Skip to main content
Version: 1.0

Observability Agent

Port: 8092 · DB Schema: observability

The observability agent is the first stage of the reactive AI pipeline. It collects telemetry on a configurable interval and publishes structured snapshots to the observability.telemetry RabbitMQ exchange.

What it collects, and from where​

This service collects from more than just the host cluster. Every 5 minutes it refreshes its target list: a fixed set of host-cluster targets, plus one target per tenant's currently-Ready vCluster, discovered dynamically by logging in as a real Super-Admin-role system account and listing every CloudSpace and its vClusters via auth-service/kubeopera-api. A tenant's target is keyed by their vCluster's namespace — the same identifier the frontend's own tenant-namespace authorization already uses, so no separate cluster-ID-based authorization scheme was needed to keep this tenant-scoped. If discovery itself fails on a given cycle, the previous target list is kept rather than cleared, so a transient auth-service or kubeopera-api hiccup doesn't blank out telemetry collection entirely.

For each configured target, it collects from:

  • k8s-monitor (/api/health, or a namespace-scoped variant for tenant targets) — cluster/namespace health, node and pod counts, API latency, network throughput
  • security-api (/api/v1/posture/summary) — host-cluster targets only, not per-tenant; security posture score

TelemetrySnapshot Fields​

FieldUnitDescription
ClusterID—The target's identifier — a real cluster ID for host-cluster targets, or a tenant vCluster's namespace for tenant targets
Source—k8s-monitor, security-api, or cicd-gateway
HealthScore0–100Overall cluster/namespace health score
CPUUsagePct%CPU utilisation
MemoryUsagePct%Memory utilisation
ReadyNodeCountcountNodes in Ready state
NodeCountcountAll registered nodes
PodCountcountAll pods observed
FailedPodCountcountPods in Failed phase
CrashLoopCountcountPods in CrashLoopBackOff
APIServerLatencyMsmsAPI server response time
NetworkRxBytesPSbytes/sIngress traffic
NetworkTxBytesPSbytes/sEgress traffic
SecurityPostureScore0–100From security-api, host-cluster targets only

REST API​

MethodPathDescription
GET/api/v1/telemetry/latestMost recent snapshot per target
GET/api/v1/telemetry/historyHistorical snapshots
GET/api/v1/telemetry/eventsTelemetry-derived events
GET/api/v1/telemetry/clustersKnown cluster/target identifiers
GET/healthzHealth check

Environment Variables​

VariableDefaultDescription
K8S_MONITOR_BASE_URLhttp://k8s-monitor:8085k8s-monitor endpoint
SECURITY_API_KEY—Shared secret for security-api's posture endpoint
COLLECTION_INTERVAL30sHow often to collect telemetry
DATABASE_URL—PostgreSQL connection
RABBITMQ_URL—RabbitMQ connection
AUTH_SERVICE_BASE_URL—Required for tenant target discovery
KUBEOPERA_API_BASE_URL—Required for tenant target discovery
AUTH_SERVICE_LOGIN / AUTH_SERVICE_PASSWORD—Credentials for the Super-Admin-role system account used to discover tenant vClusters. Tenant discovery is skipped (not an error) when these, along with the two URLs above, aren't all configured
AUTH_APP_IDKubeOpera's own app rowApp ID used for the discovery login
AUTH_JWT_ACCESS_SECRET—Validates bearer tokens on this service's own REST routes
PORT8092HTTP port