feat: post Dependabot alerts to cluster Alertmanager - #15
Merged
Conversation
Reusable retargeted from Grafana's embedded Alertmanager (which cannot ingest external alerts) to the kube-prometheus-stack Alertmanager at alertmanager.makeitwork.cloud; Grafana bearer dropped, Cloudflare Access headers only. The reusable moves to _dependabot-notify.yml because tfroot-github manages .github/workflows/dependabot-notify.yml as the caller in every repository, including this one; hosting the reusable at that path guaranteed it would be overwritten on the next tfroot-github apply.
xnoto
force-pushed
the
feat/alertmanager-target
branch
from
August 25, 2026 12:10
c578313 to
0912ea4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Retargets
dependabot-notify.ymlfrom Grafana's embedded Alertmanager to the kube-prometheus-stack Alertmanager athttps://alertmanager.makeitwork.cloud/api/v2/alerts(canonical Alertmanager v2 API, bare-array payload unchanged).Grafana 12 cannot ingest external alerts via that API without a registered Alertmanager datasource (400/404 proven in E2E), so the Grafana service account bearer is dropped — Alertmanager has no auth; the Cloudflare Access app (tfroot-cloudflare#21) is the gate.
Validation
pre-commit run -aclean (actionlint, gitleaks).Merge order
First. The kustomize-cluster#55 and tfroot-cloudflare#21 companions make the endpoint live; this one makes the workflow point at it.