DEV Community

Yuhe He
Yuhe He

Posted on

A $0 OSINT Monitoring Pipeline: Public Telegram Alerts on GitHub Actions Cron

A monitoring pipeline that runs 24/7 shouldn't cost a server. Mine crawls public Telegram channel previews, diffs them against the last run, and posts alerts to a Telegram channel — and it bills me exactly $0, because it runs entirely inside GitHub Actions' free cron.

The architecture in one breath: cron fires every 15 minutes → a Python script fetches https://t.me/s/<channel> for each channel in the collection set → normalizes and hashes each post → compares hashes against the state committed from the last run → anything new gets appended to a state file and, if it passes the alert rules, pushed to a Telegram channel via a bot token → the state file is committed back to the repo. Git is the database. No Postgres, no VPS, no daily backup chore.

Why this is genuinely enough for public-source monitoring:

  • The workload is tiny. A run touching 30 channels is 30 HTTP GETs of ~100KB HTML. The free tier's 2,000 minutes/month is not a constraint at 15-minute cadence (that's ~2,880 runs/month at ~20 seconds each — fits by being fast, not by luck; drop to 20-minute cadence for comfort).
  • State in git is a feature. Every collection run is a commit with a timestamp. Auditing "when did we first see this claim" is git log -S. A pipeline whose entire state history is a git history is better than one writing to an anonymous database you back up on Fridays.
  • Diffing is the product. Storage is trivia; the alert is the product. The script doesn't page me for "new post"; it pages me when normalized text fuzzy-matches poorly against the last 20 posts (new information), the advisory wording shifts (the delta event), or a source goes silent for N hours (absence as signal).

The failure modes, so you inherit them for free:

  1. Rate limiting. t.me/s/ is generous at 15-minute cadence; at 1-minute cadence you start seeing 429s and empty shells. Back off exponentially, and detect "empty preview page" explicitly — a 200 with no posts is how a silent outage looks.
  2. Coverage ceiling. The preview endpoint serves the latest ~20 posts; if a busy channel posts >20 times between runs you permanently miss posts. For high-velocity warzone channels, run 5-minute cadence and accept the gap; document it. This is a population, not a census.
  3. Secrets hygiene. The bot token lives in repo secrets; the committed state contains only public post text. Keep it that way or you'll publish your token in a public repo commit one sleepy night.

Total setup cost: one repo, one workflow file, one free GitHub account, and the collection-set design rules (which language channels to include, the 11 de-junking checks, the alert thresholds) — that design layer is the part worth buying, and it's the Telegram & Web OSINT Bundle ($5). The exact output format of a live pipeline run: free sample brief.

Zero servers, zero dollars, zero babysitting — the ops budget of public-source monitoring should be nothing, so you can spend everything on reading.

Top comments (0)