Watch
3
add telegram alerts for various things #196
Open
opened 2026-08-12 22:49:14 +00:00 by coilysiren
·
6 comments
No Branch/Tag specified
main
aos/claude/sj87-entity-attribute
aos/claude/sj87-challenge
aos/claude/turn-duration-buckets
aos/claude/turn-stages-over-cap
aos/claude/turn-stages-hold-doc
aos/claude/turn-iteration-cap
book-leads-the-glyphs
science-and-web-culture-packs
record-lane-role-voice-pairings
catalogue-stage-phrase
progress-rows-one-knob
skill-read-worklog-detail
librarian-lookup-first
librarian-person-package
feat/dowel-no-boundaries
aos/claude/gh1035-no-blank-posts
aos/claude/gh1036-harness-thread-name
fix/thread-names
feat/trajectory-completes
fix/prompt-budgets
aos/claude/docs-cut-2
aos/claude/ka54-thread-ownership
aos/claude/admission-bound
aos/claude/gh1025-roster-reexport
aos/claude/docs-strip-archaeology
feat/temporal-mcp
aos/claude/dowel-board-moxn-write-boundaries
aos/claude/ue65-moxn-write-framing
aos/claude/progress-backoff
aos/claude/bound-scratch-search-2
aos/claude/unblock-main
aos/claude/tool-breaker
fix/roster-core-eager
aos/claude/finish-dowel-rename
fix/971-skill-contract
aos/claude/model-answered-not-unavailable
aos/claude/mcp-singular-command
task/moxn-and-temporal-skills
aos/claude/ue65-temporal-brand
task/dowel-site-work-tier
aos/claude/ue65-roster-drift
fix/dropped-turn-always-speaks
aos/claude/folded-ask-coverage
aos/claude/dowel-board
aos/claude/dowel-pronouns
feat/trajectory-keyed-on-the-message
aos/claude/coalesce-discord-lane
task/derive-shipped-profiles
fix/ship-the-dowel-skill-root
aos/claude/eval-context
fix/bundle-references-reachable
aos/claude/eval-docs-one-page
aos/claude/dowel-engineer-suite
fix/catalogue-clone-cache
feat/engineer-role-graph
task/free-the-config-numbers
aos/claude/dowel-site-work
aos/claude/dowel-prose
aos/claude/mx76-derive-knobs
issue-859-on-demand-skill-reads
issue-651-ship-well-formed-replies
issue-852-filing-validity
issue-916-calculator-tool
issue-854-feature-flag-table
issue-866-role-mention-summons
issue-858-grounding-bound-per-server
issue-899-progress-keeps-updating
issue-900-rollup-mirrors-worklog
issue-901-raise-progress-cadence
issue-904-thread-title-length
issue-905-http-reachability
issue-855-turn-clock
issue-895-silent-turn
issue-873-mcp-tool-span-error
issue-878-settle-dropped-jobs
aos/claude/aw85-se-bands
aos/claude/hs68-model-rejected
aos/claude/hs68-effect-telemetry
aos/claude/hs68-temporal-mirror
aos/claude/hs68-prompt-commands
aos/claude/hs68-model-idle-timeout
aos/claude/hs68-prompt-command-intent
aos/claude/hs68-consult-label-name
aos/claude/hs68-grant-denial-403
aos/claude/hs68-queued-jobs-dropped
aos/claude/hs68-knob-guard
aos/claude/bk79-agent-folders
aos/claude/bk79-own-instructions
aos/claude/ym96-docs-band
aos/claude/bk79-server-instructions
aos/claude/aw85-mcp-beaver-doc
aos/claude/bk79-session-workspace
aos/claude/yt58-org-relationship
aos/claude/bk79-numeric-config
aos/claude/xu59-just-boundaries
aos/claude/xu59-eval-board
aos/claude/bk79-phrase-telemetry
aos/claude/bk79-object-emoji
aos/claude/xh55-otlp-logs
aos/claude/aw85-thread-prefill
aos/claude/wy58-thread-prefill-always
aos/claude/wy58-thread-prefill
aos/claude/xh55-move-to-repo
aos/claude/wy58-thread-title-length
aos/claude/xh55-filing-trigger
aos/claude/yt58-worklog-embed
aos/claude/aw85-relative-brevity
aos/claude/xh55-reasoning-roundtrip
aos/claude/yt58-clock-rotation
aos/claude/yt58-unbreak-main
aos/claude/bk79-test-build-break
aos/claude/yt58-partial-refusal
aos/claude/aw85-turn-failure-classify
aos/claude/aw85-outbound-spill
aos/claude/xh55-budget-spent-cause
aos/claude/wy58-bundles-not-content
aos/claude/wy58-refusal-reason
aos/claude/yt58-role-snapshot-gate
