Incidents¶
Ein Incident ist ein first-class Managed Object für die Buchführung von Sicherheits- und Betriebsvorfällen (ISMS / VA-IM). Es ist kein Note-Kind — Notes können aber als Quelle oder Post-Mortem verknüpft sein.
Kernfelder¶
| Feld | Bedeutung |
|---|---|
status | reported → investigating → contained → resolved → reviewed |
kind | u. a. upstream-provider bei automatischen Provider-Incidents |
criticality | low / medium / high |
organization / workspace | Scope; organization=null = systemweit |
pop / affected_pops | Primärer PoP + kanonische PoP-Menge |
provider_entity | Verknüpfter Provider |
affected_hosts / affected_volumes | Betroffene Ressourcen |
downtimes | Verknüpfte Downtimes |
source_note / source_datasource | Herkunft aus Provider-Status |
| Embedded Note | Beschreibung / Beweise |
Status-Maschine¶
- Nur vorwärts (Skip erlaubt, z. B.
reported→resolved) reviewedist terminal- Kein separates Acknowledge — Übernahme = Statuswechsel von
reported
Scope¶
| Scope | Sichtbarkeit |
|---|---|
| Systemweit | für berechtigte User immer sichtbar |
| Organisation / Workspace | im jeweiligen Tenant |
Automatische Erzeugung (Provider-Status)¶
Aus DataSources (rss, otc-status, webhook) entstehen provider-status-Notes. Die KI-Auswertung kann:
- Maintenances anlegen/aktualisieren
- Incidents (
kind=upstream-provider, oft systemweit) anlegen - Hosts/Volumes/PoPs über Matching verknüpfen (
provider_id,hostname,cloud_provider_volume_id, …)
Manueller Re-Scan einer Note oder DataSource ist möglich, wenn die Klassifikation nachgezogen werden soll.
UI¶
- Liste unter Operations → Incidents
- Detail: Klassifikation, PoP/Provider/Source, Embedded Note, Tabs für Downtimes und Affected Hosts/Volumes/PoPs, Activity-Timeline
Conditions & Notifications¶
INCIDENT_REVIEW_OVERDUE(WARNING), wennresolvedzu lange ohnereviewedbleibt- Notifications
incident_opened/incident_closed(idempotent)
Abgrenzung¶
- Zammad/Tickets: höchstens manuelle
reference_url— kein eingebettetes Ticketsystem - Downtimes bleiben das technische Ausfallobjekt; Incidents sind die formale Vorfallakte
- Post-Mortems können weiterhin als Notes
kind=post-mortemgeführt werden
Verwandte Themen¶
- Wartungen
- DataSources
- PoPs & Provider
- Activity-Timeline
- Criticality
- K8sVolumes — Matching über
cloud_provider_volume_id