In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select GitGuardian, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select GitGuardian and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure GitGuardian
You need permission to manage integrations in the GitGuardian workspace.
1
Create a Custom webhook
- In the GitGuardian dashboard, go to Settings → Integrations → Destinations → Custom webhook
- A webhook belongs to a team. To receive every incident in the workspace, click Add integration on the All-incidents team row; to receive only one team’s incidents, use that team’s row
- On the Configuration tab, paste the complete Flashduty integration Push URL into Webhook URL (it must include
integration_key) and click Next
integration_key in the Push URL and does not verify the signature, so you do not need to enter the token in Flashduty.2
Select events
On the Events tab, enter an Events name, turn on Internal monitoring, and under Notify when select these events (or click Select all):
Assignment, comment, feedback, access, public sharing, and Honeytoken events do not change alert state. Flashduty returns success for them and creates no alert, so you do not need to select them.To page only for high-risk leaks, add filtering rules to the webhook by severity, validity, secret type, or tag. Without rules, every incident is sent.
3
Verify the lifecycle
Trigger a new incident in the workspace and confirm that Flashduty receives an active alert. Then mark the incident Resolved in GitGuardian and confirm that the alert recovers.Send test message in the webhook’s menu (the three dots on its row) only verifies that the URL is reachable: Flashduty returns success but creates no alert.
Alert Key
Flashduty uses the incident
id (incident.id in the webhook) as the Alert Key. In GitGuardian’s published webhook examples, the New incident, New occurrence, Resolved, Ignored, and Reopened events of the same incident carry the same incident.id.
Changes to severity, validity, occurrence count, or detector name do not change the Alert Key. Incident events without incident.id are rejected.
Status and severity
The alert status follows
action: incident_resolved and incident_ignored recover the alert, and every other event in the table above triggers it. A validity, severity, or risk score change on an incident that is already resolved or ignored is ignored and does not re-open the alert. A reopened incident triggers a new alert with the same Alert Key.
The severity follows incident.severity:
unknown means GitGuardian has not rated the incident yet, so Flashduty treats it as Warning.
Labels
Troubleshooting
- No alert was created: confirm the matching event is selected and that the webhook’s filtering rules do not exclude the incident. GitGuardian states that webhook delivery is best effort and not guaranteed
- The alert did not recover: confirm Resolved and Ignored are selected under Incident status change
- Flashduty returns an invalid-parameter error: confirm the target URL is complete and includes
integration_key - An ignored incident is reopened: a new alert is created with the same Alert Key