production-incident-responder

bởi kotlin

Hướng dẫn phản ứng sự cố sản xuất cho các dịch vụ Kotlin và Spring từ cảnh báo đầu tiên đến giảm thiểu, chẩn đoán và theo dõi. Sử dụng khi tỷ lệ lỗi tăng đột biến,…

npx skills add https://github.com/kotlin/kotlin-backend-agent-skills --skill production-incident-responder

Production Incident Responder

Source mapping: Tier 2 high-value skill derived from Kotlin_Spring_Developer_Pipeline.md (SK-24).

Mission

Restore service safely before chasing perfect explanations. Keep mitigation, diagnosis, communication, and evidence preservation disciplined and explicit.

First Principles

  • Mitigate first.
  • Prefer reversible actions over heroic code changes.
  • Preserve evidence while the system is still exhibiting the problem.
  • Separate confirmed facts from working hypotheses.

Inputs To Gather

  • Current alert state, user impact, and blast radius.
  • Recent deploys, config changes, feature-flag changes, and dependency incidents.
  • Key dashboards: latency, error rate, saturation, dependency health, queue depth, pool usage.
  • Correlated traces and logs for the failing path.
  • Known runbooks, rollback mechanisms, and feature flags.

Response Sequence

  1. State impact and likely severity.
  2. Stop unsafe changes and identify the fastest reversible mitigation:
    • rollback
    • disable feature
    • reduce concurrency
    • shed load
    • rate-limit callers
    • isolate or degrade a dependency
  3. Preserve high-signal evidence while the symptom still exists.
  4. Compare timeline of incident onset with recent changes.
  5. Localize the failing layer: application, database, downstream dependency, queue, infrastructure, or configuration.
  6. Propose long-term corrective actions only after the service is stable.

Advanced Incident Heuristics

  • Restarting everything can destroy the best evidence and amplify a connection storm. Use restarts deliberately, not reflexively.
  • Scaling the app tier does not help when the database or a downstream service is the bottleneck.
  • Rate-limiting or queue pausing may protect core flows better than full rollback when only one feature path is toxic.
  • A config-only incident can look like a code regression; compare effective runtime values before patching application code.
  • A healthy dependency at low volume can still fail under retry storms from your own fleet.
  • If the system uses caches, verify whether bad cache fill, stampede, or stale data amplified the incident.
  • If the incident is intermittent, preserve timing and hypothesis logs. Races and saturation patterns are easy to lose after mitigation.
  • Post-incident work must include detection and prevention, not only the code fix.

Incident Command Nuances

  • One person should own technical command during a serious incident. Parallel debugging without a decision owner often slows mitigation.
  • Communication cadence matters. Operators and stakeholders need regular updates even when the technical picture is incomplete.
  • Rollback is not always safe if data shape or side effects have already changed. Assess rollback safety before pressing the button.
  • Canary comparison, feature-flag cohort analysis, and effective-config diffing often localize incidents faster than code inspection.
  • Preserve version, commit, config, and infrastructure fingerprints in the incident notes while they are still recoverable.

Expert Heuristics

  • Choose the first mitigation that reduces blast radius and buys time, not the one that feels most technically satisfying.
  • Prefer mitigations that also test a hypothesis when that can be done safely.
  • If the incident spans several layers, identify the current bottlenecked layer first. Solving secondary symptoms wastes the window of action.
  • A good postmortem action item changes detection, defaults, rollout strategy, or operational safety nets, not just one line of code.

Output Contract

Return these sections:

  • Impact: who or what is affected and how badly.
  • Immediate mitigation: the safest reversible action to reduce pain now.
  • Evidence: the strongest signals collected so far.
  • Working hypothesis: the leading explanation plus uncertainty.
  • Next diagnostic step: the most informative next action once stable.
  • Follow-up: long-term fix, monitoring change, and postmortem actions.

Guardrails

  • Do not recommend code changes as the very first incident action when a reversible mitigation exists.
  • Do not claim root cause certainty without evidence.
  • Do not optimize for elegance over containment during an outage.
  • Do not forget operator communication and blast-radius tracking while debugging.

Quality Bar

A good run of this skill reduces user pain quickly and leaves the team with a cleaner path to root cause. A bad run jumps to speculative code fixes while the service remains unstable and evidence disappears.

Thêm skills từ kotlin

kotlin-backend-jpa-entity-mapping
kotlin
Lớp dữ liệu (data class) của Kotlin rất tự nhiên cho DTO nhưng nguy hiểm cho thực thể JPA. Hibernate dựa vào ngữ nghĩa định danh mà lớp dữ liệu phá vỡ: equals / hashCode trên tất cả các trường làm hỏng tư cách thành viên Set / Map sau khi thay đổi trạng thái, và copy() được tạo tự động tạo ra các bản sao tách rời của các thực thể được quản lý.
kotlin-tooling-agp9-migration
kotlin
Plugin Android Gradle 9.0 khiến các plugin ứng dụng và thư viện Android không tương thích với plugin Kotlin Multiplatform trong cùng một module. Kỹ năng này hướng dẫn bạn thực hiện quá trình di chuyển.
kotlin-tooling-cocoapods-spm-migration
kotlin
Di chuyển dự án KMP từ CocoaPods (kotlin("native.cocoapods")) sang Swift Package Manager (swiftPMDependencies DSL) — thay thế pod() bằng swiftPackage(),…
kotlin-tooling-immutable-collections-0-5-x-migration
kotlin
Di chuyển mã Kotlin (và Java) từ kotlinx.collections.immutable 0.3.x / 0.4.x lên phiên bản 0.5.x mới nhất. Dòng 0.5.x đổi tên mọi phương thức trả về bản sao trên…
kotlin-tooling-java-to-kotlin
kotlin
Chuyển đổi các tệp nguồn Java sang Kotlin tự nhiên bằng phương pháp chuyển đổi 4 bước có kỷ luật với 5 bất biến được kiểm tra ở mỗi bước. Hỗ trợ chuyển đổi nhận biết framework, xử lý các mục tiêu vị trí chú thích, thành ngữ thư viện và bảo toàn API.
kotlin-tooling-native-build-performance
kotlin
Chẩn đoán và khắc phục tình trạng biên dịch và liên kết Kotlin/Native chậm trong các dự án Kotlin Multiplatform nhắm mục tiêu iOS. Sử dụng khi người dùng báo cáo iOS chậm hoặc…
kotlin-spring-proxy-compatibility
kotlin
Diagnose and prevent Kotlin plus Spring proxy failures around `@Transactional`, `@Cacheable`, `@Async`, method security, retry, configuration proxies, and JPA…
ci-cd-containerization-advisor
kotlin
Thiết kế các pipeline build, image và triển khai có thể tái tạo cho ứng dụng Kotlin và Spring, bao gồm xác minh CI, container phân lớp, an toàn khi triển khai,…