Skip to content
- Health:
/health/live has no dependencies. /health/ready checks postgres, schema (no pending migration), stream (unhealthy
only when an enabled stream loop stopped) and timezones.
- Metrics: Prometheus at
/metrics, including stayfn.invocations, stayfn.ohip_calls, stayfn.rate_limited, duration histograms,
queue depths, stream lag and stayfn.usage.*. Traces and metrics go to OTLP when OTEL_EXPORTER_OTLP_ENDPOINT is set.
- Logs: Serilog compact JSON on stdout with a correlation id on every line. PII is masked: e-mail, phone and card patterns, plus
guest-data field names.
- Capacity: one replica served about 1,000 req/s of a one-OHIP-call function on 4 vCPU, and 6,000 events/min. OHIP’s ~50 req/s per app
key is the real ceiling. Beyond 64 requests in flight and 128 queued the host sheds load with
503. See docs/limits.md.
- Retention: a worker deletes old invocations, OHIP call records, inbox/outbox rows, dead letters, audit and usage per tenant
(
Retention:* windows).
- Runbooks (
docs/runbooks/): token failures, rate-limit exhaustion, dead-letter storm, stream stalled, backup and restore.