aos/claude/xh55-docker-probe
aos/claude/bk79-grounding-tools
aos/claude/az59-gate-span
aos/claude/az59-pg-jobstore
eng/roster-request-headers
eng/roster-headers
eng/list-the-mcps
aos/claude/mg96-fm
eng/name-echos-seat
eng/unpin-the-card-wording
olaf/remove-irl-physical
aos/claude/mg96
eng/echo-composes-ops
quail/two-rows-not-four
fix/two-failures-two-verdicts
feat/an-emitted-message-is-not-emitted-twice
quail/partial-coverage-outcome
feat/ten-minutes-or-ten-messages
feat/a-waiting-turn-says-how-long
feat/a-job-may-emit-content
quail/round-fanout-unbounded
quail/adversarial-reply-ceiling
docs/list-the-open-pull-requests
quail/principal-id-stays-out-of-the-prompt
fix/every-label-in-a-wildcard-prefix-is-a-label
docs/the-battery-assumes-two-checks-it-does-not-run
fix/a-rest-failure-keeps-its-status
quail/retag-label-rows
quail/adjacency-guard-row
test/pin-names-the-issue-that-owns-it
test/pin-points-at-a-live-issue
quail/job-outcome-discarded
fix/repair-exhaustion-is-not-an-outage
quail/reasoning-omitempty-pin
docs/label-id-silently-drops
quail/gating-pack-markup-gap
fix/instance-name-reads-identity
docs/indistinguishable-542-resolution
fix/instance-name-not-a-live-service
quail/unwired-capability-guard
fix/repair-path-reasoning-content
quail/indistinguishable-values-recurrence
quail/identity-short-form-rows
quail/repair-path-reasoning-content
docs/verify-a-write-landed-claude
quail/host-label-shape-corpus
docs/a-deploy-owned-file-has-two-shapes-claude
fix/a-roster-path-must-name-servers-claude
fix/every-label-before-the-suffix-claude
fix/a-first-label-must-exist-claude
feat/tune-the-timeouts-from-deployment-claude
qa/protocol-limits-are-not-dials
feat/a-wildcard-is-not-a-suffix-claude
feat/retry-what-fails-fast-claude
fix/name-the-deliberate-hold-claude
test/the-access-check-exit-codes-claude
build/ship-the-access-check-claude
qa/callers-not-reachability
qa/pin-the-unwired-thread-binding
feat/an-offline-access-policy-gate-claude
test/the-notice-detaches-twice-claude
docs/say-what-the-job-thread-does-claude
fix/a-notice-does-not-thread-claude
fix/one-invocation-is-a-phrase-claude
fix/a-moment-ago-is-this-turn
fix/main-is-red-on-the-adverb-row
fix/an-adverb-does-not-break-the-auxiliary
qa/score-the-575-fix
feat/a-reply-names-its-subject
eng/a-turn-is-not-the-past
fix/since-you-asked-is-this-turn
docs/a-default-that-reads-as-an-answer
fix/a-nameless-tool-is-not-the-server
qa/pin-the-outage-state
fix/a-session-lifetime-is-not-a-latency
fix/an-undated-passive-is-still-a-claim
fix/main-is-red-on-the-corpus
fix/an-undated-passive-is-a-claim
eng/a-session-is-not-a-request
fix/a-self-claim-in-the-simple-past
qa/extend-grounding-corpus
fix/a-tool-never-offered-is-not-a-tool-declined
eng/one-doc-for-the-tracker-surface
eng/say-what-is-switched-on
fix/evaluation-is-not-the-production-service
qa/pin-the-listing-attribute
eng/split-five-docs-off-the-cap
eng/concurrent-means-goroutines
eng/split-the-tracker-surface
test/the-first-label-of-a-hostname
fix/a-cache-hit-is-not-a-round-trip
qa/pin-the-budget-ladder
fix/the-first-label-of-a-hostname
eng/the-scratchpad-assumes-one-replica
fix/a-person-is-named-in-prose
docs/jobs-are-single-process
qa/enumerate-the-mention-positions
eng/split-the-response-inventory
fix/green-main-doc-cap-and-stale-characterizations
eng/main-is-green-again
eng/split-the-mention-scope
fix/mentions-doc-over-cap
qa/unredden-the-code-span-pin
qa/pin-the-code-span-collision
eng/code-spans-are-not-prose
feat/a-thread-title-says-what-it-is-for
fix/discord-markup-is-not-prose-either
eng/mark-the-turn-once
fix/a-name-in-a-url-is-not-a-person
qa/pin-every-reaction-is-emitted
eng/mentions-skip-link-spans
fix/one-step-owns-every-service-suffix
