Repository navigation
[observability] Observability Coverage Report - 2026-10-04 #65447
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Daily Observability Report for AWF Firewall and MCP Gateway. A newer discussion is available at Discussion #65685. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive Summary
This daily observability audit analyzed a representative capped set of 20 recent workflow runs from the past week window (via one broad logs fetch). The sampled runs skew heavily toward failure outcomes, which is useful for debugging-readiness assessment.
A critical data-access issue affected this audit scope: run log directories downloaded by the MCP logs tool were present but not readable in this execution environment (
Permission deniedonrun-<id>directories). Because of that, file-level verification foraccess.log,gateway.jsonl, andrpc-messages.jsonlcould not be completed for the analyzed run set.Given the unreadable artifacts, observability coverage cannot be positively confirmed and is treated as a critical coverage gap for this report cycle. Remediation should prioritize artifact readability and post-download permission normalization so automated daily checks can validate telemetry health.
Key Alerts and Anomalies
🔴 Critical Issues:
/tmp/gh-aw/aw-mcp/logs/run-<id>are not readable (Permission denied), preventing validation of required firewall and MCP telemetry files.access.log, nor whether MCP-enabled runs includegateway.jsonlorrpc-messages.jsonlfallbackrpc-messages.jsonl.Coverage Summary
access.log)gateway.jsonlorrpc-messages.jsonl)📋 Detailed Run Analysis
Firewall-Enabled Runs
No runs could be positively classified as firewall-enabled because
aw_info.jsonand artifact trees were unreadable in all sampled runs.Missing Firewall Logs (access.log)
(Representative rows shown; same artifact-permission blocker affected all 20 analyzed runs.)
MCP-Enabled Runs
No runs could be positively classified as MCP-enabled due to unreadable artifact directories.
Missing MCP Telemetry (no gateway.jsonl or rpc-messages.jsonl)
(List indicates runs where telemetry could not be checked because artifacts were unreadable, not confirmed telemetry absence.)
🔍 Telemetry Quality Analysis
Firewall Log Quality
access.logentries analyzed: 0 (artifact read blocked)Gateway Log Quality
gateway.jsonl/rpc-messages.jsonlpath checks blocked by permissions)Healthy Runs Summary
No runs could be marked healthy because required telemetry files could not be inspected.
Recommended Actions
agenticworkflows logsartifact write path ownership/permissions so the report agent user can recursively readrun-<id>/contents.artifact_readable_runs / workflow_runs_analyzed) and alert when below 100% to prevent silent observability blind spots.📊 Historical Trends
Historical trend analysis is unavailable for this cycle due to artifact readability failure in the sampled run set.
Report generated automatically by the Daily Observability Report workflow
Analysis window: Last 7 days | Runs analyzed: 20
All reactions