ERROR) and recovers automatically when the gate passes (OK) on the same branch. It works with SonarQube Server (Community Build, Developer, Enterprise, Data Center) and SonarQube Cloud, which send the same webhook body.
In Flashduty On-call
You can get the push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channels and open a channel
- Go to Settings → Integrations → Dedicated integrations and click Add an integration
- Select SonarQube and click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select SonarQube and enter an integration name
- Configure the default route and select a channel; you can add more rules under Routes after creation
- Click Save and copy the generated Push URL
In SonarQube
1
Create the webhook
SonarQube Server:
- Sign in as an administrator. Go to Administration → Configuration → Webhooks for a global webhook that applies to every project, or open a project’s Project Settings → Webhooks for that project only (up to 10 per project)
- Click Create and enter a name
- Paste the full Flashduty push URL into URL; it must include
integration_key - Secret is optional. When set, SonarQube adds an
X-Sonar-Webhook-HMAC-SHA256header to each request. Flashduty does not verify it; requests are authenticated by theintegration_keyin the URL
- Go to Administration → Webhooks of the organization (organization admin required)
- Click Create, enter a name, and paste the push URL into URL
2
Run an analysis and verify
- Run an analysis of the project from CI (for example
sonar-scanner). SonarQube posts the webhook when the analysis finishes - Make the quality gate fail (for example by raising a coverage threshold temporarily) and confirm an alert appears in Flashduty
- Fix it, run another analysis, and confirm the alert recovers once the gate passes
Alert Key
The Alert Key is computed from the project key (
project.key), the branch type (branch.type, such as BRANCH or PULL_REQUEST), and the branch name (branch.name). As a result:
- A failure and a later pass on the same branch of the same project share one Alert Key, so the alert recovers when the gate passes
- Different branches, pull requests, and projects never affect each other’s alerts
- Changes to the project name, quality gate name, analysis ID, or commit do not change the Alert Key
- Analyses without branch information (editions without branch analysis) are told apart by project key alone
project.key is rejected.
Status and severity
SonarQube webhooks carry no severity, and a failed quality gate is a code quality signal rather than an outage, so every alert is Warning. Adjust it with routing or alert management in Flashduty if needed.
These deliveries are ignored, and Flashduty returns success: failed or cancelled analyses (
status is FAILED or CANCELLED, no quality gate), bodies without qualityGate, and any other qualityGate.status value.
Every passing analysis sends an OK; it is used only to recover the active alert of the same project and branch.
Labels
The alert description lists each failed condition with its metric, current value, and threshold.
Troubleshooting
- Flashduty returns an invalid parameter error: check that the URL is complete and includes
integration_key - No alert arrives: confirm the analysis produced a quality gate result. On SonarQube Server, check the status code under Last delivery on the Webhooks page; SonarQube Cloud needs a paid plan
- The alert does not recover: recovery depends on the next analysis of the same project and branch. After a pull request is closed there are no further analyses, so close its alert manually
- SonarQube Server cannot reach Flashduty: the webhook is sent by the SonarQube server itself; make sure it has outbound internet access or a configured proxy