Add firewall detection and user-friendly error handling for Supabase sign-in - #2193
Conversation
…ed (ROB-293) When Holmes starts behind an outbound firewall that blocks egress to the Robusta platform, sign-in to Supabase fails with `httpx.ConnectError: [Errno 104] Connection reset by peer` (ROB-273). DNS resolves and the TLS cert is fine, so the existing SupabaseDnsException did not match and the user only saw a raw httpx traceback with no guidance. Detect connection reset/refused/timeout errors in SupabaseDal.sign_in() and raise a new SupabaseConnectionException that logs an actionable ERROR and explains how to fix it: allowlist outbound HTTPS to *.robusta.dev, plus a `curl -vk <url>/auth/v1/health` command to confirm the block. DNS errors and genuine auth failures keep their existing behavior. Also treat SupabaseConnectionException as transient in the conversation worker / realtime reconnect loops, mirroring SupabaseDnsException, so a firewall block during reconnect is retried with backoff instead of being surfaced as an unexpected defect. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
…(ROB-293) - Log the firewall hint at WARNING instead of ERROR in SupabaseDal.sign_in(); ERROR-level logs raise Sentry alerts, which we don't want for a user-side network misconfiguration. - Revert the SupabaseConnectionException additions to the conversation worker and realtime reconnect tuples. This is a Supabase login-flow issue; the reconnect loops don't call sign_in directly, so keep the change scoped to it. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
… log (ROB-293) Add a Troubleshooting section documenting the startup "Connection reset by peer" failure: outbound firewall blocking egress to the Robusta platform, how to allowlist *.robusta.dev, and a curl health-check to confirm. Cross-links the related LITELLM_MODEL_COST_MAP_URL egress note. Link to that section from both the WARNING log and the SupabaseConnectionException message so users hitting the error can find the fix. The heading carries a pinned anchor (firewall-blocking-robusta-platform) so the in-log URL stays stable. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughAdds ChangesFirewall Connection Error Detection and Docs
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
📂 Previous Runs
|
| Status | Test case | Time | Turns | Tools | Cost | Total tokens | Input | Max input | Output | Max output | Cached | Non-cached | Reasoning | Compactions | Denied commands | Src |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ✅ | 09_crashpod | 24.0s | 3 | 7 | $0.1894 | 50,571 | 49,134 | 18,878 | 1,437 | 664 | 29,458 | 19,676 | 127 | — | — | src |
| ✅ | 101_loki_historical_logs_pod_deleted | 49.3s | 5 | 10 | $0.2577 | 90,444 | 87,590 | 20,510 | 2,854 | 889 | 66,805 | 20,785 | 496 | — | — | src |
| ✅ | 112_find_pvcs_by_uuid | 15.3s | 2 | 2 | $0.1611 | 33,872 | 32,919 | 18,597 | 953 | 591 | 14,319 | 18,600 | 132 | — | — | src |
| ✅ | 12_job_crashing | 31.8s | 4 | 11 | $0.2297 | 75,082 | 73,205 | 21,444 | 1,877 | 541 | 51,201 | 22,004 | 77 | — | — | src |
| ✅ | 176_network_policy_blocking_traffic_no_skills | 31.3s | 5 | 10 | $0.2174 | 87,499 | 85,883 | 19,441 | 1,616 | 506 | 65,893 | 19,990 | 248 | — | — | src |
| ✅ | 227_count_configmaps_per_namespace[0] | 14.8s | 3 | 6 | $0.1501 | 46,356 | 45,645 | 16,661 | 711 | 438 | 28,980 | 16,665 | 29 | — | — | src |
| ✅ | 243_pod_names_contain_service | 24.7s | 3 | 5 | $0.1691 | 47,825 | 46,589 | 17,233 | 1,236 | 455 | 29,080 | 17,509 | 192 | — | — | src |
| ✅ | 24_misconfigured_pvc | 30.7s | 4 | 11 | $0.2171 | 68,774 | 66,817 | 19,350 | 1,957 | 547 | 46,505 | 20,312 | 204 | — | — | src |
| ✅ | 254_elasticsearch_dr_test_log_check | 45.8s | 7 | 8 | $0.2165 | 87,961 | 85,392 | 15,621 | 2,569 | 786 | 69,763 | 15,629 | 280 | — | — | src |
