We're having issues with Ory Network.
# ory-network
a
We're having issues with Ory Network.
came back again almost immediately though....
but console wasn't loading and our app was getting CORS errors from whoami.
h
We’re looking into it
1
We received a few alerts, looks like some pods restarted. Everything is continuing to run though
a
okay.
thanks!
f
I'm getting
security_csrf_violation
whenever I try to create a browser flow
Could this be related?
h
No
@acoustic-airline-26089 sorry for not following up yesterday. It looks like several Kubernetes VMs restarted due to an GKE upgrade and that caused a short increase in errors where network requests failed with EOF. The system recovered quickly and we could not see any other issues. We’ll still investigate what we can do to prevent these network errors.
a
@high-optician-2097 - thanks for the update, sure, please keep us updated. Seems like lots of upgrades happening so trying to be patient and understanding 🙂
h
Agree @acoustic-airline-26089 - this particular issue was a really short (less than a 10 or 15 seconds) elevation of error rates in one region of our system. We’ll be looking into what happened and what we can do to get this sorted out as well. Having said that, the system is now fully multi-region and for example other regions continued to operate - we also don’t have plans for major infrastructure changes such as the ones we performed recently in the near future 🙂
a
did this just happen again?
h
I’m checking with SRE. What did you experience?
a
Copy code
Access to XMLHttpRequest at '<https://auth.noah.com/self-service/login/browser>' from origin '<https://app.noah.com>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
loggerBase.ts:109 ERROR: Error: Network Error
    at createError.js:16:15
    at XMLHttpRequest.<anonymous> (xhr.js:91:14)
instrumentMethod.js:37     GET <https://auth.noah.com/self-service/login/browser> net::ERR_FAILED 403
still happening apparently.
for 'some' users.
h
do you know the IPs of these users?
because we see that some IPs have been blocked due to suspicious bot activity
its actually only one ip in the last 30 minutes: 173.53.59.146
a
yeah, that's the one: 173.53.59.146
h
ok, is that a legitimate user?
a
yes, our CSM.
h
ok, let me check with SRE how to allow list this IP
we explicitly allowed this IP now - but will keep the heightened bot detection online
1