Investigate · root cause

risk lowno prod write

Registry service image pulls intermittently reset — draft RCA

Incident inc-4795 · owner Priya Raman · Atlas Public Sector. Each verified class includes attached logs, probe output, and artefact links.

Organisation · client scope

Tenant / org
Atlas Public Sector
tn-atlas · eu-west-2 · UK
Client / customer
National Registry Services
cu-registry · staging · gold
Back to workspaceEvidence

Confidence

82%

live

Risk

low

posture

Prod write

none

required

Evidence

2

classes

Rejected

1

hypotheses

Focus

off

⌘\

Analysis package

Verification agent confidence, supporting evidence with attached logs/output, and rejected hypotheses.

Read-only Agent OS
  • No shell execution
  • No cluster-admin
  • No secret reads
  • No database writes
  • No firewall changes
  • No autonomous remediation

Root cause

Verification agent confidence score

82%

TLS resets against the external registry mirror in staging.

Supporting evidence

2 verified classes · expand for logs & output

  • host mirror-stg-01.atlas.govip 10.20.8.40captured Jul 31, 2026, 11:02:00 AM

    Check · incident workspace · resource identity + timeline

      Logs · attached excerpt

      [2026-07-31T11:02:00Z] investigate: open inc-4795
      [2026-07-31T11:02:00Z] scope: tenant=tn-atlas customer=cu-registry env=staging
      [2026-07-31T11:02:00Z] resource: host=mirror-stg-01.atlas.gov ip=10.20.8.40 cluster=atlas-stg-k8s

      Output · verified details

      {
        "incidentId": "inc-4795",
        "application": "registry-mirror",
        "hostname": "mirror-stg-01.atlas.gov",
        "ipAddress": "10.20.8.40",
        "cluster": "atlas-stg-k8s",
        "status": "closed",
        "severity": "P3"
      }
    • host mirror-stg-01.atlas.govip 10.20.8.40captured Jul 31, 2026, 11:02:00 AM

      Check · agent passport · audit trail

        Logs · attached excerpt

        [2026-07-31T11:02:00Z] agent=ag-linux-02 mode=read-only
        [2026-07-31T11:02:00Z] productionWriteRequired=false

        Output · verified details

        { "assignedAgent": "ag-linux-02", "autonomy": "read-only", "write": false }

      Rejected hypotheses

      1 ruled out · with counter-evidence

      Recommendation

      Requires human execution — the Agent OS never remediates

      Confirm remediation with registry owner; no console-side write.