Skip to content
Stackship documentation Svenska

SentinelUsers

Findings

What a Sentinel finding contains, what its severities, categories and statuses mean, and when it closes, reopens and is deleted.

Requires: sentinel/read

What a finding shows

Part Contents
Severity and Category See Severity and category
What's happening What was found, in plain language
Impact What it causes if nothing is done
How to fix it Numbered steps — see Steps and who does them
Looks like a Stackship bug Shown when Sentinel suspects a bug in Stackship itself: what to include in a report, and possibly Report to Stackship — see Report a Stackship bug
How to Verify How to check that the fix worked
Technical details Collapsed: the Evidence Sentinel based the finding on — see Evidence
Details Owner (the suggested owner), Category, Severity, Status, First seen, Last seen, Status changed, Resolved at, Fingerprint and Resource

Seen N times counts every run and every rule check that saw the problem again; a rule finding therefore counts up every couple of minutes for as long as the failure lasts.

Severity and category

Severity Meaning
Critical Needs attention now — an active vulnerability or a severe misconfiguration
High Should be addressed soon — a significant risk
Medium A moderate risk worth fixing
Low A minor issue or a best-practice improvement

The category is Security, Performance, Reliability or Code. When a finding is seen again with a higher severity, it takes the higher one; it is never lowered.

Steps and who does them

Each step needs a permission on the resource, such as changing or scaling it or reading its logs, and you are shown only the steps you hold that permission for in the boundary. A note says how many more steps there are; ask your Boundary Owner, or Operations. A step that needs no permission, such as waiting, is shown to everyone.

When the fix is not yours to make, the finding says so under Contact Operations or Contact Stackship Support, with the reason. When nothing needs doing, it says No action is needed from you right now. Findings recorded before steps existed show their original recommendation text.

Evidence

Each piece of evidence shows its type and source, the namespace and object it came from, its time range, and its content, expanded on request. Log evidence also shows the pod and container, whether the lines are from the Previous container — the one that crashed — and whether older lines were cut off.

Evidence is kept only while a recent run or check refers to it. An older finding says No evidence is stored for this finding.

Caution

Evidence is shown to everyone who can read the boundary's findings — also log lines, which reach a finding through Analyze with logs or when the platform operator has turned on log evidence. Someone who may not read a resource's logs can therefore read the lines stored on a finding about it. Everything is redacted first, but redaction only catches recognisable shapes.

Statuses

Status Meaning
Open New, or still present, and not reviewed
Acknowledged Reviewed and accepted as real, not fixed yet
Resolved No longer seen
Manually resolved Marked as fixed by a person
False positive Not a real problem
Won't fix A real problem that will not be addressed

Open and Acknowledged findings are active: they are what Active alerts and Active by Category count.

Closing, reopening and deletion

  • Closing. An Open or Acknowledged finding that has not been seen for two analysis intervals — an hour by default — becomes Resolved. For rule findings the hour counts from the last rule check that saw it. A run whose language model gave no usable answer closes none of the findings the model wrote.
  • Reopening. A Resolved or Manually resolved finding that is seen again becomes Open.
  • Judgements stay. False positive and Won't fix never change by themselves, however often the problem is seen again.
  • Deletion. Resolved and Manually resolved findings are deleted 30 days after they closed, by default. Active findings, False positive and Won't fix are never deleted.