bug-reproduce
Turn a known bug into a tight, red-capable reproducer, then prove the reproducer locks that…
Periodic health sweep of the running system via the debug pipeline (cloud logs / k8s / daemon / DB slices). On a real anomaly, open a bug task (--kind work_item) carrying the evidence refs so it re-enters the bugfix loop. A healthy sweep opens NO task — never fabricate a bug.
$ npx -y skills add Prismer-AI/PrismerCloud --skill observability --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/observabilityContext preview
The summary Claude sees to decide when to auto-load this skill.
Periodic health sweep of the running system via the debug pipeline (cloud logs / k8s / daemon / DB slices). On a real anomaly, open a bug task (--kind work_item) carrying the evidence refs so it re-enters the bugfix loop. A healthy sweep opens NO task — never fabricate a bug.
name: observability description: Periodic health sweep of the running system via the debug pipeline (cloud logs / k8s / daemon / DB slices). On a real anomaly, open a bug task (--kind work_item) carrying the evidence refs so it re-enters the bugfix loop. A healthy sweep opens NO task — never fabricate a bug. license: MIT scope: common compatibility: - claude-code - prismer-sdk allowed-tools: - Bash metadata: category: observability
用 **debug pipeline** 巡检运行中的系统(cloud log / k8s / daemon / DB 切片),**异常时开一个 bug task** 把证据带回 bugfix 循环(`apc/05` S10 · 生命周期矩阵**行 11 监控→回流**)。**触发器 = product205 定时任务后端**(已建,缺前端)挂周期巡检——本 skill 是那次巡检真正干的活,不悬空。
**承重纪律**:
**什么时候用**:周期巡检(定时任务触发)或收到"系统是不是出问题了"时——先用 debug pipeline 取副作用切片核实,再决定是否回流。
| 命令 | 作用 | 输出/退出码 | | --- | --- | --- | | `npx tsx scripts/debug/admin-observability.ts capabilities [--env=local\|test\|prod]` | canonical Admin v1 discovery;读取 principal、capabilities、schema version 与 opaque contract digest | `0` 成功;不兼容/无权限非零 | | `npx tsx scripts/debug/admin-observability.ts logs --target-kind=service --target-id=prismer-cloud --purpose=<reason> [--since=15m] [--cursor=<opaque>] [--completeness=require-complete\|allow-partial]` | canonical `POST /api/admin/v1/logs:query` 只读快照;命令内部必须先 discovery;cursor 只能原样回传 | 默认 `require-complete`;置信边界完整 `0`,不满足 `3`,请求/合同错误 `1`,用法错误 `2` | | `cloud admin log-targets --kind <service\|sandbox\|daemon> --purpose <reason> [--workspace-id <id>] [--cursor <opaque>]` | daemon-held credential 下发现 DB-resolved logical targets;不接受 namespace/selector | `0` 完整成功;partial projection `2`;请求失败 `1` | | `cloud admin logs --target-kind <kind> --target-id <id> --purpose <reason> [--attach-to-task [taskId]]` | credentialless loopback 查询 service/sandbox/daemon;可经既有 daemon task-attach 把 JSON 证据绑定到 task | `0` 完整成功;partial `2`;失败 `1`;attach 要求 daemon dispatch + `PRISMER_ARTIFACTS_DIR` | | `npx tsx scripts/debug/inventory.ts [--env=local\|test\|prod] [--json]` | 全局索引:running pods / recent workspaces / recent tasks / **recent errors** | 人读 5 段 或 `--json` | | `npx tsx scripts/debug/bundle.ts <workspace\|task\|pod> <id> [--sections=db,system,k8s,daemon] [--stdout] [--since=ISO]` | 复合切片(DB+system-log+k8s+daemon) | 默认写 `./debug-bundle-*.json`,`--stdout` 打屏 | | `npx tsx scripts/debug/snapshot.ts <workspace\|task\|conversation\|container> <id> [--json\|--brief]` | DB 切片(task 终态行/runs/logs/approvals/assets) | 默认 compact,`--json` raw | | `npx tsx scripts/debug/logs.ts [--contains=text] [--since=ISO\|10m\|1h] [--level=...] [--json]` | cloud 进程 pino ring buffer | 每行一条 或 `--json` | | `cloud task create --title <t> --description <d> --kind work_item [--priority high] [--json]` | **开 bug task**(`--kind work_item` 是 board 投影) | 打印 `ID: <taskId>`(`--json` 出整行) | | `cloud task list [--json]` | 回读 task 行确认落库 | 0 成功 |
APC 自动巡检默认要求完整结果。先调用 capabilities,再由同一命令进程完成 logs query:
mkdir -p .e2e-tmp/apc/observability npx tsx scripts/debug/admin-observability.ts capabilities \ > .e2e-tmp/apc/observability/admin-capabilities.json npx tsx scripts/debug/admin-observability.ts logs \ --target-kind=service --target-id=prismer-cloud --since=15m \ --purpose="periodic APC observability sweep" \ --completeness=require-complete \ > .e2e-tmp/apc/observability/admin-service-logs.json admin_logs_exit=$?
