Skip to content

Commit 336e416

Browse files
authored
Merge pull request #947 from flashcatcloud/feat/alert-batch22-dev
docs: batch 22 integrations (NetBox, Nautobot, Infisical, HertzBeat, Vigil, Peekaping) to test
2 parents ff315d3 + 3877ebf commit 336e416

14 files changed

Lines changed: 1453 additions & 2 deletions

File tree

‎docs.json‎

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1708,6 +1708,7 @@
17081708
"zh/on-call/integration/alert-integration/alert-sources/trigger-dev",
17091709
"zh/on-call/integration/alert-integration/alert-sources/duplicati",
17101710
"zh/on-call/integration/alert-integration/alert-sources/robotalp",
1711+
"zh/on-call/integration/alert-integration/alert-sources/infisical",
17111712
"zh/on-call/integration/alert-integration/alert-sources/fivetran",
17121713
"zh/on-call/integration/alert-integration/alert-sources/coralogix",
17131714
"zh/on-call/integration/alert-integration/alert-sources/uptimeobserver",
@@ -1865,6 +1866,7 @@
18651866
"zh/on-call/integration/alert-integration/alert-sources/calibre",
18661867
"zh/on-call/integration/alert-integration/alert-sources/uptimia",
18671868
"zh/on-call/integration/alert-integration/alert-sources/clustercontrol",
1869+
"zh/on-call/integration/alert-integration/alert-sources/hertzbeat",
18681870
"zh/on-call/integration/alert-integration/alert-sources/nobl9",
18691871
"zh/on-call/integration/alert-integration/alert-sources/sevone",
18701872
"zh/on-call/integration/alert-integration/alert-sources/monitive",
@@ -1988,7 +1990,9 @@
19881990
"zh/on-call/integration/change-integration/pulumi",
19891991
"zh/on-call/integration/change-integration/harness-fme",
19901992
"zh/on-call/integration/change-integration/expo-eas",
1991-
"zh/on-call/integration/change-integration/env0"
1993+
"zh/on-call/integration/change-integration/env0",
1994+
"zh/on-call/integration/change-integration/netbox",
1995+
"zh/on-call/integration/change-integration/nautobot"
19921996
]
19931997
},
19941998
{
@@ -2033,6 +2037,8 @@
20332037
"pages": [
20342038
"zh/on-call/integration/alert-integration/alert-sources/image-upload",
20352039
"zh/on-call/integration/alert-integration/alert-sources/label-mapping-api"
2040+
"zh/on-call/integration/alert-integration/alert-sources/vigil",
2041+
"zh/on-call/integration/alert-integration/alert-sources/peekaping",
20362042
]
20372043
}
20382044
]
@@ -3321,6 +3327,7 @@
33213327
"en/on-call/integration/alert-integration/alert-sources/trigger-dev",
33223328
"en/on-call/integration/alert-integration/alert-sources/duplicati",
33233329
"en/on-call/integration/alert-integration/alert-sources/robotalp",
3330+
"en/on-call/integration/alert-integration/alert-sources/infisical",
33243331
"en/on-call/integration/alert-integration/alert-sources/fivetran",
33253332
"en/on-call/integration/alert-integration/alert-sources/coralogix",
33263333
"en/on-call/integration/alert-integration/alert-sources/uptimeobserver",
@@ -3478,6 +3485,7 @@
34783485
"en/on-call/integration/alert-integration/alert-sources/calibre",
34793486
"en/on-call/integration/alert-integration/alert-sources/uptimia",
34803487
"en/on-call/integration/alert-integration/alert-sources/clustercontrol",
3488+
"en/on-call/integration/alert-integration/alert-sources/hertzbeat",
34813489
"en/on-call/integration/alert-integration/alert-sources/nobl9",
34823490
"en/on-call/integration/alert-integration/alert-sources/sevone",
34833491
"en/on-call/integration/alert-integration/alert-sources/monitive",
@@ -3601,7 +3609,9 @@
36013609
"en/on-call/integration/change-integration/pulumi",
36023610
"en/on-call/integration/change-integration/harness-fme",
36033611
"en/on-call/integration/change-integration/expo-eas",
3604-
"en/on-call/integration/change-integration/env0"
3612+
"en/on-call/integration/change-integration/env0",
3613+
"en/on-call/integration/change-integration/netbox",
3614+
"en/on-call/integration/change-integration/nautobot"
36053615
]
36063616
},
36073617
{
@@ -3646,6 +3656,8 @@
36463656
"pages": [
36473657
"en/on-call/integration/alert-integration/alert-sources/image-upload",
36483658
"en/on-call/integration/alert-integration/alert-sources/label-mapping-api"
3659+
"en/on-call/integration/alert-integration/alert-sources/vigil",
3660+
"en/on-call/integration/alert-integration/alert-sources/peekaping",
36493661
]
36503662
}
