> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Atatus 告警集成

> 通过 Webhook 通知渠道将 Atatus 告警事件的触发和关闭同步到 Flashduty On-call。

通过 Atatus 的 Webhook 通知渠道（Notification Channel），把告警事件（Incident）的触发和关闭同步到 Flashduty On-call。每个 Atatus 告警事件对应一条 Flashduty 告警：事件开启（`Opened`）时触发，事件关闭（`Closed`）时关闭这条告警。

<div className="hide">
  ## 在 Flashduty On-call

  ***

  您可通过以下两种方式获取集成推送地址，任选其一即可。

  ### 使用专属集成

  1. 进入 Flashduty 控制台，选择 **协作空间**，打开一个协作空间
  2. 选择 **配置** → **集成数据** → **专属集成**，点击 **新增一个集成**
  3. 选择 **Atatus**，点击 **保存**
  4. 打开生成的集成卡片，复制 **推送地址**

  ### 使用共享集成

  1. 进入 Flashduty 控制台，选择 **集成中心 → 告警事件**
  2. 选择 **Atatus**，填写集成名称
  3. 配置默认路由并选择协作空间；创建后可在 **路由** 中增加更多规则
  4. 点击 **保存**，复制生成的 **推送地址**
</div>

## 在 Atatus 中配置

***

<Steps>
  <Step title="创建 Webhook 通知渠道">
    1. 登录 Atatus，进入 **Alerting → Notification Channels**，点击 **Create new notification channel**
    2. 渠道类型选择 **Webhook**
    3. **Channel name** 可填写 `Flashduty`，将 Flashduty 集成的完整推送地址粘贴到 URL 输入框
    4. 点击 **Create channel**
    5. 可打开该渠道，点击 **Send Test Notification** 验证地址：Flashduty 返回成功，并创建一条等级为 Info 的测试告警，需要手动关闭
  </Step>

  <Step title="将渠道关联到告警策略">
    在 **Alerting → Alert Policies** 中打开告警策略，点击 **Add notification channels**，勾选刚创建的 `Flashduty` 渠道，点击 **Add Channels**。Atatus 会在该策略下的告警事件开启、关闭或被确认时向渠道发送通知。
  </Step>

  <Step title="验证生命周期">
    触发一条告警规则，确认 Flashduty 收到活动告警；待事件在 Atatus 中自动关闭（或修改规则让条件不再满足）后，确认原告警恢复。
  </Step>
</Steps>

## 推送内容

***

Atatus 以 `application/json` 格式 POST 以下字段，Flashduty 直接解析，无需配置模板：

| 字段 | 含义 | 在 Flashduty 中 |
| :- | :- | :- |
| `incident_id` | 告警事件 ID | Alert Key，标签 `incident_id` |
| `rule_name` | 告警规则名称 | 告警标题，标签 `check` |
| `status` | `Opened` 或 `Closed` | 触发或关闭 |
| `severity` | `Critical` 或 `Warning` | 告警等级 |
| `description` | 触发条件，例如 `Event Count goes below 1000 events` | 描述 |
| `alert_policy_name`、`alert_policy_id` | 告警策略 | 标签 `policy`、`policy_id` |
| `rule_id` | 规则 ID | 标签 `rule_id` |
| `product` | 产品，例如 `Logs` | 标签 `product` |
| `duration` | 事件持续时间，仅关闭通知携带 | 描述 |
| `incident_url` | Atatus 中的事件链接 | 描述 |

`target_name`、`acknowledge_url`、`account_id`、`alert_url`、`timestamp` 等其他字段不会保存。

## Alert Key

***

Flashduty 使用 `incident_id` 作为 Alert Key。同一个 Atatus 事件的开启和关闭通知携带相同的 `incident_id`，因此会落在同一条告警上。事件范围由告警策略的 **Incident preference** 决定（按策略、按规则、按规则和目标），Flashduty 与 Atatus 保持一致。

请求中缺少 `incident_id` 时，Flashduty 会返回参数错误，因为无法可靠地把关闭通知关联到原告警。

## 状态和告警等级

***

| Atatus 字段 | Flashduty 状态或等级 |
| :- | :- |
| `status` 为 `Opened`，`severity` 为 `Critical` | Critical |
| `status` 为 `Opened`，`severity` 为 `Warning` 或其他值 | Warning |
| `status` 为 `Closed` | 恢复，等级沿用通知中的 `severity` |
| `status` 为 `Acknowledged` | 不创建事件，直接返回成功 |

`status` 为空或为其他值的请求会被拒绝，避免把无法判断状态的请求写入错误的告警生命周期。

## 常见问题

***

<AccordionGroup>
  <Accordion title="在 Atatus 中确认（Acknowledge）事件会影响 Flashduty 告警吗？">
    不会。确认通知会被接收并忽略，Flashduty 告警的处理请在 Flashduty 中进行。
  </Accordion>

  <Accordion title="渠道测试成功，但真实告警没收到？">
    渠道测试只验证地址可达，并创建一条独立的 Info 测试告警。请确认告警策略已关联该渠道、规则处于启用状态，且条件持续满足了规则设定的时长。
  </Accordion>
</AccordionGroup>

## 排查问题

***

* **Atatus 推送失败**：确认 URL 是完整的推送地址，且包含 `integration_key`
* **Flashduty 返回参数错误**：确认请求中带有 `incident_id`，且 `status` 为 `Opened`、`Closed` 或 `Acknowledged`
* **告警没有恢复**：确认告警策略仍关联该渠道；关闭通知与开启通知的 `incident_id` 必须相同

Webhook 渠道设置请参阅 Atatus 官方文档 [Webhook](https://docs.atatus.com/docs/product-guide/tool-integrations/webhook.html) 和 [Alert Incidents](https://docs.atatus.com/docs/alerting/alert-incidents.html)。
