Production monitoring lab
Validate outputs and schemas
Executable checks prove alerts require multi-window evidence; missing scrape ≠ healthy silence on fixtures — including the known misshape behind MON-TENANT-BLIND-9.
1Learn the idea
Read
Schema and policy checks
Add executable validation at the trust boundaries of Prometheus+Grafana board for AI answer API golden signals. Reject unknown fields where they matter, bound string sizes, and coerce only after auth/signature checks when raw bytes are security-relevant. Invariant under test: alerts require multi-window evidence; missing scrape ≠ healthy silence. A TypeScript type or Python annotation is not runtime validation — pair them with parsers.
Read
Golden and adversarial fixtures
Automate the fixtures from setup, including a recreation of MON-TENANT-BLIND-9. Assert both the visible error and the absence of side effects (no provider call, no queue write, no flag flip). Where metrics matter, assert label enums stay bounded.
Read
Implementation artifact
promtool check rules monitoring/answer-api.yaml
curl -sf localhost:8080/metrics | grep http_requests_total
Read
Gate semantics
Document which failures are client mistakes (4xx) versus operator/config mistakes (5xx/503). Oracle still stands: inject 5% 500s for 10m → Alert AnswerErrorBurn fires; recovery clears within 15m. Validation should make accidental “success with empty body” impossible for SRE watching error budget during a model bump.
Read
Stage depth
Property ideas: shuffled field order, Unicode edges, maximum-length strings, and replayed timestamps. Where money, identity, or citations matter, assertion messages should cite the field name. Do not snapshot entire provider payloads in tests; assert semantically. If validation fails open “to keep the demo working,” you have inverted the lab. Tie at least one CI job to the MON-TENANT-BLIND-9 fixture so main cannot regress silently. Re-read alerts require multi-window evidence; missing scrape ≠ healthy silence after each new parser — convenience helpers love to bypass it.
Read
Field notes for `production-monitoring-lab` / `validation`
Table-drive status codes and error codes so reviewers see coverage at a glance. Include a Unicode normalization case if user text is accepted. Verify that oversized bodies fail before CPU-heavy work. Where digests or versions are pinned, assert mismatch behavior. Keep golden files small enough to read in review. CI should fail on skipped tests that mark the incident fixture as xfail without a ticket link. In this chapter the product is Prometheus+Grafana board for AI answer API golden signals, the human stakeholder is SRE watching error budget during a model bump, and the incident id you design against is MON-TENANT-BLIND-9. Re-state the oracle in your notes — inject 5% 500s for 10m → Alert AnswerErrorBurn fires; recovery clears within 15m — and keep the invariant visible: alerts require multi-window evidence; missing scrape ≠ healthy silence. Track alert_precision on game-day ≥ 0.9 and scrape_up == 1 as the scoreboard. Surface under change control: GET /metrics. If you only have forty minutes, finish the fixture for dashboard averages hide tenant Acme 40% error rate before polishing UI. Promotion language stays ternary: promote, hold, or roll back based on evidence, not hope.
Read
Extra mastery block
For production-monitoring-lab, write a transfer example that differs in one constraint from the chapter scenario. Keep the quality bar fixed. Explain which check still applies.
Go deeper
Before you start
Why this matters
List three fixtures: one golden success, one schema/auth reject, and one regression for MON-TENANT-BLIND-9. For each, write the exact assertion (status, code, metric, or citation) that must turn red if broken.
In the wild
See how this idea shows up as a product and a company — then come back to the lesson. Skills transfer across vendors.
Related lessons
Check your understanding
Page assessment
Answer from memory. Completion is saved from this evidence, not from opening the next page.
All responses are required.