webhook_sink) to send Robusta findings to Flashduty On-call. A Prometheus alert that Robusta forwards creates a Flashduty alert when it fires and recovers automatically when Alertmanager sends the resolution. Problems that Robusta detects itself (such as CrashLoopBackoff, OOMKilled, or image pull failures) are notified once and do not recover automatically.
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Robusta and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Robusta and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure Robusta
1
Add a webhook sink
In the Helm values file you installed Robusta with (usually
generated_values.yaml), add a webhook_sink to sinksConfig:url: the full Flashduty push URL (starting withhttps://and includingintegration_key)format: must bejson. The defaulttextsends plain text, which Flashduty cannot parse and rejects with a parameter error- Do not turn on
slack_webhook. With it, Robusta sends a Slack-formatted body withoutfingerprint, and Flashduty rejects it - Keep
size_limitat its default of4096. Over the limit, Robusta drops the trailing fields;enrichmentsgoes first, and Flashduty does not read it
2
Upgrade Robusta
clusterName is written to the alert as the cluster label and is part of the Alert Key. If several clusters push to the same integration, give each cluster a different clusterName.3
Turn on auto-close after timeout
Problems that Robusta detects itself (
source is KUBERNETES_API_SERVER and similar) send no resolution, so these alerts stay open. In the channel that receives this integration, turn on auto-close after timeout and set it to how quickly your team handles problems, for example 4 hours.Alert Key
Flashduty computes the Alert Key from
cluster_name and fingerprint.
- Prometheus alerts:
fingerprintis the fingerprint Alertmanager computes for the alert. It stays the same from firing to resolution, so the firing, escalation, and resolution notifications land on the same Flashduty alert - Problems Robusta detects itself:
fingerprintis computed from the resource kind, name, namespace, node, and problem type, so the same kind of problem recurring on the same pod merges into one alert
fingerprint, because later notifications could not be matched to it.
Status and severity
Flashduty marks the alert as recovered when the request has a non-empty
ends_at or the title starts with [RESOLVED] . Robusta sends such notifications only for Prometheus alerts that Alertmanager has resolved, so make sure the Robusta receiver in Alertmanager has send_resolved: true (the Prometheus bundled with Robusta has it on by default).
When Robusta forwards a Prometheus alert, it converts the alert’s
severity label: critical, high, medium, and error become HIGH; warning and low become LOW; info and any other value become INFO; debug becomes DEBUG. A resolution keeps the last severity.
Alert content
- Title:
title, with the[RESOLVED]prefix removed from resolutions - Description:
description, the links inlinks(such as the Prometheus graph), and the resolution timeends_at - Labels:
cluster,fingerprint,aggregation_key(alert name or problem type),finding_source(such asPROMETHEUSorKUBERNETES_API_SERVER),finding_type,severity(the original Robusta severity),resource(kind/namespace/name),kind,namespace,node,container,source(alwaysrobusta), plus the resource labels and Prometheus alert labels fromsubject.labels(such asalertnameandpod)
Troubleshooting
- Flashduty returns request body is not Robusta JSON: the
webhook_sinkdoes not setformat: json - Flashduty returns fingerprint is required: make sure
slack_webhookis off andsize_limitis not set too small - A Prometheus alert does not recover: make sure the Robusta receiver in Alertmanager has
send_resolvedon and the alert has resolved in Alertmanager - CrashLoopBackoff and similar alerts do not recover: Robusta notifies these problems once; use auto-close after timeout or close them manually
- Send only some alerts: use the sink
scopeto filter by namespace, alert name, and so on
kubectl run crashy --image=busybox --restart=Always -- sh -c 'exit 1'), then delete the pod and close the alert manually.
For field details, see Robusta webhook sink.