# sample-incident-redacted.log — the evidence bundle from sample-incident-raw.log
# after review, ready to share with an AI assistant. Compare the two side by side.
#
# What changed, and why:
#  - The entire env dump was REMOVED, not masked. Secrets don't belong in an
#    evidence bundle at all; minimizing beats masking.
#  - Credentials were removed by dropping their structure (no `user:pass@`, no
#    `KEY=value`), because a masked-in-place secret line still *looks* like a
#    secret and still leaks which credentials exist and where.
#  - Identifiers were PSEUDONYMIZED with consistent placeholders (IP_1 is always
#    the same host) so the diagnostic relationships survive, without exposing real
#    hosts, subnets, customers, or people.
#  - Timestamps, request ids, status codes, and error text were KEPT — they are
#    the actual evidence.

===== haproxy.log (edge) =====
2026-09-16T14:02:11Z haproxy: CLIENT_1 [16/Sep/2026:14:02:11.004] fe_https be_api/API_HOST_1 0/0/1/-1/30001 503 212 sQ-- "GET /api/v1/checkout HTTP/1.1"
2026-09-16T14:02:12Z haproxy: CLIENT_1 [16/Sep/2026:14:02:12.101] fe_https be_api/API_HOST_2 0/0/0/-1/30001 503 212 sQ-- "POST /api/v1/orders HTTP/1.1"

===== nginx access (API_HOST_1) =====
IP_1 - - [16/Sep/2026:14:02:11 +0000] "GET /api/v1/checkout HTTP/1.1" 500 73 upstream_response_time=30.001 request_id=req_7c1f9a
IP_1 - - [16/Sep/2026:14:02:12 +0000] "POST /api/v1/orders HTTP/1.1" 500 73 upstream_response_time=30.001 request_id=req_7c1fa0

===== docker logs shopdemo-api (API_HOST_1) =====
2026-09-16T14:02:10Z api ERROR db: connection failed: could not connect to server: Connection timed out
2026-09-16T14:02:10Z api DEBUG db: dsn=postgres://DB_HOST_1:5432/shop?sslmode=require  (user + password removed)
2026-09-16T14:02:10Z api ERROR order failed for customer CUST_1 (CUST_1_EMAIL): upstream db timeout
2026-09-16T14:02:10Z api INFO  retrying with pool=primary host=DB_HOST_1

===== env dump =====
[env dump withheld: 6 secret variables (cloud keys, DB URL, service token, model API key) were removed and never sent]

===== journalctl -u nova-compute (openstack controller) =====
2026-09-16T14:01:58Z CTRL_1 nova-compute: WARNING nova.virt.libvirt.driver messaging timed out waiting for reply to db-sync on rabbit@MQ_1
2026-09-16T14:02:05Z CTRL_1 nova-compute: ERROR oslo.messaging MessagingTimeout: Timed out waiting for a reply to message ID 4b1c

===== on-call note =====
Paged the on-call alias at 14:03. DB host DB_HOST_1 not responding on 5432; suspect network partition between the api subnet (SUBNET_1) and the db host.