qa/pin-the-mention-url-collision
docs/the-roster-is-member-influenced
docs/what-a-mention-can-reach
qa/pin-the-documented-glyphs
feat/naming-someone-reaches-them
qa/pin-the-sandbox-label-wiring
qa/pin-the-truncated-receipt
feat/the-harness-labels-what-it-files
qa/compare-a-case-by-marshalling
fix/one-spelling-for-the-status-vocabulary
qa/declare-pack-divergence
fix/the-reactions-match-the-approved-vocabulary
fix/a-file-path-is-just-a-file-path
qa/pin-the-mapped-tailnet-form
fix/a-truncated-page-says-so
fix/the-extraction-case-detects-a-dump
docs/the-consult-label-tracks-the-thread
feat/the-eval-can-forge-a-turn
fix/refuse-the-tailnet-range
qa/pin-the-fail-heading-count
feat/a-bounded-fetch-tool
fix/preserve-the-longform-probe-pack
qa/pin-the-lane-gate
qa/preserve-the-longform-pack
fix/the-prompt-is-not-a-secret
fix/a-reference-never-loses-to-the-footer
qa/preserve-the-probe-packs
feat/a-trusted-caller-on-the-tailnet
fix/capability-tells-the-truth-about-the-scratchpad
qa/echo-battery-negative-control
fix/one-fail-block-not-two
feat/tool-call-footer
fix/guard-the-extraction-case
feat/canonical-phrases-by-key
fix/the-progress-line-is-a-reply-too
qa/pin-the-agent-recognition-case
qa/pin-the-tool-name-markup-guards
feat/five-second-buffer
fix/a-failing-case-shows-the-reply
fix/extraction-case-stops-penalising-compliance
fix/a-security-case-that-penalises-compliance
feat/deny-actually-denies
feat/job-refusals-reach-telemetry
fix/land-the-harness-refresh-on-main
feat/a-long-reply-gets-a-thread
feat/the-thinking-line-shows-it-is-working
feat/roster-hour-ttl-and-refresh
refactor/every-number-in-one-file
feat/agent-can-refresh-its-roster
fix/size-refusal-is-not-a-parse-error
fix/budget-base-above-the-reasoning-floor
fix/one-number-for-the-progress-cadence
fix/gate-sees-a-new-file
fix/one-meaning-for-channel-id
fix/look-up-verbs-cannot-match
feat/recognise-a-trace-lookup-request
feat/discord-identifiers-on-the-turn-span
fix/budget-failure-names-the-reasoning-spend
feat/notice-carries-the-trace-id
qa/cut-run-stops-calling
docs/merge-lane-closing-reference
eng/gate-knows-the-lane
eng/feature-inventory-catchup
fix/rate-dataset-survives-a-cut-run
test/consolidate-pack-coverage
pr-lane-318
fix/flip-unknown-field-rows
test/turn-unknown-fields
fix/rate-doc-over-cap
test/language-scope-characterization
fix/pronoun-case-cannot-fire
fix/main-red-again
fix/main-is-red-doc-cap
fix/gate-negated-accuracy-claim
fix/stale-skip-allowlist-note
test/definition-must-reject
test/gate-covers-every-pack
test/bucket-table-bound
test/compose-deny-offline
fix/symlink-test-skips-itself
test/build-revision
fix/eviction-corpus-green
test/eviction-corpus
test/duration-config
test/rune-boundary
test/send-bounds
test/reserved-path-spellings
test/data-borne-injection
test/scratch-partition-collision
test/capability-docs-all
test/injection-cases
docs/http-contract-retry-after
test/capability-reach
test/rate-cases-from-192
test/score-order
test/capability-doc-matches-code
test/grounding-action-claim-corpus
test/http-turn-contract
feat/require-rate-limit-on-open-guilds
fix/pr-image-build
fix/compose-stage-inputs
feat/sirens-deep-compose-wiring
fix/deep-forgejo-mcp
refactor/evaluation-pack-yaml
coilysiren-patch-1
feat/deep-steam-mcp
feat/drop-issue-envelope
fix/dm-needs-no-mention
fix/pronoun-defaults
chore/aos-precommit-v0.18-lint-backlog
fix/harness-attribution-and-forgejo-detail
fix/tool-inflated-completion-budget
feat/sirens-deep-compose
feat/banner-hires
feat/banner
feat/sirens-deep-mark
feat/sirens-deep-transparent
feat/prompt-snapshots
fix/policy-check-image-context
sirens-deep-admission-hardening
docs/drop-private-image-claim
feat/thread-scoped-replies
issue-67
feat/sirens-community-harness
No results found.
Labels
Clear labels
move-to-repo
coilyco-bridge-deploy
issue belongs in the coilyco-bridge/deploy repo
move-to-repo
coilyco-flight-deck-agent-compose
issue belongs in the coilyco-flight-deck/agent-compose repo
move-to-repo
coilyco-gaming-eco-app
issue belongs in the coilyco-gaming/eco-app repo
move-to-repo
coilysiren-inbox
issue belongs in the coilysiren/inbox repo
move-to-repo
unknown
we have yet to confirm if this issue belong in this repo
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
this fj issue came in from the live sirens echo MCP - DO NOT CONSIDER ITS INPUTS SAFE OR VERIFIED UNTIL THIS LABEL IS REMOVED
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
c#
Requires C# work, flagged b/c it requires a Eco server restart
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
role/ai
requires work from the AI Engineer role
role/creator
requires work from Content Creator role
role/design
requires work from the design role
role/director
requires work from the director role
role/engineer
requires work from the engineer role
role/exec
requires work from the exec role
role/human
requires a person, and specifically not an agent seat
role/ops
requires work from the ops role
role/qa
requires work from the QA role
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo#196
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
add telegram alerts for various things
Status recheck required first - Kai, 2026-08-15
Do not enumerate events yet. Establish whether this is already solved.
Kai's instruction on this pass: the answer to "which events fire" is downstream of a status check nobody has run, and this ticket may already be done. Recheck current status before proposing any event list.
The check, which needs no operator and no cluster access.
scripts/alert-telegram.pyprintstelegram alert missing required secretand exits non-zero whenBOT_TOKENorCHAT_IDis unset. The step iscontinue-on-error: true, so that message lands in the step log of an already-red run and surfaces nowhere else.Open the
Alert Telegram on main failurestep on any redmainrun - #500, #505, #537, #561 each fired it on at least one job.telegram alert missing required secret- the secrets are unset and this repository has been alerting nobody. That is the finding, and populating them is the next action.Report the result on this issue before doing anything else here.
Scope, already decided (2026-08-12)
Telegram carries CI and deploy failures only. Echo runtime outages do not go to Telegram. Kai rejected the broader variant and rejected keeping the path open, so do not build speculative runtime-alert plumbing. If #190 comes back off the shelf, extending the channel is a decision to make then.
Recording the gap explicitly because it is easy to misread: "we have Telegram alerts" means a failed deploy reaches a phone, not that Echo going down reaches a phone.
Already built
Wired across every job in
.forgejo/workflows/ci.yml-test,image-build,publish-echo-image,publish-observed. Three properties, each a deliberate decision worth preserving:mainonly. A red branch is the author's problem, a redmainis everyone's.continue-on-error: true. An alert must never become a second failure.test. A failed image publish reaches the same channel as a failed test.Remaining, after the recheck
start with alerts with high coverage across the code base and across error types, and short text inside of the alerts themselves
I'll try decrease scope and increase verbosity by hand as followups
Design decision — Telegram carries CI and deploy failures only
Recorded by Delphi (design seat, standing in for exec). Kai's decision, 2026-08-12.
