Skip to content

Add firewall detection and user-friendly error handling for Supabase sign-in - #2193

Merged
RoiGlinik merged 19 commits into
masterfrom
claude/dazzling-gauss-nespl7
Jun 16, 2026
Merged

RoiGlinik merged 19 commits into
masterfrom
claude/dazzling-gauss-nespl7

Conversation

@moshemorad

@moshemorad moshemorad commented Jun 14, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Improve error handling during Supabase authentication to detect and clearly communicate firewall/egress policy issues that block connections to the Robusta platform. When Holmes fails to connect during sign-in, it now distinguishes between DNS failures, firewall blocks, and genuine authentication errors, providing actionable guidance to users.

firewallconnectionresetlog

Key Changes

  • New Exception Classes: Added SupabaseConnectionException for connection reset/refused/timeout errors that indicate firewall blocks, distinct from SupabaseDnsException for DNS resolution failures
  • Enhanced Error Detection: Updated SupabaseDal.sign_in() to classify connection errors by examining exception types and error messages, detecting patterns like "connection reset by peer", "connection refused", "connection timed out", and errno codes (104, 111)
  • User-Friendly Messaging: Connection exceptions now include:
    • Clear explanation that the issue is almost always an outbound firewall/egress policy
    • Specific guidance to allowlist *.robusta.dev for HTTPS (port 443)
    • A diagnostic curl command targeting the configured platform URL's health endpoint
    • Link to troubleshooting documentation
  • Actionable Logging: Added WARNING-level log message before raising connection exceptions (not ERROR, to avoid spurious Sentry alerts) with the same guidance
  • Preserved Auth Errors: Genuine authentication errors (e.g., invalid credentials) propagate unchanged without wrapping, so users see the actual auth problem
  • Documentation: Added troubleshooting section to docs explaining the firewall block scenario, how to confirm it with curl, and how to fix it

Implementation Details

  • Connection error detection uses both exception type checks (ConnectionError, TimeoutError) and string pattern matching on error messages to catch various ways httpx and other libraries surface network failures
  • The health check URL is dynamically constructed from the configured platform URL to match the user's region/deployment
  • Logging is kept at WARNING level (not ERROR) to prevent false Sentry alerts for infrastructure issues outside the application's control
  • All three exception types (DNS, connection, auth) are tested with comprehensive unit tests covering success and failure paths

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby

Summary by CodeRabbit

Release Notes

  • Documentation

    • Added a new troubleshooting item for startup failures when outbound firewall/egress resets connections, including the typical traceback, HTTPS (443) allowlisting guidance for Robusta subdomains (including sp), and a simple kubectl/curl connectivity check.
    • Updated robusta-region documentation and behavior to rewrite sp.robusta.dev in addition to existing Robusta subdomains.
  • Improvements

    • Enhanced sign-in handling for connection-related failures with clearer firewall guidance and a troubleshooting reference.
  • Tests

    • Added coverage for sign-in error classification (connection/reset vs DNS vs credential errors).

claude added 3 commits June 14, 2026 13:02
…ed (ROB-293)

When Holmes starts behind an outbound firewall that blocks egress to the
Robusta platform, sign-in to Supabase fails with
`httpx.ConnectError: [Errno 104] Connection reset by peer` (ROB-273). DNS
resolves and the TLS cert is fine, so the existing SupabaseDnsException did
not match and the user only saw a raw httpx traceback with no guidance.

Detect connection reset/refused/timeout errors in SupabaseDal.sign_in() and
raise a new SupabaseConnectionException that logs an actionable ERROR and
explains how to fix it: allowlist outbound HTTPS to *.robusta.dev, plus a
`curl -vk <url>/auth/v1/health` command to confirm the block. DNS errors and
genuine auth failures keep their existing behavior.

