Repository navigation
feat: isolate logs and jobs by resolved scope (#17) - #45
Conversation
Stamp ingestion jobs and filter every service read/write, including baseline comparison, so one incident cannot contaminate another. Closes #17 Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Keep lint clean on files touched for G8 so CI ruff check passes. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Review — PR #45 (G8 scope isolation)G8 isolation is implemented correctly on the paths that matter: migration Must-fix(None) Should-fix
Nice-to-have
VerdictNeeds changes (must-fix and/or should-fix remain) |
A shared key is still global (PK on key only). Replaying it when the stored job's scope differs from the caller now returns 409 instead of another tenant's job ids. Tail/GET lookups use the scope column; resume jobs are rejected across scopes. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Review — PR #45 (G8 scope isolation, round 2)Round 1 should-fix is actually fixed. Issue #17 acceptance holds:
Must-fix(None) Should-fix(None) Nice-to-have
VerdictReady to merge (0 must-fix, 0 should-fix) |
Closes #17
Summary
A shared service must not let one incident's logs contaminate another's baseline or analysis. This adds G8 scope isolation: every service read and write is stamped and filtered by a resolved scope, including baseline comparison.
Keys are pinned by default;
--allow-scope-overridelets a caller pass an explicit request scope. CLI stays optional and defaults todefault. A service request with no resolvable scope returns400 SCOPE_REQUIRED.Data model
Migration
0008_scope_isolation:ingestion_jobs.scope(existing rows →default)log_entries:(scope, timestamp)and(scope, service, environment, fingerprint)(existing indexes kept)api_keys.allow_scope_override(default false / pinned)Behavior
scopeordefault(existing TestClient tests keep working)SCOPE_MISMATCHSCOPE_REQUIRED--scopeTests
tests/unit/test_scope.pycovers resolution, SQL compile isolation, and TestClient pin/override/list isolation.python -m pytest tests/unit/passed locally (641).Deferred
scope="default"(no invented claims)cluster_runs/explanationstables are not scope-columned; explain cache key now includes scope