| 1 | -- Platform spend guardrails (src/platform.rs, docs/SPEND-GUARDRAILS.md). |
| 2 | -- |
| 3 | -- platform_pause: g1t-wide pauses, one row per level (compute, schedules, |
| 4 | -- indexing, renders), set by staff in sudo or by the hourly usage watcher |
| 5 | -- on a severe breach. No row, or paused = 0: running. |
| 6 | CREATE TABLE IF NOT EXISTS platform_pause ( |
| 7 | level TEXT PRIMARY KEY, |
| 8 | paused INTEGER NOT NULL DEFAULT 0, |
| 9 | note TEXT, |
| 10 | set_by TEXT, |
| 11 | set_at TEXT, |
| 12 | -- 1 when the usage watcher set it, not a person. |
| 13 | auto INTEGER NOT NULL DEFAULT 0 |
| 14 | ); |
| 15 | |
| 16 | -- platform_usage: what Cloudflare counted each hour (UTC) for each metric |
| 17 | -- (workers_requests, d1_rows_read, kv_lists, …), with the script, queue, |
| 18 | -- database or namespace that counted most. The spike rule reads the last |
| 19 | -- week of it. |
| 20 | CREATE TABLE IF NOT EXISTS platform_usage ( |
| 21 | hour TEXT NOT NULL, |
| 22 | metric TEXT NOT NULL, |
| 23 | value REAL NOT NULL DEFAULT 0, |
| 24 | top_name TEXT, |
| 25 | top_value REAL, |
| 26 | read_at TEXT NOT NULL, |
| 27 | PRIMARY KEY (hour, metric) |
| 28 | ); |
| 29 | CREATE INDEX IF NOT EXISTS platform_usage_by_metric ON platform_usage (metric, hour); |
| 30 | |
| 31 | -- platform_usage_month: the month so far for each metric, as last read. |
| 32 | CREATE TABLE IF NOT EXISTS platform_usage_month ( |
| 33 | month TEXT NOT NULL, |
| 34 | metric TEXT NOT NULL, |
| 35 | value REAL NOT NULL DEFAULT 0, |
| 36 | top_name TEXT, |
| 37 | top_value REAL, |
| 38 | read_at TEXT NOT NULL, |
| 39 | PRIMARY KEY (month, metric) |
| 40 | ); |
| 41 | |
| 42 | -- platform_alerts: each breach the watcher found: over its hourly |
| 43 | -- threshold, or a spike over the week's usual hour. Emailed at most once |
| 44 | -- per metric every 6 hours. |
| 45 | CREATE TABLE IF NOT EXISTS platform_alerts ( |
| 46 | id TEXT PRIMARY KEY, |
| 47 | metric TEXT NOT NULL, |
| 48 | hour TEXT NOT NULL, |
| 49 | rule TEXT NOT NULL, |
| 50 | value REAL NOT NULL, |
| 51 | threshold REAL NOT NULL, |
| 52 | severe INTEGER NOT NULL DEFAULT 0, |
| 53 | top_name TEXT, |
| 54 | top_value REAL, |
| 55 | detail TEXT NOT NULL, |
| 56 | -- The levels it paused, comma-separated; NULL when none. |
| 57 | paused TEXT, |
| 58 | opened_at TEXT NOT NULL, |
| 59 | emailed_at TEXT |
| 60 | ); |
| 61 | CREATE INDEX IF NOT EXISTS platform_alerts_by_metric ON platform_alerts (metric, opened_at); |
| 62 | |
| 63 | -- platform_watch_runs: what each hourly run could not see. failed is a |
| 64 | -- JSON object of query key to its error ({} when every query answered); |
| 65 | -- empty is 1 when every dataset that answered had no rows, the month so |
| 66 | -- far included (the wrong account, or a token that cannot see it). Sudo |
| 67 | -- shows the latest; three runs in a row email staff. Kept 14 days. |
| 68 | CREATE TABLE IF NOT EXISTS platform_watch_runs ( |
| 69 | hour TEXT PRIMARY KEY, |
| 70 | read_at TEXT NOT NULL, |
| 71 | failed TEXT NOT NULL DEFAULT '{}', |
| 72 | empty INTEGER NOT NULL DEFAULT 0 |
| 73 | ); |
| 74 | |
| 75 | -- platform_watch_alerts: when staff were last emailed that a query (or |
| 76 | -- all_empty) stayed blind; at most once a day per key. |
| 77 | CREATE TABLE IF NOT EXISTS platform_watch_alerts ( |
| 78 | key TEXT PRIMARY KEY, |
| 79 | emailed_at TEXT NOT NULL |
| 80 | ); |