You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A 30-run repository-wide fetch from the last 7 days produced an 18-run analysis set after enforcing the breadth cap and per-workflow limits. Within that sample, 15 runs showed firewall activity and 2 runs showed MCP session activity, but none of those runs contained the canonical raw observability files required for reliable post-incident debugging.
Recursive discovery under each selected run-<id>/ folder found no access.log files, no gateway.jsonl files, and no rpc-messages.jsonl files. Some runs still exposed derived summaries in summary.json and run_summary.json with firewall request counts and limited session counts, but those summaries are not a replacement for the raw artifacts needed to trace blocked egress decisions or individual MCP tool calls.
The most important operational consequence is simple: when a firewall-enabled run fails on network behavior, or when an MCP-enabled run fails inside tool orchestration, the downloaded artifacts currently do not preserve the raw evidence needed for root-cause analysis. This is a repo-wide observability gap, not an isolated workflow regression.
Key Alerts and Anomalies
🔴 Critical Issues:
PR Sous Chef run §31338952148 had derived firewall activity (64 requests) but no discoverable access.log.
Daily Project Performance Summary Generator (Using MCP Scripts) run §31335342952 had derived firewall activity (171 requests) but no discoverable access.log.
Copilot PR Prompt Pattern Analysis run §31335227689 had derived firewall activity (40 requests) but no discoverable access.log.
Cache directory setup run §31342423042 had derived firewall activity (72 requests) but no discoverable access.log.
PR Sous Chef run §31342278171 had derived firewall activity (26 requests) but no discoverable access.log.
Detection Analysis Report run §31341405042 had derived firewall activity (236 requests) but no discoverable access.log.
9 additional firewall-enabled runs in the analyzed set had the same missing-access.log condition.
Daily Project Performance Summary Generator (Using MCP Scripts) run §31335342952 showed MCP session activity (45 tool calls) but neither gateway.jsonl nor rpc-messages.jsonl was present.
Copilot PR Prompt Pattern Analysis run §31335227689 showed MCP session activity (10 tool calls) but neither gateway.jsonl nor rpc-messages.jsonl was present.
⚠️Warnings:
aw_info.json was absent from all 18 analyzed run folders, so firewall and MCP configuration could not be confirmed from the canonical metadata file.
safe_output.jsonl was absent from all 18 analyzed run folders; only high-level safe-output summaries were available when present.
Total access.log entries analyzed: 0 raw entries across 0 files
Derived firewall requests observed in summaries: 1762
Blocked requests observed in summaries: 0 (0.0%)
Domains observed in summaries: 16 unique
Most accessed derived domains: 151.101.0.223:443, 151.101.128.223:443, 151.101.192.223:443, 151.101.64.223:443, 167.82.48.223:443
Gateway Log Quality
Telemetry source: none of the MCP-enabled runs exposed gateway.jsonl or rpc-messages.jsonl
Total raw MCP entries analyzed: 0
Derived MCP session events from summaries: 169
Derived tool calls from summaries: 55
Derived failed tool calls from summaries: 0
Average response time: N/A because no raw gateway or RPC telemetry files were present
Additional Telemetry Artifacts
summary.json / run_summary.json: present in all 18 analyzed runs
agent-stdio.log: present in 15/18 analyzed runs
aw_info.json: present in 0/18 analyzed runs
safe_output.jsonl: present in 0/18 analyzed runs
Healthy Runs Summary
No analyzed run had complete raw observability coverage for the required firewall or MCP log artifacts.
Recommended Actions
Restore publication of raw Squid access.log artifacts for every firewall-enabled run, including workflow-call layouts, and validate the path in CI with a post-run assertion.
Restore publication of raw MCP telemetry (gateway.jsonl preferred, rpc-messages.jsonl acceptable fallback) for every run with MCP session activity, and fail the workflow when both files are absent.
Include aw_info.json and safe_output.jsonl in the downloaded artifacts so configuration and actuation can be audited without reconstructing behavior from summaries.
📊 Historical Trends
No prior retained observability baseline was available in the downloaded artifacts, so this report only establishes the current daily snapshot.
Report generated automatically by the Daily Observability Report workflow Analysis window: Last 7 days | Runs analyzed: 18
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Executive Summary
A 30-run repository-wide fetch from the last 7 days produced an 18-run analysis set after enforcing the breadth cap and per-workflow limits. Within that sample, 15 runs showed firewall activity and 2 runs showed MCP session activity, but none of those runs contained the canonical raw observability files required for reliable post-incident debugging.
Recursive discovery under each selected
run-<id>/folder found noaccess.logfiles, nogateway.jsonlfiles, and norpc-messages.jsonlfiles. Some runs still exposed derived summaries insummary.jsonandrun_summary.jsonwith firewall request counts and limited session counts, but those summaries are not a replacement for the raw artifacts needed to trace blocked egress decisions or individual MCP tool calls.The most important operational consequence is simple: when a firewall-enabled run fails on network behavior, or when an MCP-enabled run fails inside tool orchestration, the downloaded artifacts currently do not preserve the raw evidence needed for root-cause analysis. This is a repo-wide observability gap, not an isolated workflow regression.
Key Alerts and Anomalies
🔴 Critical Issues:
access.log.access.log.access.log.access.log.access.log.access.log.access.logcondition.gateway.jsonlnorrpc-messages.jsonlwas present.gateway.jsonlnorrpc-messages.jsonlwas present.aw_info.jsonwas absent from all 18 analyzed run folders, so firewall and MCP configuration could not be confirmed from the canonical metadata file.safe_output.jsonlwas absent from all 18 analyzed run folders; only high-level safe-output summaries were available when present.Coverage Summary
access.log)gateway.jsonlorrpc-messages.jsonl)📋 Detailed Run Analysis
Firewall-Enabled Runs
Missing Firewall Logs (
access.log)MCP-Enabled Runs
Missing MCP Telemetry (no
gateway.jsonlorrpc-messages.jsonl)🔍 Telemetry Quality Analysis
Firewall Log Quality
access.logentries analyzed: 0 raw entries across 0 filesGateway Log Quality
gateway.jsonlorrpc-messages.jsonlAdditional Telemetry Artifacts
summary.json/run_summary.json: present in all 18 analyzed runsagent-stdio.log: present in 15/18 analyzed runsaw_info.json: present in 0/18 analyzed runssafe_output.jsonl: present in 0/18 analyzed runsHealthy Runs Summary
No analyzed run had complete raw observability coverage for the required firewall or MCP log artifacts.
Recommended Actions
access.logartifacts for every firewall-enabled run, including workflow-call layouts, and validate the path in CI with a post-run assertion.gateway.jsonlpreferred,rpc-messages.jsonlacceptable fallback) for every run with MCP session activity, and fail the workflow when both files are absent.aw_info.jsonandsafe_output.jsonlin the downloaded artifacts so configuration and actuation can be audited without reconstructing behavior from summaries.📊 Historical Trends
No prior retained observability baseline was available in the downloaded artifacts, so this report only establishes the current daily snapshot.
Report generated automatically by the Daily Observability Report workflow
Analysis window: Last 7 days | Runs analyzed: 18
All reactions