15 KiB
15 KiB
Doctor Runtime Check Index
Scope
- Runtime catalog source:
GET /api/v1/doctor/checkson 2026-03-31. - Docker compose baseline source: run
dr_20260331_195122_99ff09captured from the locally running default stack. - Canonical remediation content lives in
docs/doctor/articles/**; this index maps the live runtime catalog to those articles.
Runtime Summary
| Plugin | Checks |
|---|---|
stellaops.doctor.attestation |
3 |
stellaops.doctor.binaryanalysis |
6 |
stellaops.doctor.compliance |
7 |
stellaops.doctor.core |
9 |
stellaops.doctor.database |
8 |
stellaops.doctor.docker |
5 |
stellaops.doctor.environment |
6 |
stellaops.doctor.integration |
16 |
stellaops.doctor.observability |
6 |
stellaops.doctor.release |
6 |
stellaops.doctor.scanner |
7 |
stellaops.doctor.security |
11 |
stellaops.doctor.servicegraph |
6 |
stellaops.doctor.verification |
5 |
Baseline Legend
pass: expected healthy result in the captured compose baseline.info: informational only; not a release blocker in the captured baseline.warn: action needed or recommended; not a hard failure in the captured baseline.fail: baseline failure observed in the captured runtime.skip: not applicable in the captured runtime context.
stellaops.doctor.attestation
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.attestation.clock.skew |
warn |
warn |
article |
check.attestation.cosign.keymaterial |
fail |
skip |
article |
check.attestation.rekor.connectivity |
fail |
skip |
article |
stellaops.doctor.binaryanalysis
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.binaryanalysis.buildinfo.cache |
warn |
warn |
article |
check.binaryanalysis.corpus.kpi.baseline |
warn |
warn |
article |
check.binaryanalysis.corpus.mirror.freshness |
warn |
warn |
article |
check.binaryanalysis.ddeb.enabled |
warn |
warn |
article |
check.binaryanalysis.debuginfod.available |
warn |
info |
article |
check.binaryanalysis.symbol.recovery.fallback |
warn |
info |
article |
stellaops.doctor.compliance
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.compliance.attestation-signing |
fail |
skip |
article |
check.compliance.audit-readiness |
warn |
skip |
article |
check.compliance.evidence-integrity |
fail |
skip |
article |
check.compliance.evidence-rate |
fail |
skip |
article |
check.compliance.export-readiness |
warn |
skip |
article |
check.compliance.framework |
warn |
skip |
article |
check.compliance.provenance-completeness |
fail |
skip |
article |
stellaops.doctor.core
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.core.auth.config |
warn |
skip |
article |
check.core.config.loaded |
fail |
pass |
article |
check.core.config.required |
fail |
fail |
article |
check.core.crypto.available |
fail |
pass |
article |
check.core.env.diskspace |
fail |
pass |
article |
check.core.env.memory |
warn |
pass |
article |
check.core.env.variables |
warn |
warn |
article |
check.core.services.dependencies |
fail |
pass |
article |
check.core.services.health |
fail |
skip |
article |
stellaops.doctor.database
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.db.connection |
fail |
skip |
article |
check.db.latency |
fail |
skip |
article |
check.db.migrations.failed |
fail |
skip |
article |
check.db.migrations.pending |
warn |
skip |
article |
check.db.permissions |
fail |
skip |
article |
check.db.pool.health |
fail |
skip |
article |
check.db.pool.size |
warn |
skip |
article |
check.db.schema.version |
fail |
skip |
article |
stellaops.doctor.docker
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.docker.apiversion |
warn |
skip |
article |
check.docker.daemon |
fail |
fail |
article |
check.docker.network |
warn |
skip |
article |
check.docker.socket |
fail |
fail |
article |
check.docker.storage |
warn |
skip |
article |
stellaops.doctor.environment
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.environment.capacity |
warn |
skip |
article |
check.environment.connectivity |
warn |
skip |
article |
check.environment.deployments |
warn |
skip |
article |
check.environment.drift |
warn |
skip |
article |
check.environment.network.policy |
warn |
skip |
article |
check.environment.secrets |
warn |
skip |
article |
stellaops.doctor.integration
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.integration.ci.system |
warn |
skip |
article |
check.integration.git |
warn |
skip |
article |
check.integration.ldap |
warn |
skip |
article |
check.integration.oci.capabilities |
info |
skip |
article |
check.integration.oci.credentials |
fail |
skip |
article |
check.integration.oci.pull |
fail |
skip |
article |
check.integration.oci.push |
fail |
skip |
article |
check.integration.oci.referrers |
warn |
skip |
article |
check.integration.oci.registry |
warn |
skip |
article |
check.integration.oidc |
warn |
skip |
article |
check.integration.s3.storage |
warn |
skip |
article |
check.integration.secrets.manager |
fail |
skip |
article |
check.integration.slack |
info |
skip |
article |
check.integration.smtp |
warn |
skip |
article |
check.integration.teams |
info |
skip |
article |
check.integration.webhooks |
warn |
skip |
article |
stellaops.doctor.observability
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.observability.alerting |
info |
info |
article |
check.observability.healthchecks |
warn |
pass |
article |
check.observability.logging |
warn |
warn |
article |
check.observability.metrics |
warn |
info |
article |
check.observability.otel |
warn |
info |
article |
check.observability.tracing |
warn |
pass |
article |
stellaops.doctor.release
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.release.active |
warn |
skip |
article |
check.release.configuration |
warn |
skip |
article |
check.release.environment.readiness |
warn |
skip |
article |
check.release.promotion.gates |
warn |
skip |
article |
check.release.rollback.readiness |
warn |
skip |
article |
check.release.schedule |
info |
skip |
article |
stellaops.doctor.scanner
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.scanner.queue |
warn |
skip |
article |
check.scanner.reachability |
warn |
skip |
article |
check.scanner.resources |
warn |
skip |
article |
check.scanner.sbom |
warn |
skip |
article |
check.scanner.slice.cache |
warn |
skip |
article |
check.scanner.vuln |
warn |
skip |
article |
check.scanner.witness.graph |
warn |
skip |
article |
stellaops.doctor.security
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.security.apikey |
warn |
skip |
article |
check.security.audit.logging |
warn |
warn |
article |
check.security.cors |
warn |
warn |
article |
check.security.encryption |
warn |
skip |
article |
check.security.evidence.integrity |
fail |
skip |
article |
check.security.headers |
warn |
warn |
article |
check.security.jwt.config |
fail |
skip |
article |
check.security.password.policy |
warn |
skip |
article |
check.security.ratelimit |
warn |
info |
article |
check.security.secrets |
fail |
fail |
article |
check.security.tls.certificate |
fail |
pass |
article |
stellaops.doctor.servicegraph
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.servicegraph.backend |
fail |
skip |
article |
check.servicegraph.circuitbreaker |
warn |
info |
article |
check.servicegraph.endpoints |
fail |
skip |
article |
check.servicegraph.mq |
warn |
skip |
article |
check.servicegraph.timeouts |
warn |
pass |
article |
check.servicegraph.valkey |
warn |
pass |
article |
stellaops.doctor.verification
| Check ID | Severity | Baseline | Article |
|---|---|---|---|
check.verification.artifact.pull |
fail |
skip |
article |
check.verification.policy.engine |
fail |
skip |
article |
check.verification.sbom.validation |
fail |
skip |
article |
check.verification.signature |
fail |
skip |
article |
check.verification.vex.validation |
fail |
skip |
article |