Also treat SupabaseConnectionException as transient in the conversation
worker / realtime reconnect loops, mirroring SupabaseDnsException, so a
firewall block during reconnect is retried with backoff instead of being
surfaced as an unexpected defect.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
…(ROB-293)

- Log the firewall hint at WARNING instead of ERROR in SupabaseDal.sign_in();
  ERROR-level logs raise Sentry alerts, which we don't want for a user-side
  network misconfiguration.
- Revert the SupabaseConnectionException additions to the conversation worker
  and realtime reconnect tuples. This is a Supabase login-flow issue; the
  reconnect loops don't call sign_in directly, so keep the change scoped to it.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
… log (ROB-293)

Add a Troubleshooting section documenting the startup
"Connection reset by peer" failure: outbound firewall blocking egress to the
Robusta platform, how to allowlist *.robusta.dev, and a curl health-check to
confirm. Cross-links the related LITELLM_MODEL_COST_MAP_URL egress note.

Link to that section from both the WARNING log and the SupabaseConnectionException
message so users hitting the error can find the fix. The heading carries a pinned
anchor (firewall-blocking-robusta-platform) so the in-log URL stays stable.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 14, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds SupabaseConnectionException and FIREWALL_TROUBLESHOOTING_URL to supabase_dal.py, updates SupabaseDal.sign_in to detect connection reset/refused/timeout errors and raise the new exception with an actionable message, adds TestSignIn tests covering all error and success paths, documents the issue in a new troubleshooting section, and updates documentation to recognize and rewrite sp.robusta.dev to regional variants.

Changes

Firewall Connection Error Detection and Docs

Layer / File(s) Summary
SupabaseConnectionException and FIREWALL_TROUBLESHOOTING_URL
holmes/core/supabase_dal.py
Adds module-level FIREWALL_TROUBLESHOOTING_URL constant and SupabaseConnectionException class whose constructor builds a detailed error message including the auth health URL and the troubleshooting link.
sign_in network error detection
holmes/core/supabase_dal.py
Extends sign_in exception handling to match connection reset/refused/timeout strings, log a warning with an outbound HTTPS allowlist hint, and raise SupabaseConnectionException.
TestSignIn coverage
tests/core/test_supabase_dal.py
Adds TestSignIn class with a mocked SupabaseDal fixture and tests for firewall errors → SupabaseConnectionException, DNS errors → SupabaseDnsException, credential errors propagate unchanged, and success path returns user id and sets session.
Troubleshooting documentation
docs/reference/troubleshooting.md
Adds "Startup Fails with Connection reset by peer" section covering the httpx.ConnectError traceback, outbound HTTPS allowlisting for *.robusta.dev (including sp.robusta.dev), a kubectl health check command, and LITELLM_MODEL_COST_MAP_URL guidance.
Documentation for regional domain rewriting
docs/custom_fences.py, CLAUDE.md
Updates ROBUSTA_DOMAIN_RE to match sp.robusta.dev in addition to api.robusta.dev and platform.robusta.dev; updates robusta-region fence docstrings and CLAUDE.md guidance to reflect expanded domain rewriting coverage.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

  • HolmesGPT/holmesgpt#2094: Both PRs modify docs/custom_fences.py to extend the robusta-region host rewriting logic—this PR adds sp.robusta.dev (Supabase) to the same ROBUSTA_DOMAIN_RE/fence behavior introduced by the multi-region docs PR.
  • HolmesGPT/holmesgpt#1091: Both PRs modify holmes/core/supabase_dal.py's SupabaseDal.sign_in error handling to classify Supabase connection failures into specific exception types (this PR: SupabaseConnectionException for TCP/TLS/firewall resets; related PR: SupabaseDnsException for DNS errors).

Suggested reviewers

  • RoiGlinik
  • naomi-robusta
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 21.43% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately and concisely summarizes the main change: adding firewall detection and user-friendly error handling for Supabase sign-in failures.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Jun 14, 2026 •

Copy link
Copy Markdown
Contributor

📂 Previous Runs

⚠️ 1 older run truncated

Older runs were omitted to stay under GitHub's 64KB comment size limit.


