GitHub Status · History · Incident #6470
RESOLVEDIncident with GitHub.com
Critical · Started Aug 17, 2026 · 1:40 PM
$HTTP_PROTOCOL = (isset($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] == 'on' || $_SERVER['HTTPS'] == 1)) || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https') ? 'https://' : 'http://'; $SITE_URL = $HTTP_PROTOCOL . $_SERVER['SERVER_NAME'] . '/'; ?>
GitHub Status · History · Incident #6470
RESOLVEDCritical · Started Aug 17, 2026 · 1:40 PM
Duration
7h 35m
Severity
Critical
Detection lead
—
User reports
Peak 2/hr
Summary
On August 17, 2026, from 13:28–21:15 UTC (7h 47m), GitHub.com experienced elevated errors and latency across Issues, Pull Requests, APIs, Actions, and Copilot. At peak, web/API error rates were approximately 20%, while archive and raw-content downloads reached approximately 50%. SAML/OIDC authentication, SCIM, and Team Sync were also affected, as well as Actions workflows in GHEC with Data Residency that depend on public workflow step definitions hosted on GitHub.com. Most services recovered by 16:36 UTC as our Central US datacenter recovered; Actions was degraded until approximately 18:03 UTC; and Copilot Token Service fully recovered by 21:02. <br /><br />Some of the failing traffic was moved from Central US to Northern Virginia where it was served successfully until the network failure in Central US was debugged and resolved. Delayed replies to a single internal endpoint triggered a latent retry bug in VS Code that amplified traffic by approximately 10x and caused delayed recovery for the Copilot Token Service. <br /><br />The immediate cause of the failure was network saturation on load balancers in Central US due to a new peak in traffic. Originally this was caused by an Istio sidecar pod reaching its concurrency limits and failing to auto scale correctly because of a misconfigured policy that watched host service but not sidecar limits. One failure cascaded to more and eventually four HAProxy nodes exhausted their flow limits, degrading the gateway auth path and causing widespread authentication latency and failures. The problem was worsened by optimistic retry logic which overloaded internal load balancers. Pausing HAProxy on those nodes simultaneously produced immediate broad recovery. <br /><br />The retry storm in Northern VA was fixed by 1) temporarily reducing gateway retry logic with a PR and 2) blocking inbound Copilot Token Service token requests at the load balancers with a 403, and then gradually ramping back up traffic per-site to allow callers to succeed. <br /><br />Residual Copilot authentication failures continued because client retry behavior amplified load: a failed token operation could generate many extra requests and enter a retry loop. Copilot Token Service traffic increased from a normal 7–9K RPS to 70–100K RPS. Reducing gateway authentication retries and blocking retry-triggering responses stabilized Copilot Token Service and completed recovery. <br /><br />Complicating factors that impeded recovery included a number of scraping attacks on codeload endpoints. <br /><br />To prevent recurrence, our follow-up actions include: <br /><br />- Correcting autoscaling policies to account for service-mesh sidecar concurrency and capacity. <br /><br />- Auditing Istio request, concurrency, and scaling limits across affected services. <br /><br />- Reviewing retry limits and backoff behavior across gateways and clients. <br /><br />- Addressing the VS Code retry behavior that amplified Copilot token traffic. <br /><br />- Improving load-balancer capacity monitoring and regional failover safeguards.
Started
Aug 17, 2026 · 1:40 PM
Resolved
Aug 17, 2026 · 9:15 PM
Duration
7h 35m
Severity
Critical
Event timeline
Investigating
Aug 17 · 1:40 PM GitHubWe are investigating reports of impacted performance for some GitHub services.
Investigating
Aug 17 · 1:41 PM GitHubAPI Requests is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 1:42 PM GitHubActions is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 1:44 PM GitHubWebhooks is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 1:45 PM GitHubWe are seeing an approximate 20% error rate across numerous experiences including Pull Requests, Issues, and others. Investigations are currently under way and we will be posting updates as they become available
Investigating
Aug 17 · 1:46 PM GitHubIssues is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 1:58 PM GitHubPull Requests is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 2:04 PM GitHubWe are experiencing high error rates around 20% for web experiences and api traffic. Archive downloads and raw repository content downloads are experiencing an approximate 50% error rate. Investigations are on-going into the root cause, and updates will continue to be provided as we investigate.
Investigating
Aug 17 · 2:24 PM GitHubWe are experiencing high error rates around 20% for web experiences and api traffic. Archive downloads and raw repository content downloads are experiencing an approximate 50% error rate. SAML and OIDC authentication, SCIM, and Team Sync are also impacted. Investigations are on-going and we will continue to provide updates as we discover more information.
Investigating
Aug 17 · 2:31 PM GitHubCopilot is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 2:45 PM GitHubPull Requests is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 2:49 PM GitHubIssues is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 2:54 PM GitHubPull Requests is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 2:58 PM GitHubActions is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 2:58 PM GitHubWe are experiencing high error rates around 20% for web experiences and api traffic. Archive downloads and raw repository content downloads are experiencing an approximate 50% error rate. SAML and OIDC authentication, SCIM, and Team Sync are also impacted. We are currently performing mitigations based on our investigation thus far and are monitoring for improvement.
Investigating
Aug 17 · 2:58 PM GitHubWebhooks is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 3:01 PM GitHubAPI Requests is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 3:10 PM GitHubPages is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 3:21 PM GitHubGit Operations is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 3:40 PM GitHubWebhooks is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 3:42 PM GitHubWe are experiencing high error rates around 20% for web experiences and api traffic. Archive downloads and raw repository content downloads are experiencing an approximate 50% error rate. SAML and OIDC authentication, SCIM, and Team Sync are also impacted. We are currently performing mitigations and will post updates as we progress.