36513663
]
Lines changed: 130 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,130 @@
1+
---
2+
title: "Apache HertzBeat Alert Integration"
3+
description: "Send Apache HertzBeat alerts and recoveries to Flashduty On-call through a Webhook notice receiver."
4+
keywords: ["alert integration", "Apache HertzBeat", "HertzBeat", "webhook", "notice receiver", "monitoring", "alert rules"]
5+
---
6+
7+
Use the Webhook type of a notice receiver under **Alarm Notification → Notice Receiver** in Apache HertzBeat to sync alert rule triggers (`firing`) and recoveries (`resolved`) to Flashduty On-call. Each alert rule on each monitored target maps to one Flashduty alert: it is created when the rule fires and closed automatically when it resolves.
8+
9+
<div className="hide">
10+
11+
## In Flashduty On-call
12+
---
13+
14+
Get the push URL in either of two ways.
15+
16+
### Use a dedicated integration
17+
18+
1. In the Flashduty console, select **Channels** and open a channel
19+
2. Select **Settings** → **Integration data** → **Dedicated integration**, then click **Add an integration**
20+
3. Select **Apache HertzBeat** and click **Save**
21+
4. Open the generated integration card and copy the **push URL**
22+
23+
### Use a shared integration
24+
25+
1. In the Flashduty console, select **Integration Center → Alert Events**
26+
2. Select **Apache HertzBeat** and enter an integration name
27+
3. Set the default route and pick a channel; you can add more rules under **Routes** after creation
28+
4. Click **Save** and copy the generated **push URL**
29+
30+
</div>
31+
32+
## Configure HertzBeat
33+
---
34+
35+
<Steps>
36+
<Step title="Add a notice receiver">
37+
38+
1. Log in to HertzBeat and go to **Alarm Notification → Notice Receiver → Add Receiver**
39+
2. Select **WebHook** as the notification method
40+
3. Paste the full Flashduty push URL into the callback address
41+
4. Save. You can click **Send test message** to check connectivity
42+
43+
</Step>
44+
45+
<Step title="Add a notice policy">
46+
47+
A new receiver gets no alerts by itself. Under **Alarm Notification → Notice Policy**, add a policy that selects the receiver and, if needed, the severities and labels to notify, then save.
48+
49+
</Step>
50+
51+
<Step title="Verify the lifecycle">
52+
53+
Make an alert rule fire (for example, stop a monitored port) and confirm Flashduty receives an active alert. When the rule condition no longer holds, HertzBeat sends a `resolved` notification and the Flashduty alert recovers automatically.
54+
55+
</Step>
56+
</Steps>
57+
58+
<Warning>
59+
Flashduty parses only the default Webhook template that ships with HertzBeat. If you edit the receiver's custom template, the body changes and Flashduty cannot guarantee it parses. Custom templates are not supported.
60+
</Warning>
61+
62+
## Payload
63+
---
64+
65+
HertzBeat POSTs the default template as JSON. One request can carry several alerts in `alerts`, and Flashduty handles each one:
66+
67+
| Field | Meaning | In Flashduty |
68+
| :--- | :--- | :--- |
69+
| `status` | `firing` or `resolved`, shared by the whole request | Trigger or recovery |
70+
| `alerts[].labels.alertname` | Alert rule name | Alert title, labels `check` and `alertname` |
71+
| `alerts[].labels.instance` | Monitored target | Labels `resource` and `instance` |
72+
| `alerts[].labels.defineid` | Alert rule ID | Label `defineid` |
73+
| `alerts[].labels.severity` | Severity defined in the rule | Alert severity, label `severity` |
74+
| `alerts[].content` | Alert content | Alert description |
75+
| `alerts[].annotations` | Annotations defined in the rule | Alert description, sorted by key, one `key: value` per line |
76+
| Other keys in `alerts[].labels` | For example `instancename` and custom rule labels | Labels of the same name |
77+
78+
`commonLabels` and `commonAnnotations` are not read.
79+
80+
## Alert Key
81+
---
82+
83+
The HertzBeat payload carries no alert ID. Flashduty builds the Alert Key from `alertname`, `instance` and `defineid` in `alerts[].labels`. In real HertzBeat 1.9.0 deliveries these three values were identical on trigger, repeated notification while firing, and recovery, so all three land on one Flashduty alert. Changing the severity, content or monitor name does not change the Alert Key.
84+
85+