✅ Results of HolmesGPT evals

Automatically triggered by commit 912b95a on branch claude/dazzling-gauss-nespl7

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 14/14 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Max input Output Max output Cached Non-cached Reasoning Compactions Denied commands Src
✅ 09_crashpod 24.0s 3 7 $0.1894 50,571 49,134 18,878 1,437 664 29,458 19,676 127 — — src
✅ 101_loki_historical_logs_pod_deleted 49.3s 5 10 $0.2577 90,444 87,590 20,510 2,854 889 66,805 20,785 496 — — src
✅ 112_find_pvcs_by_uuid 15.3s 2 2 $0.1611 33,872 32,919 18,597 953 591 14,319 18,600 132 — — src
✅ 12_job_crashing 31.8s 4 11 $0.2297 75,082 73,205 21,444 1,877 541 51,201 22,004 77 — — src
✅ 176_network_policy_blocking_traffic_no_skills 31.3s 5 10 $0.2174 87,499 85,883 19,441 1,616 506 65,893 19,990 248 — — src
✅ 227_count_configmaps_per_namespace[0] 14.8s 3 6 $0.1501 46,356 45,645 16,661 711 438 28,980 16,665 29 — — src
✅ 243_pod_names_contain_service 24.7s 3 5 $0.1691 47,825 46,589 17,233 1,236 455 29,080 17,509 192 — — src
✅ 24_misconfigured_pvc 30.7s 4 11 $0.2171 68,774 66,817 19,350 1,957 547 46,505 20,312 204 — — src
✅ 254_elasticsearch_dr_test_log_check 45.8s 7 8 $0.2165 87,961 85,392 15,621 2,569 786 69,763 15,629 280 — — src
✅ 259_wrong_cluster_logs_confusion 74.5s 8 14 $0.3352 123,567 118,668 19,936 4,899 1,706 96,824 21,844 768 — — src
✅ 260_global_es_remote_cluster_logs 67.8s 10 12 $0.2996 138,837 134,868 17,871 3,969 1,232 116,336 18,532 605 — — src
✅ 43_current_datetime_from_prompt 4.6s 1 — $0.1017 14,429 14,306 14,306 123 123 0 14,306 79 — — src
✅ 51_logs_summarize_errors 20.3s 3 2 $0.1540 46,688 45,913 16,983 775 400 28,926 16,987 30 — — src
✅ 61_exact_match_counting 7.6s 2 1 $0.1146 29,149 28,928 14,642 221 152 14,283 14,645 34 — — src
Total 31.6s avg 4.3 avg 7.6 avg $2.8133 941,054 915,857 21,444 25,197 1,706 658,373 257,484 3,301 — —
Benchmark Comparison Details

Master baseline: latest master-* experiment (post-merge regression eval)
Status: 14 test/model combinations loaded

Benchmark baseline: latest ci-benchmark experiment on master
Status: 17 test/model combinations loaded

Time comparison (seconds):

Test case This branch master (1h ago) Δ vs master benchmark (1d ago) Δ vs benchmark
09_crashpod (opus-4.6) 📄 24.0s 28.5s ↓16% — —
101_loki_historical_logs_pod_deleted (opus-4.6) 📄 49.3s 39.9s ↑24% — —
112_find_pvcs_by_uuid (opus-4.6) 📄 15.3s 15.9s ±0% — —
12_job_crashing (opus-4.6) 📄 31.8s 31.5s ±0% — —
176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 31.3s 30.1s ±0% — —
227_count_configmaps_per_namespace[0] (opus-4.6) 📄 14.8s 15.3s ±0% — —
243_pod_names_contain_service (opus-4.6) 📄 24.7s 29.6s ↓17% — —
24_misconfigured_pvc (opus-4.6) 📄 30.7s 26.6s ↑15% — —
254_elasticsearch_dr_test_log_check (opus-4.6) 📄 45.8s 63.5s ↓28% — —
259_wrong_cluster_logs_confusion (opus-4.6) 📄 74.5s 67.2s ↑11% — —
260_global_es_remote_cluster_logs (opus-4.6) 📄 67.8s 61.1s ↑11% — —
43_current_datetime_from_prompt (opus-4.6) 📄 4.6s 3.8s ↑21% — —
51_logs_summarize_errors (opus-4.6) 📄 20.3s 20.0s ±0% — —
61_exact_match_counting (opus-4.6) 📄 7.6s 7.0s ±0% — —
Total (all, n=14) 31.6s 31.4s — — —
Comparable (m=14, b=0) 31.6s 31.4s ±0% — —

