Skip to content

feat: show quota denials in the activity feed - #523

Open
kevwilliams wants to merge 1 commit into
fix/activity-policy-outcome-guardsfrom
feat/activity-quota-denied
Open

kevwilliams wants to merge 1 commit into
fix/activity-policy-outcome-guardsfrom
feat/activity-quota-denied

Conversation

@kevwilliams

Copy link
Copy Markdown
Contributor

When a customer tries to create a load balancer, connector, gateway or connector advertisement and has reached their quota, the request is refused and nothing shows in their activity feed. In the last 30 days that happened about 115 times across 6 projects.

This adds a feed entry for those refusals, such as "Alice couldn't create load balancer web-1: quota reached".

It matches only requests that hit a quota limit. Permission errors, quota check timeouts and our own controllers are left out.

Depends on:

  1. fix: skip rejected and dry-run requests in activity policies #522, which this branch builds on. The base moves to main when it merges.
  2. feat: record quota admission outcome as an audit annotation milo-os/milo#821, which marks quota refusals in the audit log. Until a Milo release with it is deployed, these rules match nothing.

@kevwilliams
kevwilliams requested a review from a team as a code owner October 1, 2026 02:54
Adds a create-quota-denied rule to the HTTPProxy, Connector, Gateway and ConnectorAdvertisement policies. It matches creates that Milo's quota admission rejected, using the quota.miloapis.com/outcome audit annotation (milo-os/milo#821), and skips system users, other 403s and quota timeouts.
@kevwilliams
kevwilliams force-pushed the feat/activity-quota-denied branch from 415dc90 to 6f7c7c0 Compare October 1, 2026 02:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants