Skip to main content

The CompleteStatus Blog

Monitoring & security, explained

Practical, no-fluff guides on uptime and security monitoring — fixing security headers, email authentication, SSL certificates, and consolidating your monitoring stack.

RSS feed
outages incidents

The Atlassian Outage — Two Weeks of Downtime and What Not to Say

A maintenance script permanently deleted ~400 Atlassian customers' cloud sites; restoration took two weeks. Lessons on incident communication and backups.

6 min read
redirects http

Redirect Chains — What Every Extra Hop Costs, and How to Monitor Them

How http→https→www→slash stacks into 3–4 hops, what each hop costs in DNS and TLS handshakes, the apex-vs-www certificate gotcha, and how to monitor the chain.

6 min read
uptime monitoring

Ping vs HTTP Checks — What "Up" Actually Means

Ping succeeds while your site serves 500s; HTTP returns 200 while the page is broken. What ICMP, TCP, HTTP and browser checks each prove, and when to use them.

6 min read
security log4shell

Log4Shell — What CVE-2021-44228 Is Teaching Us, Mid-Scramble

Log4Shell (CVE-2021-44228) is a trivially exploitable RCE in Log4j, and patching is still under way. What the scramble teaches every team, Java or not.

6 min read
outages dns

The Facebook Outage — What BGP and DNS Taught Everyone This Week

Facebook, Instagram and WhatsApp vanished for six hours this week after a BGP misstep took out their DNS. What the outage teaches every team about resilience.

6 min read
https tls

Fixing Mixed Content Warnings — Finishing the HTTPS Migration You Started

Active vs passive mixed content, how browsers treat each, finding hardcoded http:// URLs, CSP upgrade-insecure-requests, and staying clean after migration.

6 min read
security ransomware

Kaseya VSA: When the Tool That Manages Everything Gets Hit

Ransomware pushed through Kaseya VSA over a holiday weekend reached businesses via their IT providers. What agencies and small teams should check now.

6 min read
outages cdn

The Fastly Outage — What Tuesday's Hour of Broken Internet Says About Third-Party Risk

Fastly's June 8 outage took down Amazon, Reddit and gov.uk for nearly an hour. What one config change teaches about CDN blast radius and third-party risk.

6 min read
ssl lets-encrypt

Let's Encrypt Renewal Failures — When 90-Day Automation Silently Stops

Let's Encrypt automation fails quietly: broken certbot upgrades, rate limits, blocked port 80, lost cron jobs. Independent expiry monitoring is the net.

6 min read
backups disaster-recovery

The OVHcloud Strasbourg Fire: Were Your Backups in the Same Building?

Last week's fire destroyed a data centre in Strasbourg and took backups with it. How to check where your copies really live, and how fast you could restore.

6 min read
http status-codes

HTTP Status Codes Through a Monitoring Lens — What Should Actually Page You

Not every non-200 is an outage and not every 200 is fine. Which HTTP status codes should page you, how to handle 503s and redirects, and the soft-200 trap.

6 min read
security supply-chain

SolarWinds Orion: When the Monitoring Tool Is the Way In

A trojanized Orion update reached thousands of networks. What we know so far, and what it means for any tool that holds the keys to your infrastructure.

6 min read

Browse by topic

Monitor your site — free

Uptime, SSL, DNS, security-header grades and SPF/DKIM/DMARC — one dashboard, one bill. The free tier includes the security layer and allows commercial use.