Cost comparison:

Test case This branch master (1h ago) Δ vs master benchmark (1d ago) Δ vs benchmark
09_crashpod (opus-4.6) 📄 $0.1894 $0.2099 ±0% — —
101_loki_historical_logs_pod_deleted (opus-4.6) 📄 $0.2577 $0.2267 ↑14% — —
112_find_pvcs_by_uuid (opus-4.6) 📄 $0.1611 $0.1626 ±0% — —
12_job_crashing (opus-4.6) 📄 $0.2297 $0.2249 ±0% — —
176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 $0.2174 $0.2185 ±0% — —
227_count_configmaps_per_namespace[0] (opus-4.6) 📄 $0.1501 $0.1491 ±0% — —
243_pod_names_contain_service (opus-4.6) 📄 $0.1691 $0.1885 ↓10% — —
24_misconfigured_pvc (opus-4.6) 📄 $0.2171 $0.2146 ±0% — —
254_elasticsearch_dr_test_log_check (opus-4.6) 📄 $0.2165 $0.3117 ↓31% — —
259_wrong_cluster_logs_confusion (opus-4.6) 📄 $0.3352 $0.2841 ↑18% — —
260_global_es_remote_cluster_logs (opus-4.6) 📄 $0.2996 $0.2971 ±0% — —
43_current_datetime_from_prompt (opus-4.6) 📄 $0.1017 $0.1017 ±0% — —
51_logs_summarize_errors (opus-4.6) 📄 $0.1540 $0.1596 ±0% — —
61_exact_match_counting (opus-4.6) 📄 $0.1146 $0.1146 ±0% — —
Total (all, n=14) $0.2009 $0.2045 — — —
Comparable (m=14, b=0) $0.2009 $0.2045 ±0% — —

Total tokens comparison:

Test case This branch master (1h ago) Δ vs master benchmark (1d ago) Δ vs benchmark
09_crashpod (opus-4.6) 📄 50,571 69,855 ↓28% — —
101_loki_historical_logs_pod_deleted (opus-4.6) 📄 90,444 69,694 ↑30% — —
112_find_pvcs_by_uuid (opus-4.6) 📄 33,872 33,603 ±0% — —
12_job_crashing (opus-4.6) 📄 75,082 72,627 ±0% — —
176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 87,499 70,868 ↑23% — —
227_count_configmaps_per_namespace[0] (opus-4.6) 📄 46,356 46,341 ±0% — —
243_pod_names_contain_service (opus-4.6) 📄 47,825 49,510 ±0% — —
24_misconfigured_pvc (opus-4.6) 📄 68,774 72,838 ±0% — —
254_elasticsearch_dr_test_log_check (opus-4.6) 📄 87,961 140,580 ↓37% — —
259_wrong_cluster_logs_confusion (opus-4.6) 📄 123,567 125,904 ±0% — —
260_global_es_remote_cluster_logs (opus-4.6) 📄 138,837 105,455 ↑32% — —
43_current_datetime_from_prompt (opus-4.6) 📄 14,429 14,429 ±0% — —
51_logs_summarize_errors (opus-4.6) 📄 46,688 47,086 ±0% — —
61_exact_match_counting (opus-4.6) 📄 29,149 29,148 ±0% — —
Total (all, n=14) 67,218 67,710 — — —
Comparable (m=14, b=0) 67,218 67,710 ±0% — —

Cached tokens comparison:

