Postmortem lab
Test postmortems signals and thresholds
Metrics for actions_closed_on_time and recurrence_90d must distinguish bad input from component failure for EM facilitating review of INC-SUM-TOK-87.
1Learn the idea
Read
Golden signals for this system
Instrument blameless postmortem for tokenizer-induced summarization outage so EM facilitating review of INC-SUM-TOK-87 can answer: demand, errors, latency/age, saturation. Emit fields needed by actions_closed_on_time and recurrence_90d with bounded labels. Sample successful high-volume traces; keep errors and rollout transitions denser within policy.
Read
Alert path worth paging
Define at least one alert that would fire for INC-SUM-TOK-87, with a for/pending window that survives deploy blips. Missing scrape or missing revision labels must not look like health. Include a trace/log example id format you will actually search.
Read
Implementation artifact
{"incident":"INC-SUM-TOK-87","actions":3,"verified":1}
Read
Tests for telemetry
Add a unit/integration check that metrics increment on the happy path and on the action 'be more careful' with no owner — recurrence in 6 weeks branch. Store machine-readable output in CI artifacts when practical.
Read
Stage depth
Cardinality discipline: tenant and revision are usually enough; raw question text is not a label. Exemplars or trace links beat screenshots alone when debugging INC-SUM-TOK-87. Define who owns alert fatigue review. If you export to a vendor, record retention and access. Synthetic probes should use non-sensitive fixtures and still exercise summarization service. Practice the query you will type at 2am once, while calm.
Read
Field notes for `postmortem-lab` / `observability`
Document the exact PromQL or log query in the runbook stub for this service. Verify histograms have buckets around your SLO target. Add a canary synthetic check that exercises the oracle path every few minutes in staging. Confirm that PII redaction happens before export. Track build/version as a label on the golden signals. Delete noisy debug logs before they become accidental product dependencies. In this chapter the product is blameless postmortem for tokenizer-induced summarization outage, the human stakeholder is EM facilitating review of INC-SUM-TOK-87, and the incident id you design against is INC-SUM-TOK-87. Re-state the oracle in your notes — postmortem published with 3 actions; action A1 verified by test that fails on old tokenizer pin — and keep the invariant visible: actions are owned, dated, verifiable; contributing factors include process not only code. Track actions_closed_on_time and recurrence_90d as the scoreboard. Surface under change control: summarization service. If you only have forty minutes, finish the fixture for action 'be more careful' with no owner — recurrence in 6 weeks before polishing UI. Promotion language stays ternary: promote, hold, or roll back based on evidence, not hope.
Read
Extra rehearsal for Postmortem lab (observability)
Set a timer for twelve minutes and attempt only the observability concerns for Postmortem lab. Speak aloud what EM facilitating review of INC-SUM-TOK-87 would see on success versus on action 'be more careful' with no owner — recurrence in 6 weeks. Write three bullet artifacts you must keep: a fixture name tied to INC-SUM-TOK-87, a metric query for actions_closed_on_time and recurrence_90d, and the rollback or refuse command for summarization service. Then extend the notes with one sentence on how actions are owned, dated, verifiable; contributing factors include process not only code would be violated if you skipped this page. Close by restating the oracle in your own words without looking: postmortem published with 3 actions; action A1 verified by test that fails on old tokenizer pin.
Go deeper
Before you start
Why this matters
Name the dashboard row or log line EM facilitating review of INC-SUM-TOK-87 opens first during INC-SUM-TOK-87. It must include a correlation id and a bounded label from actions_closed_on_time and recurrence_90d. If telemetry is missing, write whether you promote, hold, or roll back — and why hold is the default.
Related lessons
Check your understanding
Page assessment
Answer from memory. Completion is saved from this evidence, not from opening the next page.
All responses are required.