<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="rss.xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>env-sync Viewer Blog</title>
        <link>https://env-sync-viewer.catesworks.dev/blog</link>
        <description>env-sync Viewer Blog</description>
        <lastBuildDate>Mon, 28 Sep 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <item>
            <title><![CDATA[Your monitoring dashboard can lie by omission]]></title>
            <link>https://env-sync-viewer.catesworks.dev/blog/silence-is-not-health</link>
            <guid>https://env-sync-viewer.catesworks.dev/blog/silence-is-not-health</guid>
            <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A performance guard on a "latest status" query quietly turned a dead collector into a clean bill]]></description>
            <content:encoded><![CDATA[<p>A performance guard on a "latest status" query quietly turned a dead collector into a clean bill
of health. Here is how the final review of env-sync Viewer caught it before anything shipped.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_oQr6" id="the-setup">The setup<a href="https://env-sync-viewer.catesworks.dev/blog/silence-is-not-health#the-setup" class="hash-link" aria-label="Direct link to The setup" title="Direct link to The setup" translate="no">​</a></h2>
<p>env-sync Viewer has two parts. A scheduled collector records secrets-drift status for every target
in the fleet. A read-only dashboard shows each target's latest state. The dashboard exists to tell
a human when something is wrong.</p>
<p>The first version looked up each target's latest state only within the last 14 days. That seemed
reasonable: there was no retention policy yet, and nobody wanted a full history scan on every page
load. The line sat next to ordinary query code, far from the auth and access-control code that got
the most scrutiny.</p>
<h2 class="anchor anchorTargetStickyNavbar_oQr6" id="the-question-that-found-it">The question that found it<a href="https://env-sync-viewer.catesworks.dev/blog/silence-is-not-health#the-question-that-found-it" class="hash-link" aria-label="Direct link to The question that found it" title="Direct link to The question that found it" translate="no">​</a></h2>
<p>The final adversarial review asked one question: <em>what does this page show if the collector has
been silently broken for a month?</em></p>
<p>It showed nothing. There were zero targets and zero stale warnings, just an empty, calm page. The
grouping logic was correct. The bug was an assumption hidden in the <code>WHERE</code> clause: that a recent
row would always exist. When a target went silent, it didn't look stale. It stopped existing.</p>
<h2 class="anchor anchorTargetStickyNavbar_oQr6" id="the-fix">The fix<a href="https://env-sync-viewer.catesworks.dev/blog/silence-is-not-health#the-fix" class="hash-link" aria-label="Direct link to The fix" title="Direct link to The fix" translate="no">​</a></h2>
<p>We removed the time bound. Two unbounded <code>DISTINCT ON</code> queries find each target's latest-ever
snapshot and its latest-ever <em>healthy</em> snapshot. The display layer then compares the timestamps to
now. A target that has ever been seen now always appears, and it ages into <strong>stale</strong> after
<code>STALE_AFTER_HOURS</code>. A regression test against real Postgres seeds a target last seen 60 days ago
and asserts that it is still on the page, marked stale.</p>
<p>The full scan is fine at current volume. When a retention policy arrives and the query needs a
bound again, indexes come first. Silently dropping rows does not come back.</p>
<h2 class="anchor anchorTargetStickyNavbar_oQr6" id="the-lesson">The lesson<a href="https://env-sync-viewer.catesworks.dev/blog/silence-is-not-health#the-lesson" class="hash-link" aria-label="Direct link to The lesson" title="Direct link to The lesson" translate="no">​</a></h2>
<p>For any monitoring view, ask two questions: "what does it show when the thing is failing?" and
"what does it show when the thing has been <em>silent</em> for a very long time?" A false all-clear is
worse than having no dashboard, because people trust it.</p>
<p>Read more about staleness and the rest of the design in <a class="" href="https://env-sync-viewer.catesworks.dev/docs/architecture">Architecture</a>.</p>]]></content:encoded>
            <category>Monitoring</category>
            <category>Lessons</category>
        </item>
    </channel>
</rss>