Customers and the deployment map
Customers are environments that belong to a customer, visible only to people granted that customer. When a bug or vulnerability lands, they let you answer "which customers run 1.5.6?" without exposing one customer to another.
Why you would use it
You ship installed software. Each customer runs their own copy and upgrades on their own schedule. A vulnerability is announced that affects 1.5.6 and 1.5.7. Your support lead needs to know, today, which customers to contact, and your account managers each need to see their own customers and nobody else's.
With customers recorded, Affected answers by version, by artifact digest, or by vulnerability: the environments where a matching release is reported, with each report's source and age, and a separate list of the environments it cannot tell about, and why.
When you don't need it
If you run the only copy of your software, as a hosted service does, there are no customer environments to track: Environments is enough.
How it works in Logmarq
- Customers and grants. An administrator adds customers and grants people access to each one. A person with no grant for a customer sees that customer's environments nowhere: not in lists, maps, answers, or release histories. Outgoing webhooks leave them out too.
- Customer environments. An administrator records an environment for a customer on the project, with its own freshness window if the customer reports less often.
- The map. Every environment you may see, grouped by customer and project, with the release reported there, its state, and the release lines it belongs to.
- The affected answer. By version, digest, or vulnerability. For a vulnerability, a finding counts unless a not-affected or fixed decision holds for it, and a running release with no bill of materials or no recent scan is listed as one Logmarq cannot tell about.
- A customer's own notes. One customer can have customer notes with more detail than the general ones, seen only by the people granted that customer.
What it will not claim
- What is reported, not what is running. Every answer rests on recorded deployments, with their source and age. Logmarq does not reach into a customer's environment.
- Cannot tell is an answer. Stale reports, environments with nothing recorded, and releases with no scan are listed as unknowns, never counted as unaffected.
- Not yet used by an outside team. The customer map exists in the development build and has not yet been used by a team outside Dekglas.
Get started
An administrator adds a customer under Administration → Customers, then records the customer's environment from the project's page and grants the people who look after that customer. From the server:
docker exec logmarq logmarq customer create example-co "Example Co"
docker exec logmarq logmarq environments add <project> example-co-prod --customer example-co
docker exec logmarq logmarq affected --vulnerability <id>
Related pages
Environments · Customer-response packages · VEX: vulnerability decisions