Troubleshooting
Each entry below quotes a message exactly as the console returns it (from internal/console/atlas_*.go, ask*.go, datalineageingest.go and rulesrecon*.go), then gives the cause and the fix. The pages draw these messages verbatim, so what you see on screen is the text you can search for here. … marks a value filled in at runtime.
Every write is refused
this console has no sign-in configured, so an Atlas CapEx change would be unattributable — set GOOGLE_CLIENT_ID or CONSOLE_ADMIN_PASSWORD before uploading, committing or clearing capital feeds
Cause: the console has no sign-in, so nobody can be attributed. The governance, playbook, workspace, Resolve and Ask refusals have the same shape, each naming its own subject.
Fix: configure sign-in (GOOGLE_CLIENT_ID or CONSOLE_ADMIN_PASSWORD). Reads keep working in the meantime.
PERMISSION_DENIED on a write
Cause: your identity is not in CORE_ATLAS_ADMINS. That variable is optional. Unset means every identity the console admits; set, it narrows the admins to the list. On the page, the first PermissionDenied disables every write and shows the reason.
Fix: ask an admin to add your email, or have a listed admin perform the action.
UNAUTHENTICATED
unauthorized — the console session is not valid; sign in again
Cause: the session cookie expired or was revoked. Fix: sign in again.
HTTP 403 “cross-origin gRPC-web is not served by the console”
Cause: the request’s Origin names another site. gRPC-web is served same-origin only, with no CORS.
Fix: call the console from its own origin.
CapEx uploads
| Message | Cause | Fix |
|---|---|---|
File is … ; the upload cap is … per feed. Nothing was staged — split or trim the file (it is never truncated). (code too_large) | The CSV is over 8 MiB | Split the file |
File has … data rows; the cap is 50000 rows per feed. … (code too_large) | More than 50,000 rows | Split the feed |
File is not UTF-8 (first invalid byte on line …). Save it as "CSV UTF-8" and upload again — nothing was staged. (code not_utf8) | For example, an Excel Windows-1252 export | Re-save as CSV UTF-8 |
… uploads are already staged (the cap is 12); commit them or wait for the oldest to expire at … (RESOURCE_EXHAUSTED) | 12 stages are pending | Commit, or wait out the 30-minute expiry |
stage "…" is unknown or has expired (stages are kept 30m0s) — stage the file again | The stage is more than 30 minutes old | Stage the file again |
stages "…" and "…" are both for …; an ingest takes at most one upload per feed | Two stages for the same feed | Commit one per feed |
no stage_ids given — stage at least one feed first | An empty commit | Stage first |
other writers kept changing the Atlas CapEx store; gave up after … attempts — nothing was committed, retry (ABORTED) | CAS contention | Retry |
the Atlas CapEx store could not be read — nothing was committed: … (UNAVAILABLE) | The appfs root or objectd could not be read | Check the console’s store. See Overview troubleshooting |
CapEx pulls
| Message | Fix |
|---|---|
dataset is required: the table or view to read, as Explore names it | Run Explore on the source first, then name a dataset it lists |
columns names …, which the … feed does not have; its headers are … | Map only the contract headers. See the feeds |
columns maps no header; map at least one of … to a source column | Map at least one column |
Findings and paging
| Message | Cause |
|---|---|
the findings changed (a new ingest, Go-Live date, rule status or threshold) since this page_token was issued — list again from the first page | Findings are recomputed on read, so a page token dies when anything changes. List again from the first page |
no finding "…" in the current feeds — it may have been resolved by an ingest, or its rule is REJECTED (NOT_FOUND) | The finding is gone since the page loaded |
no CapEx feed is loaded — there is nothing to scan (no scan run was recorded) | A capex_scan step or scan ran with no feed loaded. Upload the feeds first |
update_mask names "…"; the only configurable field is go_live_date | UpdateConfig sets only the Go-Live date. Thresholds go through rule governance |
Rule governance
| Message | Meaning |
|---|---|
four eyes: … proposed … and may not decide it — it needs … (the proposer may only WITHDRAW) | Another person (the rule owner or an Atlas admin) must decide |
only the proposer (…) may withdraw … | Only the proposer can withdraw |
… already has an open change (…) — decide or withdraw it first | One open change per rule at a time |
rationale is required — a change nobody can explain is not reviewable | Add a rationale |
parameter "…" is not a threshold a change may set; one of: … | Use tolerance_days, unit_price_capital_threshold, approval_lag_min_days, request_plan_tolerance_pct or overspend_factor |
