Skip to content

Add Phoenix LiveView incident room on Managed Postgres - #449

Draft
sdairs wants to merge 2 commits into
mainfrom
codex/incident-room
Draft

sdairs wants to merge 2 commits into
mainfrom
codex/incident-room

Conversation

@sdairs

@sdairs sdairs commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Adds a small trusted-team Phoenix LiveView incident room. Signed-in responders open incidents, append immutable timeline notes, and move investigating/monitoring/resolved state with expected versions. Ecto commits each status update and its timeline entry together; PubSub notifies browsers only after commit, while reconnect and process restart reload durable Postgres state.

Setup documents Cloud provisioning, CA/hostname verification, separate migration/runtime roles, explicit Ecto migrations and seeded BCrypt accounts. HTTP CSRF, origin checks, expiring hashed sessions and LiveView mount/event authorization remain enabled. Views show the newest 100 incidents/latest 200 entries; there is no tenant isolation or durable broadcast queue.

Validation on a dedicated ClickHouse Managed Postgres 18.6 Cloud service, 2 October 2026, native Ubuntu 24.04 ARM64:

  • 3 unit and 8 real Cloud tests passed: certificate-specific wrong-CA/hostname controls, actual privilege denials, competing expected versions, blocked database sessions, Unicode/history bounds, revoked sessions and a scoped forced-entry failure proving rollback after status mutation and no broadcast.
  • 8 real Chromium flow checks passed, with received WebSocket frames: two-browser delivery, own-form reset/foreign draft preservation, malformed/forged fields, concurrent status race, deliberately missed broadcast/reconnect, actual server-process restart and subsequent authorized write, native 403 without CSRF, independent replay of a revoked cookie.
  • Formatting, warnings-as-errors compilation, assets build and dependency advisory audit passed. CI runs build/domain checks without Cloud credentials.

Companion article and sanitized acceptance logs/screenshot remain local for review. The dedicated Cloud fixture was deleted after independent review, with absence verified; no private credentials or endpoints are included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant