Files
content-ingestion-agent/docs/operations.md

1014 B

Operations

Deployment and monitoring

Run the ASGI/queue adapter in the platform runtime with one worker per queue partition. Metrics: sync_runs_total{connector,mode,status}, duration, fetched/published/dead-letter counts, cursor age, webhook rejection count, and publication errors. Alert on dead letters, stale cursors, repeated authentication failures, and tenant-isolation violations.

Recovery

Retry dead-letter items with their original idempotency key after correcting source or credential errors. Re-run a scoped full sync to rebuild a cursor. Cursor save occurs after publication, so a crash may replay safely.

Security and lifecycle

Use a managed secret provider for credential_ref; rotate GitHub app tokens and Graph credentials without configuration commits. Verify GitHub HMAC and Microsoft Graph validation tokens at the ingress adapter. Encrypt transport and storage, minimize audit data, enforce tenant and ACL filters, and retain tombstones for the configured period before purge.