| ✅ | 259_wrong_cluster_logs_confusion | 74.5s | 8 | 14 | $0.3352 | 123,567 | 118,668 | 19,936 | 4,899 | 1,706 | 96,824 | 21,844 | 768 | — | — | src |
| ✅ | 260_global_es_remote_cluster_logs | 67.8s | 10 | 12 | $0.2996 | 138,837 | 134,868 | 17,871 | 3,969 | 1,232 | 116,336 | 18,532 | 605 | — | — | src |
| ✅ | 43_current_datetime_from_prompt | 4.6s | 1 | — | $0.1017 | 14,429 | 14,306 | 14,306 | 123 | 123 | 0 | 14,306 | 79 | — | — | src |
| ✅ | 51_logs_summarize_errors | 20.3s | 3 | 2 | $0.1540 | 46,688 | 45,913 | 16,983 | 775 | 400 | 28,926 | 16,987 | 30 | — | — | src |
| ✅ | 61_exact_match_counting | 7.6s | 2 | 1 | $0.1146 | 29,149 | 28,928 | 14,642 | 221 | 152 | 14,283 | 14,645 | 34 | — | — | src |
| Total | 31.6s avg | 4.3 avg | 7.6 avg | $2.8133 | 941,054 | 915,857 | 21,444 | 25,197 | 1,706 | 658,373 | 257,484 | 3,301 | — | — |
Benchmark Comparison Details
Master baseline: latest master-* experiment (post-merge regression eval)
Status: 14 test/model combinations loaded
- master-27567520918 (created: 2026-06-15)
Benchmark baseline: latest ci-benchmark experiment on master
Status: 17 test/model combinations loaded
- ci-benchmark-27491953079 (created: 2026-06-14)
Time comparison (seconds):
| Test case | This branch | master (1h ago) | Δ vs master | benchmark (1d ago) | Δ vs benchmark |
|---|---|---|---|---|---|
| 09_crashpod (opus-4.6) 📄 | 24.0s | 28.5s | ↓16% | — | — |
| 101_loki_historical_logs_pod_deleted (opus-4.6) 📄 | 49.3s | 39.9s | ↑24% | — | — |
| 112_find_pvcs_by_uuid (opus-4.6) 📄 | 15.3s | 15.9s | ±0% | — | — |
| 12_job_crashing (opus-4.6) 📄 | 31.8s | 31.5s | ±0% | — | — |
| 176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 | 31.3s | 30.1s | ±0% | — | — |
| 227_count_configmaps_per_namespace[0] (opus-4.6) 📄 | 14.8s | 15.3s | ±0% | — | — |
| 243_pod_names_contain_service (opus-4.6) 📄 | 24.7s | 29.6s | ↓17% | — | — |
| 24_misconfigured_pvc (opus-4.6) 📄 | 30.7s | 26.6s | ↑15% | — | — |
| 254_elasticsearch_dr_test_log_check (opus-4.6) 📄 | 45.8s | 63.5s | ↓28% | — | — |
| 259_wrong_cluster_logs_confusion (opus-4.6) 📄 | 74.5s | 67.2s | ↑11% | — | — |
| 260_global_es_remote_cluster_logs (opus-4.6) 📄 | 67.8s | 61.1s | ↑11% | — | — |
| 43_current_datetime_from_prompt (opus-4.6) 📄 | 4.6s | 3.8s | ↑21% | — | — |
| 51_logs_summarize_errors (opus-4.6) 📄 | 20.3s | 20.0s | ±0% | — | — |
| 61_exact_match_counting (opus-4.6) 📄 | 7.6s | 7.0s | ±0% | — | — |
| Total (all, n=14) | 31.6s | 31.4s | — | — | — |
| Comparable (m=14, b=0) | 31.6s | 31.4s | ±0% | — | — |
Cost comparison:
| Test case | This branch | master (1h ago) | Δ vs master | benchmark (1d ago) | Δ vs benchmark |
|---|---|---|---|---|---|
| 09_crashpod (opus-4.6) 📄 | $0.1894 | $0.2099 | ±0% | — | — |
| 101_loki_historical_logs_pod_deleted (opus-4.6) 📄 | $0.2577 | $0.2267 | ↑14% | — | — |
| 112_find_pvcs_by_uuid (opus-4.6) 📄 | $0.1611 | $0.1626 | ±0% | — | — |
| 12_job_crashing (opus-4.6) 📄 | $0.2297 | $0.2249 | ±0% | — | — |
| 176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 | $0.2174 | $0.2185 | ±0% | — | — |
| 227_count_configmaps_per_namespace[0] (opus-4.6) 📄 | $0.1501 | $0.1491 | ±0% | — | — |
| 243_pod_names_contain_service (opus-4.6) 📄 | $0.1691 | $0.1885 | ↓10% | — | — |
| 24_misconfigured_pvc (opus-4.6) 📄 | $0.2171 | $0.2146 | ±0% | — | — |
| 254_elasticsearch_dr_test_log_check (opus-4.6) 📄 | $0.2165 | $0.3117 | ↓31% | — | — |
| 259_wrong_cluster_logs_confusion (opus-4.6) 📄 | $0.3352 | $0.2841 | ↑18% | — | — |
| 260_global_es_remote_cluster_logs (opus-4.6) 📄 | $0.2996 | $0.2971 | ±0% | — | — |
| 43_current_datetime_from_prompt (opus-4.6) 📄 | $0.1017 | $0.1017 | ±0% | — | — |
| 51_logs_summarize_errors (opus-4.6) 📄 | $0.1540 | $0.1596 | ±0% | — | — |
| 61_exact_match_counting (opus-4.6) 📄 | $0.1146 | $0.1146 | ±0% | — | — |
