fix(audit): 审计按账号 id 归属并记录来源 IP/UA,登录失败与限速入审计和指标,写入失败计数告警
This commit is contained in:
39 files changed
+794
-161
No files matched your search
@@ -144,3 +144,25 @@ spec:
|
||||
The audit log names the account (action auth.otp.locked); the owner was
|
||||
mailed. Unless they fumbled codes, someone is guessing at it
|
||||
(troubleshooting §17).
|
||||
- alert: FelisSignInFailures
|
||||
expr: sum(increase(felis_auth_failures_total[15m])) > 30
|
||||
for: 5m
|
||||
labels:
|
||||
severity: warning
|
||||
annotations:
|
||||
summary: "over 30 refused sign-ins in 15 minutes"
|
||||
description: >-
|
||||
Wrong codes, unknown addresses or bad passkey assertions well above people
|
||||
mistyping: someone is guessing or enumerating. `sum by (door, reason)
|
||||
(increase(felis_auth_failures_total[15m]))` shows where; the audit rows
|
||||
(action auth.<door>.failed) carry each caller's client_ip (troubleshooting §17).
|
||||
- alert: FelisAuditWriteFailing
|
||||
expr: increase(felis_audit_write_failures_total[15m]) > 0
|
||||
labels:
|
||||
severity: warning
|
||||
annotations:
|
||||
summary: "felis-api failed to write audit rows"
|
||||
description: >-
|
||||
The actions went through but their audit rows were lost. The felis-api log
|
||||
names each lost row (`audit: lost ...`); the usual cause is PostgreSQL
|
||||
being unreachable or out of disk.
|
||||
Reference in new issue
Block a user