feat(ops): GitOps pipeline, incident management, cost optimization, backup verification - #1140
Merged
fejilaup-cloud merged 1 commit intoSep 28, 2026
Conversation
…ackup verification - AtomicIP#1069: Argo CD + Kustomize manifests (deploy/), PR-based production promotion, manifest validation with rendered diffs, rollback via git revert - AtomicIP#1068: incidents module with PagerDuty/Opsgenie integration, automatic incident creation from alerts and Alertmanager webhook, acknowledgment, timeline, postmortems; incident response docs and postmortem template - AtomicIP#1067: api-server HPA + PDB, orphaned data cleanup, compression and storage tiering, savings ledger, weekly cost report - AtomicIP#1066: automated restore tests with integrity, freshness and RTO checks, metrics and alerts on failure, backup strategy docs Closes AtomicIP#1066 Closes AtomicIP#1067 Closes AtomicIP#1068 Closes AtomicIP#1069
|
@knightqueen-sketch Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warning
Not tested — implementation only. None of these changes have been built, run or tested (no
cargo build/cargo test, nokustomize build, no script or workflow runs). Please review and test before merging.Closes #1066
Closes #1067
Closes #1068
Closes #1069
#1069 — GitOps deployment pipeline (Argo CD)
deploy/k8s/base(Deployment, Service, HPA, PDB) +overlays/stagingandoverlays/production(Kustomize)deploy/argocd/: AppProject (allow-list, production sync window), Applications with automated sync (prune,selfHeal),argocd-cmbuild options.github/workflows/gitops-promote.yml: merge to main builds the image and bumps staging;workflow_dispatchopens a PR that bumps production, and merging it deploys.github/workflows/gitops-validate.yml: renders and kubeconform-validates overlays, then posts the rendered diff on the PRscripts/gitops-rollback.sh: rollback viagit revertof the promotion commitdocs/gitops.md#1068 — Incident management integration
api-server/src/incidents.rs: PagerDuty (Events API v2) / Opsgenie integration (INCIDENT_PROVIDER), incident store with dedup, timeline, acknowledge/resolve (propagated to the provider and to the in-process alert pipeline to stop escalation), postmortems, MTTA/MTTR stats and metricscommitment_monitoring) and an Alertmanager webhook receiver (POST /v1/admin/incidents/alertmanager)/v1/admin/incidentswired into both routers inmain.rsalertmanager.yml:incident-trackerwebhook route andopsgenie-oncallreceiverdocs/incident-response.md,docs/postmortem-template.md#1067 — Cost optimization automation
scripts/ops/cost-optimize.sh: batched orphaned/expired data cleanup, zstd compression of rotated audit logs, lz4 for old partitions, S3 lifecycle tiering, savings ledger + Pushgateway metrics, Markdown cost reportdeploy/k8s/jobs) and weekly.github/workflows/cost-report.yml(adds AWS Cost Explorer spend)docs/cost-optimization.md#1066 — Automated backup verification
scripts/ops/backup-verify.sh: freshness (RPO) checks, SHA256 +pg_verifybackupintegrity, restore + WAL replay into a disposable Postgres, schema/row/amcheckvalidation, measured recovery time vs RTO, metrics, and a direct Alertmanager alert on failure.github/workflows/backup-verification.yml(opens an issue on failure)monitoring/prometheus/operations-rules.yml: backup, cost/autoscaling and Argo CD alertsdocs/backup-strategy.md; cross-links added todocs/disaster-recovery.md,monitoring/README.md,CHANGELOG.mdRequired setup (out of band)
Secrets:
KUBE_CONFIGis not needed (Argo CD pulls). Needed:PAGERDUTY_ROUTING_KEY/OPSGENIE_API_KEY,BACKUP_BUCKET,BACKUP_VERIFY_ROLE_ARN,COST_REPORT_ROLE_ARN,COST_LEDGER_URI,PUSHGATEWAY_URL,ALERTMANAGER_URL; anops-toolboximage with aws-cli, psql, jq, zstd and docker-cli.🤖 Generated with Claude Code