Wegweiser
All notes

A report you can hand to a client

The four PDF reports open on a cover, carry the device page's instruments, and every check on them now says its own name and what it actually looks at. In German too. Plus a settings page that tells you when an API key is about to die, instead of after.

The reports Wegweiser generates have always had the right numbers in them. They have not always looked like something you would put in front of a client without apologising first.

From today the four of them, tenant, organisation, device and QBR, open on a cover and carry the same instrument language as the device page: the gauge with its 270 degrees of ticks, the segmented meters, the rulers. The structure runs to the paper edge rather than stopping at a print margin, the closing strip is the bottom of the page rather than a line dangling under it, and each level of the hierarchy gets its own crop of the cover photograph. Stand further down and the stone is closer.

That is the part you notice across the room. The part that matters when somebody actually reads it is smaller.

Every check says what it looks at

A device report used to print binary-inventory as a heading, with msinfo-SystemHardwareConfig underneath it, in a document that goes to a paying client. The readable names did exist, in a lookup that exactly one page in the whole app could reach. Everything else fell back to title-casing the internal slug, so the reports shipped machine names to customers.

The names now live next to the analyzers themselves, so there is one source and the device page reads it too. They cannot drift apart again.

Underneath each heading there is now a line or two of smallprint saying what the check actually looks at. Thirty-five of them, written for somebody who does not work in IT. A client reading "Patch Compliance 65" has no way to know whether that covers third-party software or only Windows updates, and the number means nothing until they do. Now it says.

The same thirty-five, in German

The German edition has had the interface for a fortnight. It did not have the checks. A German-speaking technician got a page of German chrome wrapped around thirty-five English check names and thirty-five English descriptions, which is the sort of half-translation that reads worse than none at all.

Both are translated now, names and summaries, so a report going to a German client is a German document rather than a German cover on an English one.

A key that expires at lunchtime now says so

If you run Wegweiser on your own AI provider key, this is the change worth knowing about.

Some credentials carry an expiry inside them. IONOS tokens do, and the token generator offers a lifetime anywhere from one hour to a year, with the short one first. Pick the short one and the settings page used to accept it, store it correctly, report success, and say nothing at all. An hour later every analysis, every chat and every overnight roll-up fails against a key the page still describes as stored. It was stored. That was never the question.

Four things changed:

  • A credential that has already expired is refused at save, and the page names the moment it died rather than storing a corpse and reporting ok.
  • A credential with less than a day left saves, but says so, and the message stays on the page instead of being reloaded away. An hour from now is somebody's outage.
  • The connection test short-circuits on an expired key without spending a round trip, and says it is stored correctly and simply no longer valid, which is a different sentence from "wrong or no api key".
  • The settings page carries a chip showing how much life the stored credential has left, and raises a banner when that is expired or short.

There was a second half to this, and it was the more confusing one. Wegweiser runs fifteen processes, and each one kept its own copy of the secrets it had read. Saving a key told whichever process happened to serve that request. The other fourteen carried on with the old value for up to five minutes. So saving a key and immediately trying it in chat was roughly a one in four chance of using the key you just typed, and an analysis worker would not see it at all until its own cache lapsed. Every save now rings a bell the other processes can hear, and a new key is live everywhere within seconds.

When something fails, the page says which thing failed

Three smaller changes with one idea behind them.

A model provider that refuses your API key used to put its own raw error envelope on the finding card, paas-auth-1 and all. It now says the provider rejected the key, points at the settings page, and says plainly that re-running will not help until it is fixed, because it will not.

An investigation that gathered evidence and then could not write up its conclusion used to report that it "ran out of time", whatever had actually stopped it. Sometimes that was true. Sometimes the provider had refused the final call and no clock was involved anywhere, and the advice that follows from the wrong diagnosis sends you to re-run something that will fail the same way. It now says which of the two happened, and the evidence it did gather stays the headline either way.

And the agent rollout breaker has stopped crying wolf. It halts an update when too many devices go quiet after installing it, which is the right instinct and the wrong question: it was asking whether a device is powered on right now, not whether it has reported since the installer ran. A ring of office workstations updated in the morning would halt its own rollout at six in the evening, when everybody went home, and leave a breaker for somebody to clear in the morning that nothing had actually tripped. It now asks whether the machine has been heard from since its own install, which is the fact that tells a bricked agent from a switched-off desk.

More notes

  1. Nobody's website gets scanned by accident

  2. Twenty-six alerts, one locked door

  3. Tell it what the machine is