feat(approvals): integrate approval-hold detection and auto-remediation into fleet alert, loop diagnostics, and muse API
This commit is contained in:
@@ -624,6 +624,26 @@ def diagnose_breaks() -> list:
|
||||
"remedy": f"Check agent {l['agent']} browser tab with 'super fleet status' or nudge via 'super dm send'."
|
||||
})
|
||||
|
||||
# 4. Check for agents held up on approvals
|
||||
try:
|
||||
import approvals
|
||||
fleet_apps = approvals.check_fleet_approvals()
|
||||
for app in fleet_apps:
|
||||
if app.get("has_pending"):
|
||||
node = app["node"]
|
||||
is_trusted = app.get("is_trusted", False)
|
||||
ip = app.get("ip") or "unknown target"
|
||||
breaks.append({
|
||||
"type": "approval_blocked",
|
||||
"severity": "WARNING" if is_trusted else "CRITICAL",
|
||||
"component": f"node:{node}",
|
||||
"agent": node,
|
||||
"detail": f"Agent {node} is held up on browser approval for {ip}",
|
||||
"remedy": f"Run 'box approvals auto' or 'box approvals allow {node}'."
|
||||
})
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
return breaks
|
||||
|
||||
|
||||
@@ -730,6 +750,24 @@ def remediate_breaks(dry_run=False) -> dict:
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
# Auto-remediate trusted approval blocks
|
||||
try:
|
||||
import approvals
|
||||
fleet_apps = approvals.check_fleet_approvals()
|
||||
for app in fleet_apps:
|
||||
if app.get("has_pending") and app.get("is_trusted"):
|
||||
node = app["node"]
|
||||
if not dry_run:
|
||||
approvals.allow_node_approval(node, caller="loop-remediate")
|
||||
remediated.append({
|
||||
"type": "approval_auto_allowed",
|
||||
"agent": node,
|
||||
"target": app.get("ip"),
|
||||
"action": f"Auto-approved trusted browser request on {node} ({app.get('ip')})"
|
||||
})
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
# 3. Alert on hard breakages if any exist
|
||||
if escalated and not dry_run:
|
||||
job_log = Path("/home/super/Projects/NetVM/job-log.jsonl")
|
||||
|
||||
Reference in New Issue
Block a user