Repository navigation
[observability] Observability Coverage Report - 2026-08-02 #49681
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Daily Observability Report for AWF Firewall and MCP Gateway. A newer discussion is available at Discussion #49870. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive Summary
I reviewed a capped sample of 20 workflow runs from the last 7 days. Coverage is complete for the one firewall-enabled run and the one MCP-enabled run in the sample, so there are no critical missing-log gaps.
The main issue is log quality, not absence: the firewall run has a usable
access.log, but it only shows allowed traffic and proxy noise, with no blocked sample to validate denial-path observability. The MCP run has valid telemetry via the canonical fallbackrpc-messages.jsonland shows healthy JSON-RPC traffic.Key Alerts and Anomalies
No critical issues detected.
🔴 Critical Issues:
run-30724324732(Daily Documentation Healer) has firewall telemetry, butaccess.logcontains 179 lines with 90 allowed tunnels, 0 blocked requests, and 89NONE_NONE:HIER_NONEnoise entries. That is usable, but it does not exercise the blocked-request path.Coverage Summary
access.log)gateway.jsonlorrpc-messages.jsonl)📋 Detailed Run Analysis
Sample Run Status
Firewall-Enabled Runs
Missing Firewall Logs (
access.log)MCP-Enabled Runs
rpc-messages.jsonlMissing MCP Telemetry
🔍 Telemetry Quality Analysis
Firewall Log Quality
/tmp/gh-aw/aw-mcp/logs/run-30724324732/sandbox/firewall/logs/access.logaccess.loglines analyzed: 179api.anthropic.com:443,o205451.ingest.us.sentry.io:443,otlp-gateway-prod-eu-west-2.grafana.net:443Gateway Log Quality
rpc-messages.jsonlfallback/tmp/gh-aw/aw-mcp/logs/run-30724324732/mcp-logs/rpc-messages.jsonlsafeoutputsrpc-messages.jsonlHealthy Runs Summary
Daily Documentation Healerhad the only firewall-enabled and MCP-enabled run in the sample, and both telemetry sources were present.Recommended Actions
access.logcollection enabled for every firewall-backed run, and ensure at least one blocked request is generated in test coverage so denial-path debugging is observable.gateway.jsonlfor MCP telemetry when available, but keeprpc-messages.jsonlas a valid fallback and ensure it remains written on every MCP-enabled run.📊 Historical Trends
No multi-day trend comparison was derived from this sample.
Report generated automatically by the Daily Observability Report workflow
Analysis window: Last 7 days | Runs analyzed: 20
All reactions