Skip to content
80 linesCodeBlameRaw
1-- Platform spend guardrails (src/platform.rs, docs/SPEND-GUARDRAILS.md).
2--
3-- platform_pause: g1t-wide pauses, one row per level (compute, schedules,
4-- indexing, renders), set by staff in sudo or by the hourly usage watcher
5-- on a severe breach. No row, or paused = 0: running.
6CREATE TABLE IF NOT EXISTS platform_pause (
7 level TEXT PRIMARY KEY,
8 paused INTEGER NOT NULL DEFAULT 0,
9 note TEXT,
10 set_by TEXT,
11 set_at TEXT,
12 -- 1 when the usage watcher set it, not a person.
13 auto INTEGER NOT NULL DEFAULT 0
14);
15
16-- platform_usage: what Cloudflare counted each hour (UTC) for each metric
17-- (workers_requests, d1_rows_read, kv_lists, …), with the script, queue,
18-- database or namespace that counted most. The spike rule reads the last
19-- week of it.
20CREATE TABLE IF NOT EXISTS platform_usage (
21 hour TEXT NOT NULL,
22 metric TEXT NOT NULL,
23 value REAL NOT NULL DEFAULT 0,
24 top_name TEXT,
25 top_value REAL,
26 read_at TEXT NOT NULL,
27 PRIMARY KEY (hour, metric)
28);
29CREATE INDEX IF NOT EXISTS platform_usage_by_metric ON platform_usage (metric, hour);
30
31-- platform_usage_month: the month so far for each metric, as last read.
32CREATE TABLE IF NOT EXISTS platform_usage_month (
33 month TEXT NOT NULL,
34 metric TEXT NOT NULL,
35 value REAL NOT NULL DEFAULT 0,
36 top_name TEXT,
37 top_value REAL,
38 read_at TEXT NOT NULL,
39 PRIMARY KEY (month, metric)
40);
41
42-- platform_alerts: each breach the watcher found: over its hourly
43-- threshold, or a spike over the week's usual hour. Emailed at most once
44-- per metric every 6 hours.
45CREATE TABLE IF NOT EXISTS platform_alerts (
46 id TEXT PRIMARY KEY,
47 metric TEXT NOT NULL,
48 hour TEXT NOT NULL,
49 rule TEXT NOT NULL,
50 value REAL NOT NULL,
51 threshold REAL NOT NULL,
52 severe INTEGER NOT NULL DEFAULT 0,
53 top_name TEXT,
54 top_value REAL,
55 detail TEXT NOT NULL,
56 -- The levels it paused, comma-separated; NULL when none.
57 paused TEXT,
58 opened_at TEXT NOT NULL,
59 emailed_at TEXT
60);
61CREATE INDEX IF NOT EXISTS platform_alerts_by_metric ON platform_alerts (metric, opened_at);
62
63-- platform_watch_runs: what each hourly run could not see. failed is a
64-- JSON object of query key to its error ({} when every query answered);
65-- empty is 1 when every dataset that answered had no rows, the month so
66-- far included (the wrong account, or a token that cannot see it). Sudo
67-- shows the latest; three runs in a row email staff. Kept 14 days.
68CREATE TABLE IF NOT EXISTS platform_watch_runs (
69 hour TEXT PRIMARY KEY,
70 read_at TEXT NOT NULL,
71 failed TEXT NOT NULL DEFAULT '{}',
72 empty INTEGER NOT NULL DEFAULT 0
73);
74
75-- platform_watch_alerts: when staff were last emailed that a query (or
76-- all_empty) stayed blind; at most once a day per key.
77CREATE TABLE IF NOT EXISTS platform_watch_alerts (
78 key TEXT PRIMARY KEY,
79 emailed_at TEXT NOT NULL
80);