A request without `labels.alertname` is rejected with a parameter error, because a recovery could not be tied to its alert. A missing `instance` or `defineid` counts as empty.
86+
87+
## Status and severity
88+
---
89+
90+
| HertzBeat field | Flashduty status or severity |
91+
| :--- | :--- |
92+
| `labels.severity` = `critical` | Critical |
93+
| `labels.severity` = `warning`, empty or any other value | Warning |
94+
| `labels.severity` = `info` | Info |
95+
| `status` = `firing` | Trigger or update the alert, severity from the table above |
96+
| `status` = `resolved` | Recovery; the alert keeps its severity |
97+
98+
A request with any other `status`, or an empty `alerts`, is rejected. In the default template `commonLabels.severity` is rewritten to decorated text (such as "Critical"), so it is not used for severity.
99+
100+
## FAQ
101+
---
102+
103+
<AccordionGroup>
104+
<Accordion title="What does Flashduty show after I click Send test message?">
105+
106+
The button sends a fixed firing request (rule name `CPU Usage Alert`, instance `127.0.0.1`, content starting with `test send msg!`). Flashduty returns HTTP 200 and opens a separate Info alert under its own Alert Key, so it never merges into a real alert. No recovery follows; close it by hand in the channel.
107+
108+
</Accordion>
109+
110+
<Accordion title="Does a long-firing alert create duplicates?">
111+
112+
No. HertzBeat resends `firing` while the alert stays active. The Alert Key is the same, so Flashduty merges them into one alert.
113+
114+
</Accordion>
115+
116+
<Accordion title="An availability alert did not close in Flashduty after the monitor came back?">
117+
118+
Flashduty recovers an alert only when HertzBeat sends `resolved`. In one test on HertzBeat 1.9.0, an availability alert was still firing several minutes after the monitor came back and sent no `resolved`, while a metric-threshold rule did. If you see this, check in the HertzBeat alert center whether the alert has recovered.
119+
120+
</Accordion>
121+
</AccordionGroup>
122+
123+
## Troubleshooting
124+
---
125+
126+
- **Flashduty receives no alerts**: confirm the URL is the full push URL (with `integration_key`), a notice policy exists, and the alert matches it
127+
- **Flashduty returns a parameter error**: confirm the body is the default HertzBeat template JSON, `status` is `firing` or `resolved`, and every alert has `labels.alertname`
128+
- **An alert does not recover**: confirm HertzBeat sent `resolved` and that its `alertname`, `instance` and `defineid` equal those of the trigger
129+
130+
For HertzBeat notification setup, see the official [Webhook notification](https://hertzbeat.apache.org/docs/help/alert_webhook/) guide.
Lines changed: 93 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,93 @@
1+
---
2+
title: "Infisical alert integration"
3+
description: "Send Infisical secret rotation failures and honey token triggers to Flashduty On-call through a project webhook."
4+
keywords: ["alert integration", "Infisical", "secrets management", "secret rotation", "honey token", "webhook"]
5+
---
6+
7+
Use an Infisical project webhook to send two kinds of security events to Flashduty On-call: a failed secret rotation (`secrets.rotation-failed`) and a triggered honey token (`honey-token.triggered`). Both create Critical alerts. Infisical sends no notification when a rotation later succeeds or when a honey token is dealt with, so these alerts do not recover on their own. Close them manually, or let the channel's auto-close timeout close them.
8+
9+
Secret modifications (`secrets.modified`), change requests, and access requests are not alerts. Flashduty returns success for them without creating an alert, and you can clear those events on the Infisical side.
10+
11+
<div className="hide">
12+
13+
## In Flashduty On-call
14+
---
15+
16+
You can get the integration Push URL in either of the following two ways.
17+
18+
### Use a dedicated integration
19+
20+
1. In the Flashduty console, select **Channels** and open a channel
21+
2. Select **Settings** → **Integrations** → **Dedicated integrations**, then click **Add an integration**
22+
3. Select **Infisical** and click **Save**
23+
4. Open the generated integration card and copy the **Push URL**
24+
25+
### Use a shared integration
26+
27+
1. In the Flashduty console, select **Integration Center → Alert Events**