… must be between … and … (a rule is switched off by a REJECTED status, visibly, not by a threshold) | The value is out of range. Reject the rule instead |
… cannot be dry-run: … (FAILED_PRECONDITION) | The fix is ADVISORY. No mechanical rewrite exists to simulate |
decision must be APPROVE or DISMISS for a remediation | Remediations take only those two decisions |
Onboarding and workspace
| Message | Fix |
|---|---|
onboarding cannot be completed; unmet: … | Grant at least one source and select the connectable engine core-capex |
dq_engine_id "…" (…) is NOT_CONNECTABLE: … | Only CORE’s engine is connectable |
source_ids names "…", which is not a connection in CORE's registry (/api/connections) | Create the connection in DataEx › Connections first |
agent_ids names "…", which is not a registered agent (RegisterAgent first) | Register the agent first |
the connection registry could not be read, so the granted sources cannot be confirmed — onboarding is unchanged: … | The registry is down. Nothing was written |
Resolve
| Message / outcome | Meaning |
|---|---|
runner_unknown — …, which is not registered in CORE (DataEx › Runners), so nothing was dialled, here or anywhere else; … | The binding or choice names no runner. Choose console or enrol the runner |
runner_offline — …: connected; dispatch arrives in rollout step 6 … | The runner is up, but CORE cannot dispatch to runners yet. Choose console |
runner_offline — …, which has not completed enrolment yet … / … enrolled but not connected … | Finish enrolment, or check that the runner is reachable from the console pod |
runner_revoked | An admin revoked it. Choose another runner or console |
failed — runner registry unavailable: … | The runner registry could not be read. Nothing was dialled |
map run … started by … at … is still in flight; one run at a time | Wait for the current map run to finish |
no registered source has a connector runtime, so there is nothing to map | No registered source type is supported by the engine |
window_days must be 1..90, got … | Access patterns take a window of 1 to 90 days |
the connection registry is not open on this console: … | The console’s registry did not open. Check CORE_ENVELOPE_KEK and the store |
Playbooks
| Message | Meaning |
|---|---|
four eyes: … and may not activate it — an active playbook starts agents on its own, … | Another Atlas admin must activate it |
four eyes: … started … and may not decide its approval | The run’s initiator cannot approve it |
… is … — only an ACTIVE playbook runs | Activate it first |
… already has a run in flight (…, …) | Wait for the run, or cancel it |
cron "…": the minute field must be ONE number 0-59 — … | A schedule fires at most once an hour |
….dispatch_agent.agent "…": one of … (ListDispatchableAgents) | Only these six agents are dispatchable |
….notify.repo "…": a repository NAME in the console's org (no owner/, no URL) | Give a bare repository name |
Event skipped: cooldown: trigger … started a run at … / chain depth … exceeds 3 … | The loop guard skipped the event. This is working as designed |
the GitHub App installation named no org, so there is nowhere to dispatch to | Configure the GitHub App on the console |
A step ends TIMED_OUT | The agent’s step report never arrived. Check the agent’s workflow run and its playbook-step-report.sh step |
Step-report door: 401 missing bearer token, 404 unknown run "…", 409 step … of … is not awaiting a report … or … awaits a report from agent "…", not "…".
Ask
| Status / message | Fix |
|---|---|
UNAVAILABLE inference not configured (INFERENCE_REMOTE_URL unset) — no model was called | Point the console at the model router |
UNAVAILABLE the sovereign model could not be reached, so this Ask stopped: … | Check the inference plane (DataEx › Inference) |
PERMISSION_DENIED (the guardrail’s own wording) | The question or the answer was blocked by the console-ask guardrails |
INVALID_ARGUMENT question is … bytes; the limit is 2000 | Shorten the question |
INVALID_ARGUMENT scope must be INTELLIGENCE or DATAEX | Set the scope |
Answer STOPPED with a stop_reason | A step, token or deadline limit was hit. Ask a narrower question |
Lineage and recon ingests
| Response | Fix |
|---|---|
503 observed lineage ingest is not configured (CORE_HEALTH_INGEST_TOKEN unset; …) | The provisioner-generated health token Secret is not mounted on the console |
503 rules-reconciliation ingest is not configured (CORE_RECON_INGEST_TOKEN unset) | Secret core-recon-token is not projected |
403 bad ingest token | The caller holds a different token |
An empty page is not an error
An EMPTY provenance means nothing has been uploaded or explored, and the page says so. An UNAVAILABLE provenance means the store could not be read, and the page gives the store’s reason. Neither is drawn as zero. On a fresh workspace, rules reconciliation shows mostly Shadow, which is correct (see Rule governance).