| Total (all, n=14) | $0.2009 | $0.2045 | — | — | — |
| Comparable (m=14, b=0) | $0.2009 | $0.2045 | ±0% | — | — |
Total tokens comparison:
| Test case | This branch | master (1h ago) | Δ vs master | benchmark (1d ago) | Δ vs benchmark |
|---|---|---|---|---|---|
| 09_crashpod (opus-4.6) 📄 | 50,571 | 69,855 | ↓28% | — | — |
| 101_loki_historical_logs_pod_deleted (opus-4.6) 📄 | 90,444 | 69,694 | ↑30% | — | — |
| 112_find_pvcs_by_uuid (opus-4.6) 📄 | 33,872 | 33,603 | ±0% | — | — |
| 12_job_crashing (opus-4.6) 📄 | 75,082 | 72,627 | ±0% | — | — |
| 176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 | 87,499 | 70,868 | ↑23% | — | — |
| 227_count_configmaps_per_namespace[0] (opus-4.6) 📄 | 46,356 | 46,341 | ±0% | — | — |
| 243_pod_names_contain_service (opus-4.6) 📄 | 47,825 | 49,510 | ±0% | — | — |
| 24_misconfigured_pvc (opus-4.6) 📄 | 68,774 | 72,838 | ±0% | — | — |
| 254_elasticsearch_dr_test_log_check (opus-4.6) 📄 | 87,961 | 140,580 | ↓37% | — | — |
| 259_wrong_cluster_logs_confusion (opus-4.6) 📄 | 123,567 | 125,904 | ±0% | — | — |
| 260_global_es_remote_cluster_logs (opus-4.6) 📄 | 138,837 | 105,455 | ↑32% | — | — |
| 43_current_datetime_from_prompt (opus-4.6) 📄 | 14,429 | 14,429 | ±0% | — | — |
| 51_logs_summarize_errors (opus-4.6) 📄 | 46,688 | 47,086 | ±0% | — | — |
| 61_exact_match_counting (opus-4.6) 📄 | 29,149 | 29,148 | ±0% | — | — |
| Total (all, n=14) | 67,218 | 67,710 | — | — | — |
| Comparable (m=14, b=0) | 67,218 | 67,710 | ±0% | — | — |
Cached tokens comparison:
| Test case | This branch | master (1h ago) | Δ vs master | benchmark (1d ago) | Δ vs benchmark |
|---|---|---|---|---|---|
| 09_crashpod (opus-4.6) 📄 | 29,458 | 47,922 | ↓39% | — | — |
| 101_loki_historical_logs_pod_deleted (opus-4.6) 📄 | 66,805 | 47,633 | ↑40% | — | — |
| 112_find_pvcs_by_uuid (opus-4.6) 📄 | 14,319 | 14,319 | ±0% | — | — |
| 12_job_crashing (opus-4.6) 📄 | 51,201 | 48,972 | ±0% | — | — |
| 176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 | 65,893 | 47,773 | ↑38% | — | — |
| 227_count_configmaps_per_namespace[0] (opus-4.6) 📄 | 28,980 | 28,979 | ±0% | — | — |
| 243_pod_names_contain_service (opus-4.6) 📄 | 29,080 | 29,445 | ±0% | — | — |
| 24_misconfigured_pvc (opus-4.6) 📄 | 46,505 | 49,907 | ±0% | — | — |
| 254_elasticsearch_dr_test_log_check (opus-4.6) 📄 | 69,763 | 116,265 | ↓40% | — | — |
| 259_wrong_cluster_logs_confusion (opus-4.6) 📄 | 96,824 | 104,659 | ±0% | — | — |
| 260_global_es_remote_cluster_logs (opus-4.6) 📄 | 116,336 | 81,118 | ↑43% | — | — |
| 43_current_datetime_from_prompt (opus-4.6) 📄 | — | — | — | — | — |
| 51_logs_summarize_errors (opus-4.6) 📄 | 28,926 | 28,946 | ±0% | — | — |
| 61_exact_match_counting (opus-4.6) 📄 | 14,283 | 14,283 | ±0% | — | — |
| Total (all, n=14) | 47,027 | 47,159 | — | — | — |
| Comparable (m=13, b=0) | 50,644 | 50,786 | ±0% | — | — |
Turns comparison:
| Test case | This branch | master (1h ago) | Δ vs master | benchmark (1d ago) | Δ vs benchmark |
|---|---|---|---|---|---|
| 09_crashpod (opus-4.6) 📄 | 3 | 4 | ↓25% | — | — |
| 101_loki_historical_logs_pod_deleted (opus-4.6) 📄 | 5 | 4 | ↑25% | — | — |
| 112_find_pvcs_by_uuid (opus-4.6) 📄 | 2 | 2 | ±0% | — | — |
| 12_job_crashing (opus-4.6) 📄 | 4 | 4 | ±0% | — | — |
| 176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 | 5 | 4 | ↑25% | — | — |
| 227_count_configmaps_per_namespace[0] (opus-4.6) 📄 | 3 | 3 | ±0% | — | — |
| 243_pod_names_contain_service (opus-4.6) 📄 | 3 | 3 | ±0% | — | — |
| 24_misconfigured_pvc (opus-4.6) 📄 | 4 | 4 | ±0% | — | — |
| 254_elasticsearch_dr_test_log_check (opus-4.6) 📄 | 7 | 10 | ↓30% | — | — |
| 259_wrong_cluster_logs_confusion (opus-4.6) 📄 | 8 | 9 | ↓11% | — | — |
| 260_global_es_remote_cluster_logs (opus-4.6) 📄 | 10 | 7 | ↑43% | — | — |
| 43_current_datetime_from_prompt (opus-4.6) 📄 | 1 | 1 | ±0% | — | — |