28+
2. Select **Infisical** and enter an integration name
29+
3. Configure the default route and select a channel; you can add more rules under **Routes** after the integration is created
30+
4. Click **Save** and copy the generated **Push URL**
31+
32+
</div>
33+
34+
## Configure Infisical
35+
---
36+
37+
<Steps>
38+
<Step title="Create a webhook">
39+
40+
1. Open the Infisical project, go to **Project Settings → Webhooks**, and click **Add Webhook**
41+
2. Set **Type** to **General**
42+
3. Set **Environment** to the environment to watch. One webhook covers one environment, so create one per environment you want to monitor
43+
4. Set **Secret Path** to `/**` to cover every folder in that environment. `/` alone matches only the root folder, so a rotation configured in a subfolder would not trigger it
44+
5. Paste the complete Flashduty Push URL (including `integration_key`) into **Webhook URL**
45+
6. Expand **Advanced Settings** and select only **Secret Rotation Failed** and **Honey Token Triggered** under **Events**
46+
7. **Secret Key** can stay empty. If you set one, Infisical adds a signature in the `x-infisical-signature` header; Flashduty records it but does not verify it, and authenticates requests by the `integration_key` in the Push URL
47+
48+
</Step>
49+
50+
<Step title="Verify">
51+
52+
In the webhook list, open the actions menu on the webhook's row and select **Test**. Flashduty creates an Info alert titled `Infisical test notification`. It does not recover on its own, so close it manually after checking.
53+
54+
</Step>
55+
56+
<Step title="Turn on auto-close timeout">
57+
58+
In the channel that receives these alerts, turn on [auto-close timeout](/en/on-call/channel/create-edit) with a duration of 24 hours. If the same rotation or the same honey token sends again within the merge window, the same alert is updated; once it is closed, a new alert is triggered.
59+
60+
</Step>
61+
</Steps>
62+
63+
## Alert Key
64+
---
65+
66+
The Infisical request body has no alert ID, so Flashduty uses the monitored object itself as the Alert Key:
67+
68+
- **Rotation failure**: project ID + environment + folder path + rotation name (`project.projectId`, `project.environment`, `project.secretPath`, `project.rotationName`)
69+
- **Honey token**: project ID + environment + folder path + token name (`project.projectId`, `project.environment`, `project.secretPath`, `honeyToken.name`)
70+
71+
Repeated failures of one rotation (including manual runs and retries), or one honey token triggered several times from different IPs, merge into the same alert. A change in the error message, project name, source IP, or timestamp does not change the Alert Key. A request missing `project.projectId`, `project.environment`, `project.rotationName`, or `honeyToken.name` is rejected.
72+
73+
## Status and severity
74+
---
75+
76+
| Infisical event | Flashduty severity | Notes |
77+
| :--- | :--- | :--- |
78+
| `secrets.rotation-failed` | Critical | The rotation failed and the credential may be stale. The description is the error message Infisical reports |
79+
| `honey-token.triggered` | Critical | A honey token was used, which means the credential leaked. The description has the AWS event, source IP, and region |
80+
| `test` (Test button) | Info | A separate test alert |
81+
| Any other event | No alert | Success is returned |
82+
83+
Neither alert has a recovery event.
84+
85+
## Troubleshooting
86+
---
87+
88+
- **Infisical reports a failed webhook**: check that the Push URL is complete and includes `integration_key`, and that the webhook **Type** is **General** (the Slack and Microsoft Teams types send their own message formats)
89+
- **No alert after a rotation failure**: check that the webhook's **Environment** matches the rotation's environment, that **Secret Path** matches the rotation's folder (for example `/**`), and that **Secret Rotation Failed** is selected
90+
- **The alert does not recover**: Infisical sends no recovery notification; close the alert manually or turn on the channel's auto-close timeout
91+
- **The test alert stays open**: the Test button's request never recovers; close it manually
92+
93+
For more detail, see the Infisical documentation: [Webhooks](https://infisical.com/docs/documentation/platform/webhooks).

0 commit comments

Comments
 (0)