This repository was archived by the owner on Jun 22, 2026. It is now read-only.
v2.28.0: cross-tenant portfolio-rollup ingest (Atlas Situational Awareness) - #161
Merged
Conversation
v2.24.0: promote dev→main (TRI-20 write path + TRI-9 + TRI-16)
v2.25.1: promote dev→main (TRI-6 agent bug-write path)
v2.26.0: admin — LLM Provider Health module (prod)
v2.27.0: admin — promote cross-tenant LLM usage dashboard + ingest to prod
…eness PRT)
Receiver for the per-tenant PII-free Foundry portfolio rollup that each Atlas
tenant pushes daily (atlas /api/internal/portfolio-rollup-report). Mirrors the
llm-usage ingest: x-ingest-secret constant-time auth (PORTFOLIO_ROLLUP_INGEST_SECRET,
503 unconfigured / 401 mismatch), validate the PII-free { tenantSlug, generatedAt,
rollup{categories[]} } body, replace-per-tenant upsert. New table tenant_portfolio_rollup
(migration 0025) stores per-category counts + max severity + at-risk-$ SUM (micros) only.
Secret provisioned in triarch-dev-website (matches the atlas value) + both backends granted.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Central receiver for the per-tenant PII-free Foundry portfolio rollup that each Atlas tenant pushes daily (atlas
/api/internal/portfolio-rollup-report, Phase 51 PRT). The cross-tenant aggregator the atlas push was best-effort no-op-ing without.What
POST /api/platform/ingest/portfolio-rollup— mirrorsingest/llm-usage:x-ingest-secretconstant-time auth (PORTFOLIO_ROLLUP_INGEST_SECRET; 503 unconfigured / 401 mismatch), validate the PII-free{ tenantSlug, generatedAt, rollup{ categories[] } }body, replace-per-tenant upsert.tenant_portfolio_rollup(migration 0025) — per(tenant_slug, category): count + max severity + severity buckets + at-risk-$ SUM (micros). No entity/contact/per-record data — PII-free by construction.apphosting.yamlbindsPORTFOLIO_ROLLUP_INGEST_SECRET.Secret coordination (done)
Provisioned
PORTFOLIO_ROLLUP_INGEST_SECRETintriarch-dev-websitewith the same value as the atlas project, and granted both backends (members match the known-goodLLM_USAGE_INGEST_SECRET) — so the rollout won't break on a missing secret and atlas's push authenticates.🤖 Generated with Claude Code