state.json keeps the reason for each failed nameserver query and each failed certificate check in error (README, State File Format). Neither the dashboard nor /api/v1/status shows it: the API has no error field, and the dashboard shows the status error with - in the records column, the same - a nameserver that answered with no records gets. The log does not have the reason either. In the run, every nameserver of pool.ntp.org, the 13 servers listed for a domain that does not exist, and the certificate of expired.badssl.com showed as failed with no way to learn why short of reading state.json inside the container, where the reasons were cannot resolve a.ntpns.org.: no authoritative nameservers found, server returned a referral and x509: certificate has expired or is not yet valid.
To see it, watch expired.badssl.com and look for the reason on the dashboard and in /api/v1/status. The API's types are in internal/handlers/status.go; the dashboard is internal/handlers/templates/dashboard.html.
Definition of done
/api/v1/status gives error for each nameserver entry and each certificate entry whose status is error.
The dashboard shows that reason in the entry's row, so a failed nameserver no longer looks like one that answered with no records.
README "Web Dashboard" and "HTTP API" say so.
A handler test covers a failed nameserver entry and a failed certificate entry.
Model: opus-5-5
Found in the trial run for https://git.eeqj.de/sneak/dnswatcher/issues/149.
`state.json` keeps the reason for each failed nameserver query and each failed certificate check in `error` (README, State File Format). Neither the dashboard nor `/api/v1/status` shows it: the API has no `error` field, and the dashboard shows the status `error` with `-` in the records column, the same `-` a nameserver that answered with no records gets. The log does not have the reason either. In the run, every nameserver of `pool.ntp.org`, the 13 servers listed for a domain that does not exist, and the certificate of `expired.badssl.com` showed as failed with no way to learn why short of reading `state.json` inside the container, where the reasons were `cannot resolve a.ntpns.org.: no authoritative nameservers found`, `server returned a referral` and `x509: certificate has expired or is not yet valid`.
To see it, watch `expired.badssl.com` and look for the reason on the dashboard and in `/api/v1/status`. The API's types are in `internal/handlers/status.go`; the dashboard is `internal/handlers/templates/dashboard.html`.
## Definition of done
- `/api/v1/status` gives `error` for each nameserver entry and each certificate entry whose status is `error`.
- The dashboard shows that reason in the entry's row, so a failed nameserver no longer looks like one that answered with no records.
- README "Web Dashboard" and "HTTP API" say so.
- A handler test covers a failed nameserver entry and a failed certificate entry.
Model: opus-5-5
clawbot
added this to the 1.0 milestone 2026-10-02 07:35:33 +02:00
Built in #235: /api/v1/status gives error for each nameserver entry and certificate entry whose status is error, and the dashboard shows that reason in the entry's row.
Not done: the log still has no reason; this issue's definition of done does not ask for it.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/dnswatcher/pulls/235: `/api/v1/status` gives `error` for each nameserver entry and certificate entry whose status is `error`, and the dashboard shows that reason in the entry's row.
Not done: the log still has no reason; this issue's definition of done does not ask for it.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found in the trial run for #149.
state.jsonkeeps the reason for each failed nameserver query and each failed certificate check inerror(README, State File Format). Neither the dashboard nor/api/v1/statusshows it: the API has noerrorfield, and the dashboard shows the statuserrorwith-in the records column, the same-a nameserver that answered with no records gets. The log does not have the reason either. In the run, every nameserver ofpool.ntp.org, the 13 servers listed for a domain that does not exist, and the certificate ofexpired.badssl.comshowed as failed with no way to learn why short of readingstate.jsoninside the container, where the reasons werecannot resolve a.ntpns.org.: no authoritative nameservers found,server returned a referralandx509: certificate has expired or is not yet valid.To see it, watch
expired.badssl.comand look for the reason on the dashboard and in/api/v1/status. The API's types are ininternal/handlers/status.go; the dashboard isinternal/handlers/templates/dashboard.html.Definition of done
/api/v1/statusgiveserrorfor each nameserver entry and each certificate entry whose status iserror.Model: opus-5-5
Built in #235:
/api/v1/statusgiveserrorfor each nameserver entry and certificate entry whose status iserror, and the dashboard shows that reason in the entry's row.Not done: the log still has no reason; this issue's definition of done does not ask for it.
Model: opus-5-5