| 51_logs_summarize_errors (opus-4.6) 📄 | 3 | 3 | ±0% | — | — |
| 61_exact_match_counting (opus-4.6) 📄 | 2 | 2 | ±0% | — | — |
| Total (all, n=14) | 4.3 | 4.3 | — | — | — |
| Comparable (m=14, b=0) | 4.3 | 4.3 | ±0% | — | — |
Tool calls comparison:
| Test case | This branch | master (1h ago) | Δ vs master | benchmark (1d ago) | Δ vs benchmark |
|---|---|---|---|---|---|
| 09_crashpod (opus-4.6) 📄 | 7 | 8 | ↓12% | — | — |
| 101_loki_historical_logs_pod_deleted (opus-4.6) 📄 | 10 | 8 | ↑25% | — | — |
| 112_find_pvcs_by_uuid (opus-4.6) 📄 | 2 | 2 | ±0% | — | — |
| 12_job_crashing (opus-4.6) 📄 | 11 | 10 | ↑10% | — | — |
| 176_network_policy_blocking_traffic_no_skills (opus-4.6) 📄 | 10 | 9 | ↑11% | — | — |
| 227_count_configmaps_per_namespace[0] (opus-4.6) 📄 | 6 | 6 | ±0% | — | — |
| 243_pod_names_contain_service (opus-4.6) 📄 | 5 | 7 | ↓29% | — | — |
| 24_misconfigured_pvc (opus-4.6) 📄 | 11 | 9 | ↑22% | — | — |
| 254_elasticsearch_dr_test_log_check (opus-4.6) 📄 | 8 | 14 | ↓43% | — | — |
| 259_wrong_cluster_logs_confusion (opus-4.6) 📄 | 14 | 11 | ↑27% | — | — |
| 260_global_es_remote_cluster_logs (opus-4.6) 📄 | 12 | 13 | ±0% | — | — |
| 43_current_datetime_from_prompt (opus-4.6) 📄 | — | — | — | — | — |
| 51_logs_summarize_errors (opus-4.6) 📄 | 2 | 2 | ±0% | — | — |
| 61_exact_match_counting (opus-4.6) 📄 | 1 | 1 | ±0% | — | — |
| Total (all, n=14) | 7.1 | 7.7 | — | — | — |
| Comparable (m=13, b=0) | 7.6 | 7.7 | ±0% | — | — |
Comparison indicators:
±0%— diff under 10% (within noise threshold)↑N%/↓N%— diff 10-25%↑N%/↓N%— diff over 25% (significant)
📖 Legend
| Icon | Meaning |
|---|---|
| ✅ | The test was successful |
| ➖ | The test was skipped |
| The test failed but is known to be flaky or known to fail | |
| 🚧 | The test had a setup failure (not a code regression) |
| 🔧 | The test failed due to mock data issues (not a code regression) |
| 🚫 | The test was throttled by API rate limits/overload |
| ❌ | The test failed and should be fixed before merging the PR |
🔄 Re-run evals manually
⚠️ Warning:/evalcomments always run using the workflow from master, not from this PR branch. If you modified the GitHub Action (e.g., added secrets or env vars), those changes won't take effect.To test workflow changes, use the GitHub CLI or Actions UI instead:
gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref claude/dazzling-gauss-nespl7 -f markers=regression -f filter=
Option 1: Comment on this PR with /eval:
/eval
tags: regression
Or with more options (one per line):
/eval
model: gpt-4o
tags: regression
id: 09_crashpod
iterations: 5
Run evals on a different branch (e.g., master) for comparison:
/eval
branch: master
tags: regression
| Option | Description |
|---|---|
model |
Model(s) to test (default: same as automatic runs) |
tags |
Pytest tags / markers (no default - runs all tests!) |
id |
Eval ID / pytest -k filter (use /list to see valid eval names) |
iterations |
Number of runs, max 10 |
branch |
Run evals on a different branch (for cross-branch comparison) |
Quick re-run: Use /rerun to re-run the most recent /eval on this PR with the same parameters.
Option 2: Trigger via GitHub Actions UI → "Run workflow"
Option 3: Add PR labels to include extra evals (applies to both automatic runs and /eval comments):
| Label | Effect |
|---|---|
evals-tag-<name> |
Run tests with tag <name> alongside regression |
evals-id-<name> |
Run a specific eval by test ID |
evals-model-<name> |
Override the model (use model list name, e.g. sonnet-4.5) |
Examples: evals-tag-easy, evals-id-09_crashpod, evals-model-sonnet-4.5
🏷️ Valid tags
