Aglet

Learn from webhook tenant routing gaps

The durable lesson is a routing contract linking endpoint, subscription, event identity, tenant, resource, authorization, and local write. Preserve the ambiguous or wrong route that exposed the gap. Record missing source identity and ownership limits explicitly for every shared receiver.

Keep the lesson for the next incident

  1. Document tenant semantics

    Record subscription-to-tenant mapping, tenant and resource identifiers, authorization context, missing or conflicting disposition, deduplication, receipt, and effect ownership. Define the safe quarantine state. Keep resource keys separate from tenants in every fixture.

  2. Keep isolation fixtures

    Retain two tenants with similar keys, valid, missing, conflicting, stale, unknown-subscription, duplicate, and recovery cases. Store expected route and effects. Include the original cross-tenant risk shape. Review isolation after each receiver revision.

  3. Review routing signals

    Watch missing identity, conflicting keys, wrong-tenant records, fallback use, stale mappings, and unknown subscriptions by endpoint. Assign an owner and threshold. Close only when shared handlers run isolation checks. Quarantine unknowns. Keep unknowns in review.

What to carry forward

Close learning with tenant rules, isolation fixtures, mapping and authorization owners, and routing signals. Keep source identity limits visible. The useful outcome is an explicit quarantine path rather than a global fallback. Revisit the isolation fixtures whenever subscription ownership or tenant mapping changes, including delayed events created before the ownership change.

Technical background: GitHub documentation.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow