Treating "another PC is linked to this machine" as proof of replacement was wrong. A PC imaged for machine 3010 carries that number from the bench, before it has replaced anything, and several PCs sharing one machine number is a normal state at this site: the part markers do it. Both PCs then reported on their own schedules, each report moved the link and raised an alert, and the pair traded the machine back and forth for as long as both were alive. The PC holding a machine now keeps it while it is still alive. Alive means it has reported within MACHINE_CLAIM_QUIET_HOURS and its asset is still In Use. A challenger is recorded as a dormant link instead, which doubles as the marker saying the claim has already been announced, so a PC sitting on a bench does not alert on every collector cycle. The handover still happens on its own once the old PC has been quiet for a day, which is what a PC pulled off a machine does. Moving the old PC off In Use - Retired, Inventory, In Repair - hands the machine over on the next report, which gives IT a one-step way to force a swap the moment it happens rather than waiting out the window. A day is long enough that a PC switched off overnight, or one behind a network outage, never loses its bay to a spare. Alerts for both cases are gated on a new computers_machinelink_alerts setting and ship OFF. Several part markers legitimately share a machine number here, so the alerts would fire on correct data. Links, warnings in the collector response, and archived history are unaffected; only the sending is gated. Also: the alert goes through send_alert rather than resolving recipients by hand, which had missed the SMTP_ALERT_RECIPIENTS environment fallback, so a site configuring SMTP by environment would have got the webhook and no email.
48 KiB
48 KiB