No Description

jarvis 83a35bf48f docs: render existing Mermaid blocks as SVG + PNG 1 month ago
cmd bb8f155fea M13b W4: integration smoke + verification doc; fix 2nd cross-tenant leak 1 month ago
deploy 8f4f2b2cbc F2: publish-success counter + smoke assertion + NATS resource alerts 1 month ago
docs 83a35bf48f docs: render existing Mermaid blocks as SVG + PNG 1 month ago
gen aab63b3a45 M11(1/5): proto schema + buf codegen + Go stubs 1 month ago
internal bb8f155fea M13b W4: integration smoke + verification doc; fix 2nd cross-tenant leak 1 month ago
loadgen 39907d1ca3 fix(loadgen): main() exits when --duration expires, not just on SIGTERM 1 month ago
migrations 4c956fd086 M13b W3: Telegram bot CRUD (super_admin only, bot_token write-only) 1 month ago
proto aab63b3a45 M11(1/5): proto schema + buf codegen + Go stubs 1 month ago
scripts bb8f155fea M13b W4: integration smoke + verification doc; fix 2nd cross-tenant leak 1 month ago
testfakes bebd6a26a2 M8(2/3): smoke script + verification doc + 3 consecutive 12/12 green 1 month ago
web 4c956fd086 M13b W3: Telegram bot CRUD (super_admin only, bot_token write-only) 1 month ago
.env.example d066e01e5d M13a W4: docker-compose + bootstrap + E2E smoke (authd stack) 1 month ago
.gitignore b2c43653e3 M13b W0: SPA shell + embed into admind 1 month ago
ARCHITECTURE.md 8ca86628a1 feat(spec): add gRPC bidi-streaming as fourth ingest protocol (M11) 2 months ago
Dockerfile d066e01e5d M13a W4: docker-compose + bootstrap + E2E smoke (authd stack) 1 month ago
M0_VERIFICATION.md d76aa0b08d chore: shift app HTTP ports 8080-8083 to 8800-8803 (project rule) 2 months ago
M10_BENCH_VERIFICATION.md 9809827f62 M10(5/5): m10_bench_smoke.py + M10_BENCH_VERIFICATION.md (W5) 1 month ago
M10_PLAN.md 316400dea1 M10: detailed implementation plan (5 workstreams, 9 commits, ~4 sessions) 1 month ago
M10_SMOKE_LOG.md a915be15ff M10(4/5): runaway-source fault injection + W4 verification docs 1 month ago
M10_VERIFICATION.md a915be15ff M10(4/5): runaway-source fault injection + W4 verification docs 1 month ago
M11_NATS_INVESTIGATION.md fafba39e6c M11 NATS investigation: root cause + fix plan 1 month ago
M11_PLAN.md 6a4e99781c M11 plan: gRPC bidi-streaming ingest (proto + server + client + loadgen + smoke) 1 month ago
M11_VERIFICATION.md cbcb33b305 M11 + F2: SHIPPED with full self-defense 1 month ago
M12_PLAN.md 80879e915e M12 plan: K8s + multi-broker NATS, 50k/s ceiling 1 month ago
M13_API_CONTRACT.md 4c13c3fdb4 M13 (frontend admin) + M14 (security hardening) — planning 1 month ago
M13_FRONTEND_SPEC.md 4c13c3fdb4 M13 (frontend admin) + M14 (security hardening) — planning 1 month ago
M13_PLAN.md 4c13c3fdb4 M13 (frontend admin) + M14 (security hardening) — planning 1 month ago
M13a_PLAN.md fa843980e2 M13a W5: JWT gate on routerd / archiverd / deliverd-fcm / deliverd-telegram 1 month ago
M13a_W5_VERIFICATION.md fa843980e2 M13a W5: JWT gate on routerd / archiverd / deliverd-fcm / deliverd-telegram 1 month ago
M13b.dlog bb8f155fea M13b W4: integration smoke + verification doc; fix 2nd cross-tenant leak 1 month ago
M13b_PLAN.md 2cc3c273af M14: split into M14-backend + M14-ui, M14-backend runs before M13 1 month ago
M13b_VERIFICATION.md bb8f155fea M13b W4: integration smoke + verification doc; fix 2nd cross-tenant leak 1 month ago
