Elevated Device URLs/VPN Errors

Incident Report for balena.io

Postmortem

Impact

Users were unable to access their devices via SSH through the web-terminal or the CLI. The CLI would return an error:

user does not have permission to access device

An error in our Renovate configuration allowed our automation system to merge and deploy an unintended backend component to production.

Resolution

Our team quickly identified the issue and:

  1. Immediately rolled back the component to the previous verified version
  2. Restored remote SSH access for all affected devices
  3. Corrected the Renovate bot configuration to prevent similar automatic deployments

Response

  • Enhanced deployment controls: We've restored our automation configuration to ensure all components must pass manual review before production deployment
  • Improved monitoring: We're considering implementing additional alerts to catch similar issues faster
  • Process review: We're reviewing our automated deployment processes to identify other potential gaps

We apologize for the disruption and appreciate your patience as we resolved this issue. If you continue to experience any problems, please contact our support team.

Posted Sep 18, 2025 - 14:18 UTC

Resolved

This incident has been resolved.
Posted Sep 17, 2025 - 22:01 UTC

Monitoring

A fix has been implemented and we are monitoring the results.
Posted Sep 17, 2025 - 21:53 UTC

Identified

The issue has been identified and a fix is being implemented.
Posted Sep 17, 2025 - 21:32 UTC

Monitoring

A fix has been implemented and we are monitoring the results.
Posted Sep 17, 2025 - 20:54 UTC

Identified

The issue has been identified and a fix is being implemented.
Posted Sep 17, 2025 - 20:53 UTC

Investigating

We're experiencing an elevated level of errors in our Device URLs and VPN infrastructure and are currently looking into the issue.
Posted Sep 17, 2025 - 20:10 UTC
This incident affected: Cloudlink (VPN).