benchmark, chain-of-causation, compaction, confluence, context_window, conversation_worker, coralogix, counting, database, datadog, datetime, db-connectors, easy, elasticsearch, embeds, fast, frontend, grafana, hard, images, integration, kafka, kubernetes, leaked-information, logs, loki, manual, mcp, medium, metrics, multi-cluster, network, newrelic, no-cicd, numerical, one-test, port-forward, prometheus, question-answer, regression, skills, slackbot, storage, token-limit, toolset-limitation, traces, transparency, victorialogs
🤖 Valid models
deepseek-chat, deepseek-r1-reasoner, deepseek-reasoner, deepseek-v3.2-chat, fable-5, gemini-3-flash-preview, gemini-3-pro-preview, gemini-3.1-pro-preview, gpt-4.1, gpt-5.2-high-reasoning, gpt-5.3-codex, gpt-5.4, gpt-5.5, haiku-4.5, kimi-2.5, kimi-2.5-openrouter, opus-4.5, opus-4.6, opus-4.7, opus-4.8, qwen-next-80B-instruct, qwen-next-80B-thinking, sonnet-4.5, sonnet-4.6
Commands: /eval · /rerun · /list
CLI: gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref claude/dazzling-gauss-nespl7 -f markers=regression -f filter=
✅ Deploy Preview for holmes-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
✅ Docker images ready for
Use these tags to pull the images for testing. 📋 Copy commandsgcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:702e60726
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:702e60726 me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:702e60726
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:702e60726
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:702e60726
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:702e60726 me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:702e60726
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:702e60726Patch Helm values in one line (choose the chart you use): HolmesGPT chart: helm upgrade --install holmesgpt ./helm/holmes \
--set registry=me-west1-docker.pkg.dev/robusta-development/development \
--set image=holmes-dev:702e60726 \
--set operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
--set operator.image=holmes-operator-dev:702e60726Robusta wrapper chart: helm upgrade --install robusta robusta/robusta \
--reuse-values \
--set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
--set holmes.image=holmes-dev:702e60726 \
--set holmes.operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
--set holmes.operator.image=holmes-operator-dev:702e60726 |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/reference/troubleshooting.md`:
- Around line 80-82: The fenced code block containing the httpx.ConnectError
message is missing a language identifier after the opening triple backticks. Add
`text` as the language specifier to the opening fence markers (change ``` to
```text) to resolve the markdownlint warning and ensure proper rendering of the
code block.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: d37cb62f-7014-49d5-93fe-e130d564af4d
📒 Files selected for processing (3)
docs/reference/troubleshooting.mdholmes/core/supabase_dal.pytests/core/test_supabase_dal.py
Addresses CodeRabbit review on PR #2193. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
…ector Use the robusta-region fence for the Supabase health-check command so the troubleshooting page shows the correct host per region (US/EU/AP), matching how other docs pages present regional URLs. Extend ROBUSTA_DOMAIN_RE to also rewrite the sp.robusta.dev (Supabase) host, not just api/platform. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
…LAUDE.md The fence now rewrites sp.robusta.dev (Supabase host) in addition to api/platform, so keep the CLAUDE.md guidance in sync: list sp.robusta.dev, point at ROBUSTA_DOMAIN_RE for the covered-host set, and add troubleshooting.md to the existing-usages list. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
…the pod On this error the Holmes pod exits at startup and goes into CrashLoopBackOff (the sign-in runs at module import in server.py with no try/except), so `kubectl exec` into it doesn't work. Change the troubleshooting command to run curl from a temporary pod in the same namespace, and reword the exception message accordingly. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