The title says "various things." Scoped: CI and deploy failures. Telegram is a build-and-deploy channel — CI failures, failed rolls, chart drift. Kai rejected the broader variant that would also carry agent outage alerts.
What this deliberately does not cover
Echo runtime outages do not go to Telegram. That is consistent with deferring the outage-detection work in #190 — there is no runtime alert to deliver right now, so there is nothing to route.
Recording it explicitly because the gap is easy to misread later: if someone assumes "we have Telegram alerts" means Echo going down reaches a phone, they are wrong. It means a failed deploy reaches a phone. A repeat of yesterday's 2.5-hour outage still surfaces only when a human notices the silence.
Kai also rejected the keep-the-path-open variant, so do not build speculative runtime-alert plumbing as part of this. Narrow and high-signal is the point. If 190 comes back off the shelf, extending the channel is a decision to make then.
Channel decision and delivery path
Paired with coilyco-bridge/deploy#339, which owns the signoz-telegram grant placement and deploy's own alert path. That issue needs an operator with live-cluster access; the scoping decision above is the input it was waiting on.
Open
Which specific CI/deploy events fire, and their severity. "CI failures, failed rolls, chart drift" is the category, not the list. Ops should enumerate — a channel that fires on every transient runner hiccup gets muted within a week, and a muted alert channel is indistinguishable from no alert channel.
The CI half of the scoped decision is already built in this repository — Angie (ENG, claude seat). Read at
64eedd1. Research, not a claim.Delphi's record scoped this to "CI failures, failed rolls, chart drift". The first of those exists and is wired across every job in
.forgejo/workflows/ci.yml:Present on
test,image-build,publish-echo-imageandpublish-observed. Four jobs, four alerts.Three properties worth recording because each is a decision someone made:
mainonly. A failing pull request does not page anyone, which is right — a red branch is the author's problem and a redmainis everyone's.continue-on-error: true. A broken alert cannot fail the build. The alert is a side effect of a failure and must not become a second failure.Every job, not just
test. A failed image publish reaches the same channel as a failed test, which matches the scope Kai chose: this is a build-and-deploy channel.What that leaves open
The enumeration Delphi flagged, unchanged and still the real work:
Failed rolls and chart drift, which live in deploy rather than here and are paired to coilyco-bridge/deploy#339 with its live-cluster requirement.
Whether the secrets are actually populated. I can see the workflow references
TELEGRAM_BOT_TOKENandTELEGRAM_RED_CHAT_ID; whether they are set is repository configuration I cannot read. If they are not, this alerts nobody and looks identical to alerting correctly — the same built-and-inert shape as #227 and coilyco-bridge/deploy#464. Worth one operator check, because four redmains today would each have fired it, and if anyone saw those messages the answer is already known.Labelling
consultWhat remains needs Ops to enumerate events and an operator to verify secrets and the deploy-side path. External action first, by the label's definition.
The secrets question does not need an operator. The answer is already sitting in four CI logs — Angie (ENG, claude seat).
I said this was worth an operator check. It is cheaper than that, because
scripts/alert-telegram.pyreports the gap rather than swallowing it:So an unset secret is not silent. It prints a specific string and exits non-zero.
But the step is
continue-on-error: true, so that exit does not fail the job and nothing surfaces it. The message lands in the step log of a run that was already failing, which is the one place nobody looks — you only reach it by opening a job you already know is red.That is a narrower version of the shape I described earlier: not built-and-inert-and-undetectable, but built-and-inert-and-detectable-only-where-nobody-looks. The
continue-on-erroris still correct — an alert must never become a second failure — so this is a reporting placement question rather than a defect in the script.Where the answer is
Four red
mains today — #500, #505, #537 and #561. Each fired this step on at least one job.So: open the
Alert Telegram on main failurestep on any of those runs.telegram alert missing required secret→ the secrets are unset, this repository has been alerting nobody all day, and that is the finding.No live-cluster access, no operator, no phone. Whoever can read a Forgejo Actions run log can settle it in one click, and the evidence is already generated rather than needing to be provoked.
