Iris login / authentication outage

Incident Report for Equiem

Postmortem

Summary

On 8 July 2026, users were unable to sign in to Iris. The sign-in page looped without completing, affecting all users attempting to log in. Sign-in was restored at 00:42 UTC, within 40 minutes of the first report reaching us at 00:04 UTC.

What happened

We deployed an upgrade to a core authentication library to remediate a security vulnerability. The upgrade carried a documented breaking change for a specific legacy authentication setting. Our test environment used the modern setting and passed all checks, but our production environment was still on the legacy setting, a configuration difference dating back to when Iris was originally built that had gone unnoticed. When the upgrade reached production, sign-in broke.

The first report reached us at 00:04 UTC. An incident was declared at 00:25 UTC, the root cause was identified within a minute, and a rollback was deployed, restoring sign-in at 00:42 UTC.

Impact

Sign-in to Iris was restored within 40 minutes of the first report.

What we are doing about it

The underlying cause was configuration drift between our test and production environments. That has been corrected: both environments now use the same modern authentication setting, and the security upgrade was safely redeployed the following day with no regressions. Two further follow-up actions have come out of the review: verifying production configuration directly against documented breaking changes before upgrades of this kind are released, rather than relying on the test environment as a proxy, and adding a manual review step immediately after high-impact production deployments that land during peak usage hours.

Posted Jul 23, 2026 - 21:20 UTC

Resolved

The fix has been deployed and users can log in to Iris again. This incident is resolved.
Posted Jul 08, 2026 - 00:45 UTC

Identified

Users are unable to log in to Iris. We have identified the root cause and are deploying a fix.
Posted Jul 08, 2026 - 00:33 UTC
This incident affected: Supporting Applications (Iris).