recovery.resource_failed_over
Automatic failover swapped a banned channel or group for its standby without the creator: the failover you sleep through.
When this fires
A probe finds a channel gone or the bot removed from it, the project has Automatic Failover switched on, a healthy standby is linked, and the allowance permits: the platform points the resource at its standby, revokes the old links and queues every active member's re-admission, all without the creator. This event fires the moment the resource points at the standby; it sits under a recovery whose recovery.operation_started carries automatic: true.
Members the bot cannot reach. A failover emails the members the bot can no longer message, at a per-email fee the creator accepted when switching failover on. The roll call's
emailedcounter says how many.
Caveats
- The standby that was consumed fires
recovery.standby_removedwithreason: usedbeside this event. project.resource.updatedalso fires for the same resource withchanges.space_id, as it does for any swap.
Related events
recovery.resource_replaced: the same swap made by the creator.recovery.operation_reverted: the creator put the old chat back.
Ability to subscribe
A token needs this to subscribe an endpoint to the event.
Header Parameters
t=<unix seconds>,v1=<hex>: the HMAC-SHA256 of "<t>.<raw body>" under the endpoint's secret. Verify it before acting, and refuse a t more than 300 seconds from now. During a secret rotation a v0= signature under the previous secret may precede v1=.
The event's ULID, bare. The envelope's id is the same ULID prefixed evt_, so strip the prefix before comparing. Deduplicate on it: a retry carries the same id.
The event name, the same as the envelope's type.
Always application/json.
Always Subscriby-Webhooks/1.0.
Payload
JSONWhat Subscriby posts to your endpointapplication/json
The signed JSON envelope posted to your endpoint.
The envelope every event is delivered in.
Responses
2XXAny success status
Your endpoint acknowledged the delivery. Any 2xx status within 30 seconds marks it delivered; the response body is ignored.
defaultAny other status
Any other status, a connection failure, or no answer within 30 seconds counts as a failed attempt. The delivery is retried 8 times, after 10 seconds, 30 seconds, 2 minutes, 10 minutes, 1 hour, 6 hours, 1 day, 3 days; the last failure dead-letters it, and it can be retried from the dashboard or POST /v1/webhook-deliveries/{delivery}/retry. After 20 consecutive failures the endpoint is paused until it is resumed.
How is this guide?
Last updated on
recovery.installation_failed_over
Automatic failover switched a project onto its standby bot without the creator, because the platform refused the live one: the bot-side twin of recovery.resource_failed_over.
recovery.resource_replaced
The creator pointed a resource at a replacement channel or group: in a recovery after a ban, or on demand for a healthy resource.