M13c_PLAN.md 4c13c3fdb4 M13 (frontend admin) + M14 (security hardening) — planning 1 month ago
M14_SECURITY_PLAN.md 2cc3c273af M14: split into M14-backend + M14-ui, M14-backend runs before M13 1 month ago
M1_SMOKE_LOG.md af90a2cb4d M1(verified): live smoke test all 9 steps green + 6 compose/Dockerfile fixes 2 months ago
M1_VERIFICATION.md d5a211622a M1(8/8): M1 verification doc + SPEC update + PROMPT log 2 months ago
M2_SMOKE_LOG.md 280e0489de M2(3/3): verification doc + smoke log + smoke script + README/SPEC bump 2 months ago
M2_VERIFICATION.md 280e0489de M2(3/3): verification doc + smoke log + smoke script + README/SPEC bump 2 months ago
M3_SMOKE_LOG.md 692798a1a5 M3(3/3): M3 verification doc + smoke log + smoke script + README/PROMPT/SPEC bump 1 month ago
M3_VERIFICATION.md 692798a1a5 M3(3/3): M3 verification doc + smoke log + smoke script + README/PROMPT/SPEC bump 1 month ago
M4_SMOKE_LOG.md 75554256e1 M4(2/3): M4 verification doc + smoke log + smoke script + EMQX env-var refactor + ACL deploy README 1 month ago
M4_VERIFICATION.md 75554256e1 M4(2/3): M4 verification doc + smoke log + smoke script + EMQX env-var refactor + ACL deploy README 1 month ago
M5_SMOKE_LOG.md 49290cdf64 M5(2/3): M5 verification doc + smoke log + 7-step live smoke script 1 month ago
M5_VERIFICATION.md 49290cdf64 M5(2/3): M5 verification doc + smoke log + 7-step live smoke script 1 month ago
M6.5_SMOKE_LOG.md 223cb48e8c M6.5(2/3): M6.5 verification doc + smoke log + 5-step live smoke script 1 month ago
M6.5_VERIFICATION.md 223cb48e8c M6.5(2/3): M6.5 verification doc + smoke log + 5-step live smoke script 1 month ago
M6_SMOKE_LOG.md edad5a8992 M6(2/3): M6 verification doc + smoke log + 6-step live smoke script 1 month ago
M6_VERIFICATION.md edad5a8992 M6(2/3): M6 verification doc + smoke log + 6-step live smoke script 1 month ago
M7_SMOKE_LOG.md 4bf357efed M7(2/3)+(3/3): verification doc + smoke log + SPEC/PROMPT/README bump 1 month ago
M7_VERIFICATION.md 4bf357efed M7(2/3)+(3/3): verification doc + smoke log + SPEC/PROMPT/README bump 1 month ago
M8_SMOKE_LOG.md bebd6a26a2 M8(2/3): smoke script + verification doc + 3 consecutive 12/12 green 1 month ago
M8_VERIFICATION.md bebd6a26a2 M8(2/3): smoke script + verification doc + 3 consecutive 12/12 green 1 month ago
M9_SMOKE_LOG.md c09c8d9a3f M9(2.5/3): fill M9_SMOKE_LOG.md with live results (7/7 green on parres) 1 month ago
M9_VERIFICATION.md 94eda074f9 M9(2.5/3): add M9_VERIFICATION.md + M9_SMOKE_LOG.md 1 month ago
Makefile bb8f155fea M13b W4: integration smoke + verification doc; fix 2nd cross-tenant leak 1 month ago
PROMPT.md fe81973473 M8(3/3): PROMPT + README + SPEC bump to 'shipped 2026-06-14' 1 month ago
README.md d066e01e5d M13a W4: docker-compose + bootstrap + E2E smoke (authd stack) 1 month ago
SPEC.md fa843980e2 M13a W5: JWT gate on routerd / archiverd / deliverd-fcm / deliverd-telegram 1 month ago
broad-announce.dlog 70e1c6990d Adopt workspace .dlog deployment protocol 1 month ago
docker-compose.yml fa843980e2 M13a W5: JWT gate on routerd / archiverd / deliverd-fcm / deliverd-telegram 1 month ago
go.mod 8f221518b5 M13a W1: authd IdP (in-house JWT + refresh-token store) 1 month ago
go.sum 8f221518b5 M13a W1: authd IdP (in-house JWT + refresh-token store) 1 month ago
pnpm-workspace.yaml b2c43653e3 M13b W0: SPA shell + embed into admind 1 month ago

