trim: reduce Liveboard to its core observability pipeline - #10
Merged
Merged
Conversation
Drops the whole tracing feature: the /traces dashboard page and its three components, the /v1/spans ingest route, the /v1/traces query route, the spans table and its RLS policy, and the span buffer/wire types in the JS SDK. Request events keep their trace_id as a plain correlation id that the SDKs still propagate via the x-trace-id header.
Removes the Fastify plugin, the Django middleware and the Flask extension, along with the machinery only they used: the SDK's sync (threaded) event buffer, the sync HTTP sender, and the Django/Flask route-pattern normalisers. Package manifests drop the corresponding extras and peer deps.
Drops the /alerts dashboard page and rule list, the /v1/alert-rules, /v1/alert-history and /v1/channels routes, the alert-evaluator worker loop and its Slack/Discord/PagerDuty/webhook delivery module, and the alert_rules, alert_history and alert_channels tables. Incidents are untouched: the z-score anomaly detector still writes them and the overview panel still renders them. The worker now runs three loops instead of four.
Drops /status/[slug] and its preview page, the five status components, the /v1/public/status/* routes, the /v1/services uptime query, the Resend email module and the double opt-in subscriber table, plus the status-page toggle in project settings and the slug-minting internal route. The anomaly detector still creates and publishes incidents; it just no longer emails status-page subscribers about them.
Keeps the sortable per-route table with p50/p95/p99, error rate and health score, plus route search and the method filter. Drops the detail drawer, the two-endpoint comparison mode, the latency histogram, and the approximate status-range/latency-threshold filters that went with them. The /v1/endpoints query is unchanged.
The alert-rules, alert-channels and status-page migrations are gone, so multitenancy/api_keys/rls move down to 002/003/004 and their revision pointers follow. Single head, no gaps: 001 -> 002 -> 003 -> 004.
python-jose and passlib were never imported — API-key auth uses hashlib + hmac.compare_digest, and browser sessions are NextAuth's job — so they only inflated the image.
Features table, screenshots, SDK section, architecture diagram and project tree now describe what actually ships: live dashboard, endpoint explorer, z-score anomaly detection with AI summaries, realtime over Socket.io/SSE, and multi-tenancy with RLS. Tracing, alert rules and public status pages move to the roadmap. Also drops a stale reference to the status-page BFF route from the verifyProjectAccess doc comment.
ryzrr
force-pushed
the
trim/slim-feature-set
branch
from
September 7, 2026 19:10
92cda32 to
ab0006b
Compare
NEXT_PUBLIC_LIVEBOARD_API_KEY and NEXT_PUBLIC_WS_URL are read by no code — the socket client derives its URL from NEXT_PUBLIC_API_URL, and dashboard reads go through the BFF with a session, never an API key. Compose was still passing both as build args, so Dockerfile.frontend baked them in as NEXT_PUBLIC_* env, i.e. a raw project ingest key shipped in the client bundle. Dropping the plumbing removes that exposure.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Cuts ~37% of the codebase (5,039 lines, 34 files) so the project's surface area matches its core story: ingest → Redis Streams → TimescaleDB → live dashboard, with anomaly detection and multi-tenancy on top.
Removed
/tracespage, flame graph, span detail, service map,POST /v1/spans,GET /v1/traces, thespanstable and its RLS policy. Events keeptrace_idas a plain correlation id the SDKs still propagate viax-trace-id./alertspage, rule list,/v1/alert-rules,/v1/alert-history,/v1/channels, the alert-evaluator worker loop, the Slack/Discord/PagerDuty/webhook delivery module, and thealert_rules/alert_history/alert_channelstables./status/[slug]and its authenticated preview, the five status components,/v1/public/status/*, the/v1/servicesuptime query, the Resend email module,status_subscribers, and the status-page toggle in project settings.python-jose,passlib(never imported — API-key auth useshashlib+hmac.compare_digest).Kept
XADD/ consumer groups, aggregation worker bulk-writing to TimescaleDB viaasyncpgCOPYLast-Event-IDresumellama-3.3-70bincident summariesNotes
docker compose down -v.main's history — each is restorable withgit checkout main -- <paths>.next build,tsc --noEmit,eslint --max-warnings 0,ruff checkon the API and Python SDK, andtsc --noEmiton the JS SDK all pass.