The dashboard and /api/v1/status do not say why a nameserver or certificate check failed #225

Closed
opened 2026-10-02 07:35:33 +02:00 by clawbot · 1 comment
Collaborator

Found in the trial run for #149.

state.json keeps the reason for each failed nameserver query and each failed certificate check in error (README, State File Format). Neither the dashboard nor /api/v1/status shows it: the API has no error field, and the dashboard shows the status error with - in the records column, the same - a nameserver that answered with no records gets. The log does not have the reason either. In the run, every nameserver of pool.ntp.org, the 13 servers listed for a domain that does not exist, and the certificate of expired.badssl.com showed as failed with no way to learn why short of reading state.json inside the container, where the reasons were cannot resolve a.ntpns.org.: no authoritative nameservers found, server returned a referral and x509: certificate has expired or is not yet valid.

To see it, watch expired.badssl.com and look for the reason on the dashboard and in /api/v1/status. The API's types are in internal/handlers/status.go; the dashboard is internal/handlers/templates/dashboard.html.

Definition of done

  • /api/v1/status gives error for each nameserver entry and each certificate entry whose status is error.
  • The dashboard shows that reason in the entry's row, so a failed nameserver no longer looks like one that answered with no records.
  • README "Web Dashboard" and "HTTP API" say so.
  • A handler test covers a failed nameserver entry and a failed certificate entry.

Model: opus-5-5

Found in the trial run for https://git.eeqj.de/sneak/dnswatcher/issues/149. `state.json` keeps the reason for each failed nameserver query and each failed certificate check in `error` (README, State File Format). Neither the dashboard nor `/api/v1/status` shows it: the API has no `error` field, and the dashboard shows the status `error` with `-` in the records column, the same `-` a nameserver that answered with no records gets. The log does not have the reason either. In the run, every nameserver of `pool.ntp.org`, the 13 servers listed for a domain that does not exist, and the certificate of `expired.badssl.com` showed as failed with no way to learn why short of reading `state.json` inside the container, where the reasons were `cannot resolve a.ntpns.org.: no authoritative nameservers found`, `server returned a referral` and `x509: certificate has expired or is not yet valid`. To see it, watch `expired.badssl.com` and look for the reason on the dashboard and in `/api/v1/status`. The API's types are in `internal/handlers/status.go`; the dashboard is `internal/handlers/templates/dashboard.html`. ## Definition of done - `/api/v1/status` gives `error` for each nameserver entry and each certificate entry whose status is `error`. - The dashboard shows that reason in the entry's row, so a failed nameserver no longer looks like one that answered with no records. - README "Web Dashboard" and "HTTP API" say so. - A handler test covers a failed nameserver entry and a failed certificate entry. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 07:35:33 +02:00
Author
Collaborator

Built in #235: /api/v1/status gives error for each nameserver entry and certificate entry whose status is error, and the dashboard shows that reason in the entry's row.

Not done: the log still has no reason; this issue's definition of done does not ask for it.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/dnswatcher/pulls/235: `/api/v1/status` gives `error` for each nameserver entry and certificate entry whose status is `error`, and the dashboard shows that reason in the entry's row. Not done: the log still has no reason; this issue's definition of done does not ask for it. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#225