README.md

broad-announce

Multi-tenant notification router. Receives alerts from many source systems (HTTP/JSON webhooks, WebSockets, MQTT, gRPC bidi-streaming), normalizes them, resolves recipients via companiesgroupsindividuals + subscriptions, and delivers to FCM (Android), Telegram, SMS, email, voice, Slack, MS Teams, and arbitrary outbound webhooks.

Status: M0 + M1 + M2 + M3 + M4 + M5 + M6 + M6.5 + M7 + M8 + M11 + F2 + M13a + M14-backend W1 shipped 2026-06-17. M0 is the single-host docker-compose stack + 4 Go services + loadgen-http

  • alert schema. M1 is the end-to-end: signed webhook → broker → router → deliverd-fcm → fakefcmd (live-verified, 1530 deliveries in the loadgen burst, 0 failures). M2 is the recipient-resolution rules engine (source.allowed_targets + routing_rules + subscriptions with min_severity, quiet hours, inminent_colapse bypass; hard-fail on zero recipients). M3 is Telegram delivery + bot commands (deliverd split into per-channel binaries, telegramd long-polling bot with /start /subscribe /unsubscribe /preferences /status /mute /unmute, faketgmd fake Bot API, 14 deliveries in 8 sendMessage calls, 0 failures). M4 is MQTT ingest (EMQX 5.10.4 broker with per-source ACL on ba/<co>/<src>/incoming, ingestd's MQTT subscriber reuses the same ProcessAlert pipeline as HTTP, loadgen-mqtt publisher, 12 deliveries in 5-step smoke with 0 failures). M5 is WebSocket ingest (GET /v1/ingest/ws with {api_key} auth frame, 35-conn load test, per-IP cap 32) + live tail (GET /v1/tail/ws?token=***&company_id=... for operators, in-process pub/sub fan-out, 13/13 checks green across 3 consecutive smoke runs). M6 is dedupe + ×N display (sliding-window TTL via single Lua script, default 300s; dedupe runs before rate limit so duplicates are "free"; recipient sees (×N) inline suffix on the title; per-source dedupe_collapsed_total and dedupe_count_max_observed metrics, 11/11 checks green across 3 consecutive smoke runs). M6.5 is router-level dedupe collapse (a 100-alert burst produces 1 message to the recipient, not 100; the tail still sees the full storm; debounce with max-wait 2s, configurable via BA_ROUTERD_DEDUPE_FLUSH_MS; 9/9 checks green across 3 consecutive smoke runs). M7 is the data tier: deliveries becomes a Timescale hypertable with a 7-day retention policy, and a new archiverd service ships rows older than 7 days into ClickHouse (ba_archive.deliveries_archive MergeTree, 365-day TTL, plus a per-company daily SummingMergeTree MV for M9 dashboards); idempotent via pg_try_advisory_lock + FOR UPDATE SKIP LOCKED; m7_smoke.sh 4-step, 9-check green × 3 consecutive runs on the remote playground parres (192.168.44.94). M8 is the DLQ + replay UI: deliveries_dlq Timescale hypertable (7d retention, mirror of deliveries plus original_subject and discarded columns); in-process retry with bounded exp backoff (10 attempts, base 100ms, cap 2s, ~12s total wall clock for a fully failing target, env-driven via BA_DELIVERD_*); internal/dlq.Write() records the terminal failure; archiverd ships DLQ rows to ClickHouse ba_archive.deliveries_dlq_archive (2y TTL, longer than live's 1y because DLQ is forensic); admind exposes GET /v1/dlq (list/filter, 30d window), POST /v1/dlq/{id}/replay (re-publishes the original NATS envelope onto the original subject then marks the row discarded), POST /v1/dlq/{id}/discard (mark discarded, idempotent), and a minimal HTML UI at GET /dlq with filter form + inline replay/discard buttons; m8_smoke.sh 4-step, 12-check green × 3 consecutive runs on the local docker-compose stack. See M0_VERIFICATION.mdM8_VERIFICATION.md and M1_SMOKE_LOG.mdM8_SMOKE_LOG.md for the smoke tests. Spec is in SPEC.md, diagrams in ARCHITECTURE.md, build log in PROMPT.md.

v1 in one paragraph

Six Go services (ingestd, routerd, deliverd-fcm, deliverd-telegram, telegramd, admind) wired together by NATS JetStream. Postgres + Timescale for live data, ClickHouse for archive, Redis for dedupe + rate limits, EMQX for MQTT. Strict app-level multi-tenant isolation. ~5k alerts/sec on Docker Compose, 50k/sec design ceiling for v2 K8s.

