Skip to content
This repository was archived by the owner on Jun 22, 2026. It is now read-only.

v2.28.0: cross-tenant portfolio-rollup ingest (Atlas Situational Awareness) - #161

Merged
MyAlterLego merged 5 commits into
devfrom
feat/portfolio-rollup-ingest
Jun 20, 2026
Merged

v2.28.0: cross-tenant portfolio-rollup ingest (Atlas Situational Awareness)#161
MyAlterLego merged 5 commits into
devfrom
feat/portfolio-rollup-ingest

Conversation

@MyAlterLego

Copy link
Copy Markdown
Collaborator

Central receiver for the per-tenant PII-free Foundry portfolio rollup that each Atlas tenant pushes daily (atlas /api/internal/portfolio-rollup-report, Phase 51 PRT). The cross-tenant aggregator the atlas push was best-effort no-op-ing without.

What

  • POST /api/platform/ingest/portfolio-rollup — mirrors ingest/llm-usage: x-ingest-secret constant-time auth (PORTFOLIO_ROLLUP_INGEST_SECRET; 503 unconfigured / 401 mismatch), validate the PII-free { tenantSlug, generatedAt, rollup{ categories[] } } body, replace-per-tenant upsert.
  • New table tenant_portfolio_rollup (migration 0025) — per (tenant_slug, category): count + max severity + severity buckets + at-risk-$ SUM (micros). No entity/contact/per-record data — PII-free by construction.
  • apphosting.yaml binds PORTFOLIO_ROLLUP_INGEST_SECRET.

Secret coordination (done)

Provisioned PORTFOLIO_ROLLUP_INGEST_SECRET in triarch-dev-website with the same value as the atlas project, and granted both backends (members match the known-good LLM_USAGE_INGEST_SECRET) — so the rollout won't break on a missing secret and atlas's push authenticates.

🤖 Generated with Claude Code

MyAlterLego and others added 5 commits June 1, 2026 13:01
v2.24.0: promote dev→main (TRI-20 write path + TRI-9 + TRI-16)
v2.25.1: promote dev→main (TRI-6 agent bug-write path)
v2.26.0: admin — LLM Provider Health module (prod)
v2.27.0: admin — promote cross-tenant LLM usage dashboard + ingest to prod
…eness PRT)

Receiver for the per-tenant PII-free Foundry portfolio rollup that each Atlas
tenant pushes daily (atlas /api/internal/portfolio-rollup-report). Mirrors the
llm-usage ingest: x-ingest-secret constant-time auth (PORTFOLIO_ROLLUP_INGEST_SECRET,
503 unconfigured / 401 mismatch), validate the PII-free { tenantSlug, generatedAt,
rollup{categories[]} } body, replace-per-tenant upsert. New table tenant_portfolio_rollup
(migration 0025) stores per-category counts + max severity + at-risk-$ SUM (micros) only.

Secret provisioned in triarch-dev-website (matches the atlas value) + both backends granted.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
@MyAlterLego
MyAlterLego merged commit 5bce260 into dev Jun 20, 2026
14 checks passed
@MyAlterLego
MyAlterLego deleted the feat/portfolio-rollup-ingest branch June 20, 2026 22:07
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant