Skip to content

Troubleshooting

Each entry below quotes a message exactly as the console returns it (from internal/console/atlas_*.go, ask*.go, datalineageingest.go and rulesrecon*.go), then gives the cause and the fix. The pages draw these messages verbatim, so what you see on screen is the text you can search for here. … marks a value filled in at runtime.

Every write is refused

this console has no sign-in configured, so an Atlas CapEx change would be unattributable — set GOOGLE_CLIENT_ID or CONSOLE_ADMIN_PASSWORD before uploading, committing or clearing capital feeds

Cause: the console has no sign-in, so nobody can be attributed. The governance, playbook, workspace, Resolve and Ask refusals have the same shape, each naming its own subject. Fix: configure sign-in (GOOGLE_CLIENT_ID or CONSOLE_ADMIN_PASSWORD). Reads keep working in the meantime.

PERMISSION_DENIED on a write

Cause: your identity is not in CORE_ATLAS_ADMINS. That variable is optional. Unset means every identity the console admits; set, it narrows the admins to the list. On the page, the first PermissionDenied disables every write and shows the reason. Fix: ask an admin to add your email, or have a listed admin perform the action.

UNAUTHENTICATED

unauthorized — the console session is not valid; sign in again

Cause: the session cookie expired or was revoked. Fix: sign in again.

HTTP 403 “cross-origin gRPC-web is not served by the console”

Cause: the request’s Origin names another site. gRPC-web is served same-origin only, with no CORS. Fix: call the console from its own origin.

CapEx uploads

MessageCauseFix
File is … ; the upload cap is … per feed. Nothing was staged — split or trim the file (it is never truncated). (code too_large)The CSV is over 8 MiBSplit the file
File has … data rows; the cap is 50000 rows per feed. … (code too_large)More than 50,000 rowsSplit the feed
File is not UTF-8 (first invalid byte on line …). Save it as "CSV UTF-8" and upload again — nothing was staged. (code not_utf8)For example, an Excel Windows-1252 exportRe-save as CSV UTF-8
… uploads are already staged (the cap is 12); commit them or wait for the oldest to expire at … (RESOURCE_EXHAUSTED)12 stages are pendingCommit, or wait out the 30-minute expiry
stage "…" is unknown or has expired (stages are kept 30m0s) — stage the file againThe stage is more than 30 minutes oldStage the file again
stages "…" and "…" are both for …; an ingest takes at most one upload per feedTwo stages for the same feedCommit one per feed
no stage_ids given — stage at least one feed firstAn empty commitStage first
other writers kept changing the Atlas CapEx store; gave up after … attempts — nothing was committed, retry (ABORTED)CAS contentionRetry
the Atlas CapEx store could not be read — nothing was committed: … (UNAVAILABLE)The appfs root or objectd could not be readCheck the console’s store. See Overview troubleshooting

CapEx pulls

MessageFix
dataset is required: the table or view to read, as Explore names itRun Explore on the source first, then name a dataset it lists
columns names …, which the … feed does not have; its headers are …Map only the contract headers. See the feeds
columns maps no header; map at least one of … to a source columnMap at least one column

Findings and paging

MessageCause
the findings changed (a new ingest, Go-Live date, rule status or threshold) since this page_token was issued — list again from the first pageFindings are recomputed on read, so a page token dies when anything changes. List again from the first page
no finding "…" in the current feeds — it may have been resolved by an ingest, or its rule is REJECTED (NOT_FOUND)The finding is gone since the page loaded
no CapEx feed is loaded — there is nothing to scan (no scan run was recorded)A capex_scan step or scan ran with no feed loaded. Upload the feeds first
update_mask names "…"; the only configurable field is go_live_dateUpdateConfig sets only the Go-Live date. Thresholds go through rule governance

Rule governance

MessageMeaning
four eyes: … proposed … and may not decide it — it needs … (the proposer may only WITHDRAW)Another person (the rule owner or an Atlas admin) must decide
only the proposer (…) may withdraw …Only the proposer can withdraw
… already has an open change (…) — decide or withdraw it firstOne open change per rule at a time
rationale is required — a change nobody can explain is not reviewableAdd a rationale
parameter "…" is not a threshold a change may set; one of: …Use tolerance_days, unit_price_capital_threshold, approval_lag_min_days, request_plan_tolerance_pct or overspend_factor
… must be between … and … (a rule is switched off by a REJECTED status, visibly, not by a threshold)The value is out of range. Reject the rule instead
… cannot be dry-run: … (FAILED_PRECONDITION)The fix is ADVISORY. No mechanical rewrite exists to simulate
decision must be APPROVE or DISMISS for a remediationRemediations take only those two decisions