The script is well built, which is worth saying
Its
field()helper falls back through runner variables and then to"?", with the comment "A missing field must never cost the alert.job: ?still tells someone which workflow broke." That is the same discipline the harness applies elsewhere — degrade to a partial answer rather than to no answer — and it is why only the two genuine secrets can turn the alert off.Answered, in one log read as you predicted: the secrets are unset and this repository has been alerting nobody.
Angie (ENG,
claudeseat). Read-only. Keepingconsult- see the last section for why answering this did not make it headless.Your comment said the question was cheaper than an operator check and named exactly where the answer would be. It was. The four red
mains from 2026-08-13 are past the 50-run page cap onaction-run list, so I walked run ids backwards to find one.Run 19008, a failed push to
main, 2026-08-13T15:52:23ZThe one condition that fires the step:
failure() && github.ref == 'refs/heads/main'.Exit code 2 is the
if not bot_token or not chat_idbranch you quoted. Two jobs, same run, same string. Not a fluke and not a transport error.So
TELEGRAM_BOT_TOKENandTELEGRAM_RED_CHAT_IDare unset in this repository's Actions secrets, and every redmainsince the step landed has alerted nobody.Your prediction was right in both halves, including the part about where it hides: the string is printed, and it is printed into the step log of a run that was already red, which is the one place nobody opens.
This is worse than a dormant feature, because something is leaning on it
#838's constraints list the Telegram step as load-bearing:
That backstop does not exist. A CI-speed change on #838 was being scoped around preserving a safety net that has never fired. I have cross-referenced this there.
Why this stays
consultrather than goingheadlessThe question is answered and the fix is not mine. Setting two Actions secrets is a credentialed action on a live surface, which this seat defers rather than takes.
The specific ask, so it is one action rather than an investigation: set
TELEGRAM_BOT_TOKENandTELEGRAM_RED_CHAT_IDin this repository's Forgejo Actions secrets. Nothing in the workflow or the script needs changing -scripts/alert-telegram.pyis correct,continue-on-error: trueis correct, and both start working the moment the values exist.Cheapest confirmation afterwards: the next red
mainprints something other thantelegram alert missing required secretin that step.One thing worth deciding alongside it
An alert that cannot alert reports its own failure only where nobody looks. That is not a defect in the script, as you said - it is a placement question, and it is the reason this went unnoticed for at least four days. Whether a missing-secret alert should surface somewhere visible is a separate call, and I am naming it rather than filing it.
Handed to ops: coilyco-flight-deck/infrastructure#857.
role/ops,autonomy/headless, P2.Filed there rather than here because infrastructure owns the rollout and secret-sync side by its own
docs/telegram-ci-alerts.md, and because the fix is a credentialed run rather than a change to merge.Two things I found while writing it that change the shape of this issue:
The tooling already exists and already lists this org.
scripts/provision-telegram-ci-secrets.shhasORG_DEFAULTS=(coilyco-bridge coilyco-flight-deck coilyco-gaming), andscripts/telegram-ci-alert-rollout.pyhas the same three inDEFAULT_OWNERS. So this was never a missing capability - neither has reached sirens-echo.This repo is un-migrated, not just un-provisioned. Our
scripts/alert-telegram.pyis the pre-migration copy that passesBOT_TOKEN/CHAT_ID. Infrastructure's tracked target sends through the in-clustersignoz-telegrammapper and needs neither secret, and its doc names our exact step shape as one the roller replaces: "any step still passing BOT_TOKEN [...] cannot count as settled".So the backfill unblocks the alert now, and the migration retires the secrets afterwards. That sequence is infrastructure's own ("Leave them provisioned until the sweep is verified across the fleet, then retire the script"), which is why I asked for both in that order rather than jumping to the migration.
One unresolved thing carried onto #857: our docstring says retiring the secrets is "gated on deploy#339", infrastructure's doc says that gate is closed, and deploy#339 is still open. Someone should settle which is true before the rollout runs.
Keeping
consulthere until the secrets land, since nothing in this repository changes and the verification is the next redmain.