Skip to content

Verifying

Run these in order; each one gates the next.

bao kv get seaweedfs/observability/loki
kubectl -n observability get externalsecret

Then that data actually lands in SeaweedFS, which is the part worth proving — the buckets start empty at cutover, so anything missing here is the first sign the endpoint or the minted credentials are wrong:

aws --endpoint-url http://10.82.50.100:8333 s3 ls s3://loki
aws --endpoint-url http://10.82.50.100:8333 s3 ls s3://mimir/blocks/

Then tenancy, where the negative results are the interesting ones:

curl -s "http://loki.observability.svc:3100/loki/api/v1/labels"
curl -s -H 'X-Scope-OrgID: CBC' "http://loki.observability.svc:3100/loki/api/v1/labels"
curl -s -H 'X-Scope-OrgID: ABC-CRM' "http://loki.observability.svc:3100/loki/api/v1/labels"

The first must be refused for want of a tenant, the second must return labels, and the third must be empty — never CBC's.

Finally through Grafana: log in with GEWISWG, land in the CBC org as Editor, and confirm the federated datasources return logs and up{}. An account holding only GRAFANA-ABC_CRM-RO must land in exactly one org, see only that namespace, and have no route to the rest.