The service board is the union, and aliases decide coverage only
Decided
serviceBoardRows() renders every check the monitor reports *plus* every declared component no check appears to cover — not one or the other.
Affects: lib/support-center.ts, app/support/page.tsx, app/security/page.tsx Amends D-013.
D-013 established the rule that made the status board honest: what is watched is what is shown. Under it, connecting a monitor replaced the authored component catalogue with the monitor's own checks, so that no translation layer could ever display a vendor's check under one of our names and get the mapping wrong. That reasoning was correct about the danger and wrong about the remedy.
The live audit supplied the shape that makes it bite. The Better Stack account carries four monitors; the catalogue declares six components. Under the original rule, the moment a token reached the deployment, "Webhook delivery" and "Field device sync" would have vanished from /support entirely and the headline would have read "4 of 4 components nominal" — a sentence that sounds like complete coverage and describes partial coverage. A reader could not have distinguished a retired subsystem from an unwatched one. The rule against showing the wrong thing as green had quietly become a rule for showing an incomplete thing as complete.
The join is deliberately weak, and that is the whole safety argument. Aliases answer exactly one question — does some check appear to watch this, or do we still owe the reader a "nobody is watching this" row? They never supply a display name, a state, or an availability figure; those always come from the monitor. So a wrong alias fails by listing a component once instead of twice, or twice instead of once. Both are visible on the page, and neither is a false green. D-013's actual concern is untouched.
Consequences accepted:
- Row counts are no longer check counts, so
/supportand/securitycompute three numbers where they computed one: checks reported, checks passing, and components with no check. "N of M checks passing" stays a sentence about checks. /supportgains a third headline, "All monitored systems operational", for the case that is now the common one. "All systems operational" is a claim about subsystems nobody is watching; "some systems are degraded" is wrong in the other direction, because an unwatched component is not a broken one.- Status icons follow
anyTrouble, notallOperational, so a coverage gap and an outage never share a glyph.
A side effect worth having: the four-monitors-against-six-components mismatch recorded as finding L15 now appears on our own page, naming the three checks that do not exist — dispatch, the public API, and webhook delivery — rather than being visible only to someone diffing two hosts.
This would be wrong if aliases ever grew into a mapping table that supplied names or states. The moment an alias can rename a check, D-013's original objection returns in full and this decision should be reverted rather than patched.