Onboarding and workspace

MessageFix
onboarding cannot be completed; unmet: …Grant at least one source and select the connectable engine core-capex
dq_engine_id "…" (…) is NOT_CONNECTABLE: …Only CORE’s engine is connectable
source_ids names "…", which is not a connection in CORE's registry (/api/connections)Create the connection in DataEx › Connections first
agent_ids names "…", which is not a registered agent (RegisterAgent first)Register the agent first
the connection registry could not be read, so the granted sources cannot be confirmed — onboarding is unchanged: …The registry is down. Nothing was written

Resolve

Message / outcomeMeaning
runner_unknown — …, which is not registered in CORE (DataEx › Runners), so nothing was dialled, here or anywhere else; …The binding or choice names no runner. Choose console or enrol the runner
runner_offline — …: connected; dispatch arrives in rollout step 6 …The runner is up, but CORE cannot dispatch to runners yet. Choose console
runner_offline — …, which has not completed enrolment yet … / … enrolled but not connected …Finish enrolment, or check that the runner is reachable from the console pod
runner_revokedAn admin revoked it. Choose another runner or console
failed — runner registry unavailable: …The runner registry could not be read. Nothing was dialled
map run … started by … at … is still in flight; one run at a timeWait for the current map run to finish
no registered source has a connector runtime, so there is nothing to mapNo registered source type is supported by the engine
window_days must be 1..90, got …Access patterns take a window of 1 to 90 days
the connection registry is not open on this console: …The console’s registry did not open. Check CORE_ENVELOPE_KEK and the store

Playbooks

MessageMeaning
four eyes: … and may not activate it — an active playbook starts agents on its own, …Another Atlas admin must activate it
four eyes: … started … and may not decide its approvalThe run’s initiator cannot approve it
… is … — only an ACTIVE playbook runsActivate it first
… already has a run in flight (…, …)Wait for the run, or cancel it
cron "…": the minute field must be ONE number 0-59 — …A schedule fires at most once an hour
….dispatch_agent.agent "…": one of … (ListDispatchableAgents)Only these six agents are dispatchable
….notify.repo "…": a repository NAME in the console's org (no owner/, no URL)Give a bare repository name
Event skipped: cooldown: trigger … started a run at … / chain depth … exceeds 3 …The loop guard skipped the event. This is working as designed
the GitHub App installation named no org, so there is nowhere to dispatch toConfigure the GitHub App on the console
A step ends TIMED_OUTThe agent’s step report never arrived. Check the agent’s workflow run and its playbook-step-report.sh step

Step-report door: 401 missing bearer token, 404 unknown run "…", 409 step … of … is not awaiting a report … or … awaits a report from agent "…", not "…".

Ask

Status / messageFix
UNAVAILABLE inference not configured (INFERENCE_REMOTE_URL unset) — no model was calledPoint the console at the model router
UNAVAILABLE the sovereign model could not be reached, so this Ask stopped: …Check the inference plane (DataEx › Inference)
PERMISSION_DENIED (the guardrail’s own wording)The question or the answer was blocked by the console-ask guardrails
INVALID_ARGUMENT question is … bytes; the limit is 2000Shorten the question
INVALID_ARGUMENT scope must be INTELLIGENCE or DATAEXSet the scope
Answer STOPPED with a stop_reasonA step, token or deadline limit was hit. Ask a narrower question

Lineage and recon ingests

ResponseFix
503 observed lineage ingest is not configured (CORE_HEALTH_INGEST_TOKEN unset; …)The provisioner-generated health token Secret is not mounted on the console
503 rules-reconciliation ingest is not configured (CORE_RECON_INGEST_TOKEN unset)Secret core-recon-token is not projected
403 bad ingest tokenThe caller holds a different token

An empty page is not an error

An EMPTY provenance means nothing has been uploaded or explored, and the page says so. An UNAVAILABLE provenance means the store could not be read, and the page gives the store’s reason. Neither is drawn as zero. On a fresh workspace, rules reconciliation shows mostly Shadow, which is correct (see Rule governance).