Test case This branch master (1h ago) Δ vs master benchmark (1d ago) Δ vs benchmark
09_crashpod (opus-4.6) 📄 29,458 47,922 ↓39% — —
101_loki_historical_logs_pod_deleted (opus-4.6) 📄 66,805 47,633 ↑40% — —
112_find_pvcs_by_uuid (opus-4.6) 📄 14,319 14,319 ±0% — —
12_job_crashing (opus-4.6) 📄 51,201 48,972 ±0% — —
176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 65,893 47,773 ↑38% — —
227_count_configmaps_per_namespace[0] (opus-4.6) 📄 28,980 28,979 ±0% — —
243_pod_names_contain_service (opus-4.6) 📄 29,080 29,445 ±0% — —
24_misconfigured_pvc (opus-4.6) 📄 46,505 49,907 ±0% — —
254_elasticsearch_dr_test_log_check (opus-4.6) 📄 69,763 116,265 ↓40% — —
259_wrong_cluster_logs_confusion (opus-4.6) 📄 96,824 104,659 ±0% — —
260_global_es_remote_cluster_logs (opus-4.6) 📄 116,336 81,118 ↑43% — —
43_current_datetime_from_prompt (opus-4.6) 📄 — — — — —
51_logs_summarize_errors (opus-4.6) 📄 28,926 28,946 ±0% — —
61_exact_match_counting (opus-4.6) 📄 14,283 14,283 ±0% — —
Total (all, n=14) 47,027 47,159 — — —
Comparable (m=13, b=0) 50,644 50,786 ±0% — —

Turns comparison:

Test case This branch master (1h ago) Δ vs master benchmark (1d ago) Δ vs benchmark
09_crashpod (opus-4.6) 📄 3 4 ↓25% — —
101_loki_historical_logs_pod_deleted (opus-4.6) 📄 5 4 ↑25% — —
112_find_pvcs_by_uuid (opus-4.6) 📄 2 2 ±0% — —
12_job_crashing (opus-4.6) 📄 4 4 ±0% — —
176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 5 4 ↑25% — —
227_count_configmaps_per_namespace[0] (opus-4.6) 📄 3 3 ±0% — —
243_pod_names_contain_service (opus-4.6) 📄 3 3 ±0% — —
24_misconfigured_pvc (opus-4.6) 📄 4 4 ±0% — —
254_elasticsearch_dr_test_log_check (opus-4.6) 📄 7 10 ↓30% — —
259_wrong_cluster_logs_confusion (opus-4.6) 📄 8 9 ↓11% — —
260_global_es_remote_cluster_logs (opus-4.6) 📄 10 7 ↑43% — —
43_current_datetime_from_prompt (opus-4.6) 📄 1 1 ±0% — —
51_logs_summarize_errors (opus-4.6) 📄 3 3 ±0% — —
61_exact_match_counting (opus-4.6) 📄 2 2 ±0% — —
Total (all, n=14) 4.3 4.3 — — —
Comparable (m=14, b=0) 4.3 4.3 ±0% — —

Tool calls comparison:

Test case This branch master (1h ago) Δ vs master benchmark (1d ago) Δ vs benchmark
09_crashpod (opus-4.6) 📄 7 8 ↓12% — —
101_loki_historical_logs_pod_deleted (opus-4.6) 📄 10 8 ↑25% — —
112_find_pvcs_by_uuid (opus-4.6) 📄 2 2 ±0% — —
12_job_crashing (opus-4.6) 📄 11 10 ↑10% — —
176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 10 9 ↑11% — —
227_count_configmaps_per_namespace[0] (opus-4.6) 📄 6 6 ±0% — —
243_pod_names_contain_service (opus-4.6) 📄 5 7 ↓29% — —
24_misconfigured_pvc (opus-4.6) 📄 11 9 ↑22% — —
254_elasticsearch_dr_test_log_check (opus-4.6) 📄 8 14 ↓43% — —
259_wrong_cluster_logs_confusion (opus-4.6) 📄 14 11 ↑27% — —
260_global_es_remote_cluster_logs (opus-4.6) 📄 12 13 ±0% — —
43_current_datetime_from_prompt (opus-4.6) 📄 — — — — —
51_logs_summarize_errors (opus-4.6) 📄 2 2 ±0% — —
61_exact_match_counting (opus-4.6) 📄 1 1 ±0% — —
Total (all, n=14) 7.1 7.7 — — —
Comparable (m=13, b=0) 7.6 7.7 ±0% — —

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📖 Legend
Icon Meaning
✅ The test was successful
➖ The test was skipped
⚠️ The test failed but is known to be flaky or known to fail
🚧 The test had a setup failure (not a code regression)
🔧 The test failed due to mock data issues (not a code regression)
🚫 The test was throttled by API rate limits/overload
❌ The test failed and should be fixed before merging the PR
🔄 Re-run evals manually

⚠️ Warning: /eval comments always run using the workflow from master, not from this PR branch. If you modified the GitHub Action (e.g., added secrets or env vars), those changes won't take effect.