`admin_logs_exit=3` 表示所需置信边界不完整,**不得宣布 healthy**;读取 JSON 中的 `requestId`、`sources[]`、`partial`、`attemptedSourceTiers`、`availableSourceTiers`、 `confidenceBoundary.productionRetainedRequirement`、`contractDigest`、`evidenceHash` 后报告受限结论。 `attemptedSourceTiers` 只说明服务端尝试过某 tier;只有 `availableSourceTiers` 才代表可用证据, retained source 为 `unavailable` 或 `error` 时严禁把它写成 retained evidence。 只有 human 明确做探索性查询时才可传 `allow-partial`,且逐 source outcome 仍必须保留。`1/2` 是请求或 用法失败,同样不能当作“没有 error”。canonical 输出可作为 task-bound evidence,但先确认其中不含凭据; 不要长期保存为 loose file。
生产环境的 `require-complete` 还有强 gate:必须同时看到 `availableSourceTiers` 包含 `retained`、 `confidenceBoundary.productionRetainedRequirement.satisfied=true`、稳定 ordering/continuity、 完整 coverage、`truncated=false`、`mayDuplicate=false`。任一不满足均按退出码 `3` 处理。 分页时只可把响应 `nextCursor` 原样作为下一次 `--cursor=<opaque>`;不得解析、修改或自行生成 cursor。 SLS 当前只提供 offset continuation,服务端会明确标记 `continuity=best-effort`、`mayDuplicate=true` 和 `partial=true`;即使 provider query 返回 Complete 也不得升级成完整证据。Sandbox/Daemon 查询前先用 `cloud admin log-targets` 发现 logical id,禁止把 Pod、namespace 或 label selector 当 target id 猜测。
mkdir -p .e2e-tmp/apc/observability npx tsx scripts/debug/inventory.ts | tee .e2e-tmp/apc/observability/inventory.md; echo "inventory exit=$?" npx tsx scripts/debug/inventory.ts --json > .e2e-tmp/apc/observability/inventory.json # 机器形(可选)
**产物落 repo-relative 的 `.e2e-tmp/apc/observability/`(已在 `.gitignore`),不要落 `/tmp`**——判据要**读回**你引用的那一行,`/tmp` 从仓库根不可解析、跑完即毁的证据等于没有证据(同 test204「证据销毁反 pattern」)。**报告前不许删**这批产物。
读
Repo: Prismer-AI/PrismerCloud
Turn a known bug into a tight, red-capable reproducer, then prove the reproducer locks that…
Review a diff against its acceptance criteria in four segments (convention adherence, bug…
Five-dimension design audit (frontend UI/UX · server data-model & flow · endpoint spec ·…
Before merge, mechanize Documentation-First — derive the code delta from git diff, then…
Diagnose the local dev machine before any APC loop step — run apc env doctor, classify each…
Close out a local coding task on the bound daemon — stage, commit, branch, merge, push via…