Investigating
Aug 17 · 4:16 PM GitHubWe are experiencing high error rates around 20% for web experiences and api traffic. Archive downloads and raw repository content downloads are experiencing an approximate 50% error rate. SAML and OIDC authentication, SCIM, and Team Sync are also impacted. We are still working to identify the root cause and will continue to post updates as we learn more and perform mitigation.
Investigating
Aug 17 · 4:36 PM GitHubWe identified the problematic component and have taken corrective actions. There are strong signs of recovery but we are still working to completely restore service, with error rates still remaining slightly elevated. We will post further updates as recovery continues.
Investigating
Aug 17 · 4:59 PM GitHubThe degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks has been mitigated. We are monitoring to ensure stability.
Investigating
Aug 17 · 5:30 PM GitHubGit Operations is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 5:34 PM GitHubWe identified the problematic component and have taken corrective actions, but we are seeing residual impact across numerous services. We are continuing to apply additional mitigations and investigate the remaining impact.
Investigating
Aug 17 · 5:36 PM GitHubIssues is experiencing degraded performance. We are continuing to investigate.
Investigating
Aug 17 · 6:11 PM GitHubWe identified the problematic component and have taken corrective actions, but we are seeing residual impact in the form of sporadic authentication failures. We are continuing to apply additional mitigations and investigate the remaining impact.
Investigating
Aug 17 · 6:23 PM GitHubThe degradation affecting Git Operations has been mitigated. We are monitoring to ensure stability.
Investigating
Aug 17 · 6:48 PM GitHubAPI Requests is experiencing degraded availability. We are continuing to investigate.
Investigating
Aug 17 · 7:01 PM GitHubAPI Requests is operating normally.
Investigating
Aug 17 · 7:13 PM GitHubWe are continuing to investigate sporadic authentication failures. We have partially disabled authentication token retries and have seen improvement, and we are monitoring impact before fully applying this mitigation.
Investigating
Aug 17 · 8:08 PM GitHubWe are continuing to investigate sporadic failures affecting Copilot authentication in some applications. Copilot usage via the GitHub CLI and GitHub App are unaffected.
Investigating
Aug 17 · 8:22 PM GitHubIssues is operating normally.
Investigating
Aug 17 · 8:45 PM GitHubWe are continuing to apply mitigations to address sporadic Copilot authentication failures in some applications. We expect full recovery within the next 30 minutes. Copilot usage via the GitHub CLI and GitHub App are unaffected.
Resolved
Aug 17 · 9:15 PM GitHubOn August 17, 2026, from 13:28–21:15 UTC (7h 47m), GitHub.com experienced elevated errors and latency across Issues, Pull Requests, APIs, Actions, and Copilot. At peak, web/API error rates were approximately 20%, while archive and raw-content downloads reached approximately 50%. SAML/OIDC authentication, SCIM, and Team Sync were also affected, as well as Actions workflows in GHEC with Data Residency that depend on public workflow step definitions hosted on GitHub.com. Most services recovered by 16:36 UTC as our Central US datacenter recovered; Actions was degraded until approximately 18:03 UTC; and Copilot Token Service fully recovered by 21:02. <br /><br />Some of the failing traffic was moved from Central US to Northern Virginia where it was served successfully until the network failure in Central US was debugged and resolved. Delayed replies to a single internal endpoint triggered a latent retry bug in VS Code that amplified traffic by approximately 10x and caused delayed recovery for the Copilot Token Service. <br /><br />The immediate cause of the failure was network saturation on load balancers in Central US due to a new peak in traffic. Originally this was caused by an Istio sidecar pod reaching its concurrency limits and failing to auto scale correctly because of a misconfigured policy that watched host service but not sidecar limits. One failure cascaded to more and eventually four HAProxy nodes exhausted their flow limits, degrading the gateway auth path and causing widespread authentication latency and failures. The problem was worsened by optimistic retry logic which overloaded internal load balancers. Pausing HAProxy on those nodes simultaneously produced immediate broad recovery. <br /><br />The retry storm in Northern VA was fixed by 1) temporarily reducing gateway retry logic with a PR and 2) blocking inbound Copilot Token Service token requests at the load balancers with a 403, and then gradually ramping back up traffic per-site to allow callers to succeed. <br /><br />Residual Copilot authentication failures continued because client retry behavior amplified load: a failed token operation could generate many extra requests and enter a retry loop. Copilot Token Service traffic increased from a normal 7–9K RPS to 70–100K RPS. Reducing gateway authentication retries and blocking retry-triggering responses stabilized Copilot Token Service and completed recovery. <br /><br />Complicating factors that impeded recovery included a number of scraping attacks on codeload endpoints. <br /><br />To prevent recurrence, our follow-up actions include: <br /><br />- Correcting autoscaling policies to account for service-mesh sidecar concurrency and capacity. <br /><br />- Auditing Istio request, concurrency, and scaling limits across affected services. <br /><br />- Reviewing retry limits and backoff behavior across gateways and clients. <br /><br />- Addressing the VS Code retry behavior that amplified Copilot token traffic. <br /><br />- Improving load-balancer capacity monitoring and regional failover safeguards.
User reports · incident window
Hourly report count. Red bars mark the incident window.
Peak: 2 reports/hr
Pulsetic catches degradations minutes before vendors acknowledge them.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026. Pulsetic® is a registered trademark.