To test workflow changes, use the GitHub CLI or Actions UI instead:

gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref claude/dazzling-gauss-nespl7 -f markers=regression -f filter=

Option 1: Comment on this PR with /eval:

/eval
tags: regression

Or with more options (one per line):

/eval
model: gpt-4o
tags: regression
id: 09_crashpod
iterations: 5

Run evals on a different branch (e.g., master) for comparison:

/eval
branch: master
tags: regression
Option Description
model Model(s) to test (default: same as automatic runs)
tags Pytest tags / markers (no default - runs all tests!)
id Eval ID / pytest -k filter (use /list to see valid eval names)
iterations Number of runs, max 10
branch Run evals on a different branch (for cross-branch comparison)

Quick re-run: Use /rerun to re-run the most recent /eval on this PR with the same parameters.

Option 2: Trigger via GitHub Actions UI → "Run workflow"

Option 3: Add PR labels to include extra evals (applies to both automatic runs and /eval comments):

Label Effect
evals-tag-<name> Run tests with tag <name> alongside regression
evals-id-<name> Run a specific eval by test ID
evals-model-<name> Override the model (use model list name, e.g. sonnet-4.5)

Examples: evals-tag-easy, evals-id-09_crashpod, evals-model-sonnet-4.5

🏷️ Valid tags

benchmark, chain-of-causation, compaction, confluence, context_window, conversation_worker, coralogix, counting, database, datadog, datetime, db-connectors, easy, elasticsearch, embeds, fast, frontend, grafana, hard, images, integration, kafka, kubernetes, leaked-information, logs, loki, manual, mcp, medium, metrics, multi-cluster, network, newrelic, no-cicd, numerical, one-test, port-forward, prometheus, question-answer, regression, skills, slackbot, storage, token-limit, toolset-limitation, traces, transparency, victorialogs

🤖 Valid models

deepseek-chat, deepseek-r1-reasoner, deepseek-reasoner, deepseek-v3.2-chat, fable-5, gemini-3-flash-preview, gemini-3-pro-preview, gemini-3.1-pro-preview, gpt-4.1, gpt-5.2-high-reasoning, gpt-5.3-codex, gpt-5.4, gpt-5.5, haiku-4.5, kimi-2.5, kimi-2.5-openrouter, opus-4.5, opus-4.6, opus-4.7, opus-4.8, qwen-next-80B-instruct, qwen-next-80B-thinking, sonnet-4.5, sonnet-4.6


Commands: /eval · /rerun · /list

CLI: gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref claude/dazzling-gauss-nespl7 -f markers=regression -f filter=

@netlify

netlify Bot commented Jun 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for holmes-docs ready!

Name Link
🔨 Latest commit 912b95a
🔍 Latest deploy log https://app.netlify.com/projects/holmes-docs/deploys/6a3049ba6703a80008595844
😎 Deploy Preview https://deploy-preview-2193--holmes-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Jun 14, 2026 •

Copy link
Copy Markdown
Contributor

✅ Docker images ready for 702e60726 (built in 5m 9s)

⚠️ Warning: does not support ARM (ARM images are built on release only - not on every PR)

Use these tags to pull the images for testing.

