Postmortem: ()
Blameless: describe what the system and the process allowed, not who erred.
Summary
Section titled “Summary”<Two or three sentences: what failed, for how long, how it was fixed.>
Impact
Section titled “Impact”- <Who was affected and how: failed requests (count and ratio), latency, error-budget minutes burned, data lost or delayed (none is an answer).>
Timeline
Section titled “Timeline”All times UTC.
| Time | Event |
|---|---|
| HH:MM:SS | |
| HH:MM:SS | <first signal: alert, page, user report> |
| HH:MM:SS | |
| HH:MM:SS | |
| HH:MM:SS | <recovery confirmed, and how> |
Root cause
Section titled “Root cause”<The chain of causes, down to the one that, once removed, prevents this class of failure. Name the component, the file, and the condition.>
Detection
Section titled “Detection”<How it was detected and how long that took. Would an alert have caught it sooner? Which one, with what threshold?>
Resolution
Section titled “Resolution”<What restored service, and what fixed the cause (they may differ).>
Action items
Section titled “Action items”| Action | Kind (prevent, detect, mitigate) | Owner | Done |
|---|---|---|---|
| <link or “open”> |