-score anomaly detection with AI summaries, realtime over Socket.io/SSE,
and multi-tenancy with RLS. Tracing, alert rules and public status pages
move to the roadmap.

Also drops a stale reference to the status-page BFF route from the
verifyProjectAccess doc comment.
@ryzrr
ryzrr force-pushed the trim/slim-feature-set branch from 92cda32 to ab0006b Compare September 7, 2026 19:10
NEXT_PUBLIC_LIVEBOARD_API_KEY and NEXT_PUBLIC_WS_URL are read by no code —
the socket client derives its URL from NEXT_PUBLIC_API_URL, and dashboard
reads go through the BFF with a session, never an API key. Compose was
still passing both as build args, so Dockerfile.frontend baked them in as
NEXT_PUBLIC_* env, i.e. a raw project ingest key shipped in the client
bundle. Dropping the plumbing removes that exposure.
@ryzrr
ryzrr merged commit 4494d8d into main Sep 8, 2026
4 checks passed
@ryzrr
ryzrr deleted the trim/slim-feature-set branch September 8, 2026 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant