Notes on API and vendor monitoring
Uptime checks, incident response, SLA tracking, and the parts of vendor monitoring that actually matter when something breaks.
91 articles · page 1 of 10
DORA and NIS2: What They Require for Third-Party ICT Monitoring
What DORA and NIS2 actually say about monitoring third-party ICT providers, which articles apply, and where availability data counts as evidence.
Your Uptime Is Not Your Uptime: Availability Across a Dependency Chain
Serial dependencies multiply. Ten vendors at 99.9% each give you 99.0%, or 87 hours a year. How to compute your real ceiling and what redundancy buys.
Reading Vendor Status Feeds Programmatically: Formats, Endpoints and Traps
The formats vendors publish status in, the endpoints worth calling, and the failure modes that make naive parsing quietly and confidently wrong.
Cloud Concentration Risk: When Everybody Fails at the Same Time
Your vendors look independent on paper and share infrastructure underneath. How correlated failure happens, and why multi-cloud fixes less than you think.
Severity Levels for Third-Party Outages: A Scale That Holds Up
Standard SEV scales assume you can fix the thing that broke. When the broken thing is a vendor you cannot fix, severity has to key on user impact instead.
Scheduled Maintenance and the SLA Math Nobody Checks
Almost every SLA excludes planned maintenance. A 99.9% deal with a four-hour monthly window really means 99.34%, or 4.7 hours down instead of 43 minutes.
Fail Over or Wait It Out: Deciding During a Vendor Outage
Failover has its own failure rate and its own recovery cost. The four inputs that decide it, and how to pre-commit the call before you are under pressure.
The PulsAPI MCP Server: Live Vendor Status Inside Your AI Agent
PulsAPI now ships a remote MCP server. Five tools, one URL, an OAuth sign-in instead of a pasted key, and no config file to keep a secret out of.
MCP Servers for DevOps: Giving AI Agents Live Infrastructure Context
What the Model Context Protocol is, which operations workflows it genuinely improves, how remote servers authenticate, and how to vet one before connecting it.
Shipping a Remote MCP Server: What OAuth 2.1 Actually Requires
PKCE, dynamic client registration, resource indicators, and a discovery chain that starts at a 401. The specs a remote MCP server must satisfy, and why each exists.