The Holmes image already ships curl and is cached on the node, so reusing it avoids a second image pull (which the same firewall may also block) and tests egress with Holmes's exact CA/network config. Derive the image from the existing deployment instead of pulling curlimages/curl. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
… image Replace the <holmes-deployment>/<holmes-namespace> placeholders with a command that discovers the Holmes pod by its stable `app=holmes` label (works even in CrashLoopBackOff) and reuses its namespace and image. The user only picks a region tab; nothing needs editing after copying. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
Embed a terminal-style screenshot in the troubleshooting section showing the WARNING line and the SupabaseConnectionException traceback exactly as Holmes prints them at startup, so users can visually match what they see in `kubectl logs`. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
…to claude/dazzling-gauss-nespl7
…he docs The startup message duplicated the docs (curl command, run-from-another-pod steps, per-region subdomains) inside a traceback, making it noisy. Trim both the WARNING log and the SupabaseConnectionException message to a short statement of the cause + the key fix (allowlist *.robusta.dev) and a link to the troubleshooting docs for the full steps. Regenerate the log screenshot to match. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
The WARNING log and the exception both carried the docs URL, so it showed up twice in the startup logs. Keep the URL (and the fix) only in the SupabaseConnectionException message and reduce the WARNING to a short heads-up that points to the error below. Regenerate the screenshot to match. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
Put all the actionable instruction (cause, allowlist '*.robusta.dev', docs link) in the WARNING log that prints above the traceback, and reduce SupabaseConnectionException to a thin technical wrapper around the underlying connection error. Update the test and regenerate the screenshot to match. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
The screenshot was only for review, not for the published docs. Drop the image embed and delete the asset; the text description of the error remains. https://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby Signed-off-by: Claude <noreply@anthropic.com>
Summary
Improve error handling during Supabase authentication to detect and clearly communicate firewall/egress policy issues that block connections to the Robusta platform. When Holmes fails to connect during sign-in, it now distinguishes between DNS failures, firewall blocks, and genuine authentication errors, providing actionable guidance to users.
Key Changes
SupabaseConnectionExceptionfor connection reset/refused/timeout errors that indicate firewall blocks, distinct fromSupabaseDnsExceptionfor DNS resolution failuresSupabaseDal.sign_in()to classify connection errors by examining exception types and error messages, detecting patterns like "connection reset by peer", "connection refused", "connection timed out", and errno codes (104, 111)*.robusta.devfor HTTPS (port 443)Implementation Details
ConnectionError,TimeoutError) and string pattern matching on error messages to catch various ways httpx and other libraries surface network failureshttps://claude.ai/code/session_01KVrzw7n3HtrfbSEZtRXZby
Summary by CodeRabbit
Release Notes
Documentation
sp), and a simplekubectl/curlconnectivity check.robusta-regiondocumentation and behavior to rewritesp.robusta.devin addition to existing Robusta subdomains.Improvements
Tests