Skip to main content
Version: 2.0

Observability Agent

Service: observability-agent-srv · Port: 8092 · Database schema: observability

The observability agent is the first stage of the reactive pipeline. On every cycle it collects telemetry for each cluster and tenant, stores it as a snapshot, and publishes it to the observability.telemetry exchange for the analysis agent. Its history also powers the charts and the /agents/observability page.

What it collects​

Targets​

The agent collects from two kinds of target:

  • Host clusters — every cluster registered in KubeOpera.
  • Tenant vClusters — every Ready vCluster in every CloudSpace, identified by its vCluster namespace.

It refreshes the target list every five minutes by asking kubeopera-api for registered clusters and CloudSpaces, using its own service identity with read-only platform scope. If a refresh fails, the previous target list is kept, so a brief outage elsewhere never interrupts collection.

Sources​

For each target it gathers:

SourceWhat it provides
k8s-monitorHealth score, node and pod counts, failures and crash loops, API server latency, network throughput. Tenant targets use a namespace-scoped view.
security-apiThe security posture score — for host clusters and for each tenant's own workloads.
cicd-gatewayRecent deployments (from cicd.events), so later stages can relate anomalies to changes.

Telemetry snapshot​

FieldUnitDescription
ClusterID—The target: a host cluster ID or a tenant vCluster namespace.
Source—k8s-monitor, security-api or cicd-gateway.
HealthScore0–100Overall health of the cluster or tenant.
CPUUsagePct%CPU utilization.
MemoryUsagePct%Memory utilization.
ReadyNodeCountcountNodes in the Ready state.
NodeCountcountAll nodes.
PodCountcountAll pods observed.
FailedPodCountcountPods in the Failed phase.
CrashLoopCountcountPods in CrashLoopBackOff.
APIServerLatencyMsmsAPI server response time.
NetworkRxBytesPSbytes/sInbound traffic.
NetworkTxBytesPSbytes/sOutbound traffic.
SecurityPostureScore0–100Security posture from security-api.

Events​

DirectionExchangeMessage
Publishesobservability.telemetryTelemetryPublishMessage — one per target per cycle.
Consumescicd.eventsDeployment events, attached to the next snapshot as change markers.

REST API​

MethodPathDescription
GET/api/v1/telemetry/latestThe most recent snapshot for each target.
GET/api/v1/telemetry/historySnapshot history (?cluster_id=&from=&to=).
GET/api/v1/telemetry/eventsEvents derived from telemetry.
GET/api/v1/telemetry/clustersKnown target identifiers.
GET/healthzHealth check.

Tenant users only see snapshots for their own vClusters.

Configuration​

VariableDefaultDescription
COLLECTION_INTERVAL30sHow often to collect telemetry.
TARGET_REFRESH_INTERVAL5mHow often to refresh the list of targets.
K8S_MONITOR_BASE_URLhttp://k8s-monitor:8085k8s-monitor endpoint.
SECURITY_API_BASE_URLhttp://security-api:8086security-api endpoint.
SECURITY_API_KEY—Shared secret for security-api.
KUBEOPERA_API_BASE_URL—Used to discover clusters and CloudSpaces.
AUTH_SERVICE_BASE_URL—Used to obtain the service's own access token.
SERVICE_CLIENT_ID / SERVICE_CLIENT_SECRET—The service identity used for discovery (read-only platform scope).
AUTH_JWT_ACCESS_SECRET—Validates bearer tokens on this service's REST API.
DATABASE_URL—PostgreSQL connection.
RABBITMQ_URL—RabbitMQ connection.
PORT8092HTTP port.

Troubleshooting​

  • A tenant is missing from /telemetry/clusters. Check the tenant's CloudSpace is Ready; new vClusters appear within one target refresh (five minutes by default).
  • Snapshots stop arriving. Check the service can reach k8s-monitor and RabbitMQ: kubectl logs deploy/observability-agent-srv -n kubeopera-core.