Repo layout

SPEC.md             - requirements, entities, severity, retention
ARCHITECTURE.md     - diagrams, sequences, SLOs, capacity model
PROMPT.md           — build log, decisions, open questions
M0_VERIFICATION.md  — M0 smoke test (signed webhook → 202)
M1_VERIFICATION.md  — M1 smoke test (end-to-end → fakefcmd)
M2_VERIFICATION.md  — M2 smoke test (recipient resolution)
M3_VERIFICATION.md  — M3 smoke test (Telegram delivery + bot)
M4_VERIFICATION.md  — M4 smoke test (MQTT ingest + EMQX ACL)
M5_VERIFICATION.md  — M5 smoke test (WS ingest + live tail + per-IP cap)
M6_VERIFICATION.md  — M6 smoke test (dedupe + ×N + sliding TTL + free-for-dupes)
M6.5_VERIFICATION.md — M6.5 smoke test (router-level dedupe collapse)
M7_VERIFICATION.md  — M7 smoke test (Timescale 7d + ClickHouse archive)
M8_VERIFICATION.md  — M8 smoke test (DLQ + retry + replay UI)
M1_SMOKE_LOG.md     — M1 live run results
M2_SMOKE_LOG.md     — M2 live run results
M3_SMOKE_LOG.md     — M3 live run results
M4_SMOKE_LOG.md     — M4 live run results
M5_SMOKE_LOG.md     — M5 live run results (3 consecutive green)
M6_SMOKE_LOG.md     — M6 live run results (3 consecutive green)
M6.5_SMOKE_LOG.md   — M6.5 live run results (3 consecutive green)
M7_SMOKE_LOG.md     — M7 live run results (3 consecutive green, on parres)
M8_SMOKE_LOG.md     — M8 live run results (3 consecutive green, local)
docker-compose.yml  — single-host M0–M8 stack
Dockerfile          — multi-stage build for all 9 binaries (M0–M8 + archiverd + authd)
.env.example        — every BA_* knob documented
cmd/ingestd/        — HTTP POST handler (M0) + MQTT subscriber (M4) + WS ingest (M5) + dedupe before rate limit (M6); M11 = TLS
cmd/routerd/        — consumer (M0) + recipient resolution (M2) + M6.5 dedupe Collapser with max-wait debounce
cmd/routerd/        - M2 rules engine + M3 channel union
cmd/deliverd-fcm/   - M1 FCM HTTP v1 delivery + M8 retry + DLQ write
cmd/deliverd-telegram/ - M3 Telegram Bot API delivery + M8 retry + DLQ write
cmd/telegramd/      - M3 long-polling bot loop + command handler
cmd/admind/         - /v1/ping (M0) + /v1/dlq + /v1/dlq/{id} + /v1/dlq/{id}/{replay,discard} + /dlq HTML UI (M8); M13a W3 = JWT gate
cmd/archiverd/      - M7 hourly Timescale→ClickHouse archiver + M8 DLQ drain
cmd/authd/          - M13a W1: in-house multi-tenant auth IdP (JWT + refresh-token store)
internal/authd/     - M13a: JWT (HS256) + magic links + refresh-token CRUD + audit hooks
internal/auth/      - M14 W2: mTLS client cert verifier
internal/dlq/       - M8 deliveries_dlq writer
internal/retry/     - M8 bounded exp-backoff retry helper
loadgen/cmd/http/   - HTTP traffic generator (M0)
loadgen/cmd/mqtt/   - MQTT traffic generator (M4)
loadgen/cmd/ws/     - WebSocket traffic generator (M5)
internal/alert/     - Alert v1 type + Validate() + Severity.Rank
internal/broker/    - NATS JetStream wrapper
internal/config/    - env-driven config
internal/dedupe/    - 60s SET NX EX + INCR
internal/ratelimit/ - per-second INCR bucket
internal/httpserver/ - /health + /metrics scaffold
internal/observability/ - slog + Prometheus
internal/postgres/  - pgxpool wrapper
internal/routing/   - Resolver (M2 rules engine, M3 channel union)
internal/telegram/  - BotClient + command parser + handler
internal/store/     - Redis + (later) Postgres
deploy/prometheus/  - prometheus.yml
migrations/         - 001-004 + seed/seed_m2/seed_m3.sql
testfakes/          - fakefcmd (M1), faketgmd (M3)

License

Private. © 2026 Techno-World.