📋 Copy commands

⚠️ Temporary images are deleted after 30 days. Copy to a permanent registry before using them:

gcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:702e60726
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:702e60726 me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:702e60726
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:702e60726
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:702e60726
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:702e60726 me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:702e60726
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:702e60726

Patch Helm values in one line (choose the chart you use):

HolmesGPT chart:

helm upgrade --install holmesgpt ./helm/holmes \
  --set registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set image=holmes-dev:702e60726 \
  --set operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set operator.image=holmes-operator-dev:702e60726

Robusta wrapper chart:

helm upgrade --install robusta robusta/robusta \
  --reuse-values \
  --set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.image=holmes-dev:702e60726 \
  --set holmes.operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.operator.image=holmes-operator-dev:702e60726

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/reference/troubleshooting.md`:
- Around line 80-82: The fenced code block containing the httpx.ConnectError
message is missing a language identifier after the opening triple backticks. Add
`text` as the language specifier to the opening fence markers (change ``` to
```text) to resolve the markdownlint warning and ensure proper rendering of the
code block.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d37cb62f-7014-49d5-93fe-e130d564af4d

📥 Commits

Reviewing files that changed from the base of the PR and between 48c4921 and 21513c0.

📒 Files selected for processing (3)
  • docs/reference/troubleshooting.md
  • holmes/core/supabase_dal.py
  • tests/core/test_supabase_dal.py

Comment thread docs/reference/troubleshooting.md Outdated
claude and others added 16 commits June 14, 2026 14:17
…ector

Use the robusta-region fence for the Supabase health-check command so the
troubleshooting page shows the correct host per region (US/EU/AP), matching how
other docs pages present regional URLs. Extend ROBUSTA_DOMAIN_RE to also rewrite
the sp.robusta.dev (Supabase) host, not just api/platform.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
…LAUDE.md

The fence now rewrites sp.robusta.dev (Supabase host) in addition to
api/platform, so keep the CLAUDE.md guidance in sync: list sp.robusta.dev,
point at ROBUSTA_DOMAIN_RE for the covered-host set, and add troubleshooting.md
to the existing-usages list.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
…the pod

On this error the Holmes pod exits at startup and goes into CrashLoopBackOff
(the sign-in runs at module import in server.py with no try/except), so
`kubectl exec` into it doesn't work. Change the troubleshooting command to run
curl from a temporary pod in the same namespace, and reword the exception
message accordingly.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
The Holmes image already ships curl and is cached on the node, so reusing it
avoids a second image pull (which the same firewall may also block) and tests
egress with Holmes's exact CA/network config. Derive the image from the existing
deployment instead of pulling curlimages/curl.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
… image

Replace the <holmes-deployment>/<holmes-namespace> placeholders with a command
that discovers the Holmes pod by its stable `app=holmes` label (works even in
CrashLoopBackOff) and reuses its namespace and image. The user only picks a
region tab; nothing needs editing after copying.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
Embed a terminal-style screenshot in the troubleshooting section showing the
WARNING line and the SupabaseConnectionException traceback exactly as Holmes
prints them at startup, so users can visually match what they see in
`kubectl logs`.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
…he docs

The startup message duplicated the docs (curl command, run-from-another-pod
steps, per-region subdomains) inside a traceback, making it noisy. Trim both the
WARNING log and the SupabaseConnectionException message to a short statement of
the cause + the key fix (allowlist *.robusta.dev) and a link to the
troubleshooting docs for the full steps. Regenerate the log screenshot to match.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
The WARNING log and the exception both carried the docs URL, so it showed up
twice in the startup logs. Keep the URL (and the fix) only in the
SupabaseConnectionException message and reduce the WARNING to a short heads-up
that points to the error below. Regenerate the screenshot to match.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
Put all the actionable instruction (cause, allowlist '*.robusta.dev', docs link)
in the WARNING log that prints above the traceback, and reduce
SupabaseConnectionException to a thin technical wrapper around the underlying
connection error. Update the test and regenerate the screenshot to match.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
The screenshot was only for review, not for the published docs. Drop the image
embed and delete the asset; the text description of the error remains.

https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Signed-off-by: Claude <noreply@anthropic.com>
@RoiGlinik
RoiGlinik merged commit 175fdb6 into master Jun 16, 2026
19 of 22 checks passed
@RoiGlinik
RoiGlinik deleted the claude/dazzling-gauss-nespl7 branch June 16, 2026 08:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants