App Advisor
Service: app-advisor-srv · Port: 8105
The App Advisor is an AI advisor that understands what your application does and gives advice that fits it. A checkout service, an ML training job and a nightly data pipeline have very different needs; the Advisor knows the difference.
Every tenant gets their own App Advisor, running inside their vCluster and deployed by advisor-controller. It only ever sees that tenant's apps.
What it does
| Capability | Description |
|---|---|
| Discovery | Finds the apps running in the vCluster and builds a profile for each — every 10 minutes and on demand. |
| Domain classification | Recognizes each app's domain — ecommerce, api_service, ml_training, data_pipeline, auth, analytics and more — from its image, labels and configuration. You can override the classification. |
| Proactive advice | Writes recommendations that explain why they matter for this kind of app. |
| Conversations | A streaming Q&A session per app — ask about performance, reliability, scaling or cost. |
| Change validation | Given a proposed change, predicts its impact before you apply it. |
| Live metrics | Current request rate, latency, error rate, CPU, memory, replicas and restarts. |
How advice is generated
- Profile — discovery records each app's workload shape: replicas, resources, probes, volumes, autoscaling and traffic.
- Classify — the app's domain is detected (or taken from your override).
- Evaluate — the profile and live metrics are checked against best practices for that domain.
- Explain — Claude writes each piece of advice with its reasoning, impact and the change to make.
Advice has a status — open, dismissed or implemented — so you can track what you've acted on.
Security
Every /api/v1/* route requires a valid token, and every request is checked against the tenant that owns the vCluster. The dashboard's AI Chat forwards the user's own token; agent-runtime uses a service token carrying the tenant it's working for. AI calls use the tenant's AI credential.
REST API
| Method | Path | Description |
|---|---|---|
GET | /api/v1/discovered-apps | Apps discovered in this vCluster. |
POST | /api/v1/discover | Run discovery now. |
GET | /api/v1/profiles | All app profiles. |
GET · PUT | /api/v1/apps/{app_id}/profile | Read or override an app's profile (for example its domain). |
GET | /api/v1/apps/{app_id}/advice | Advice for an app (?status=). |
POST | /api/v1/apps/{app_id}/advice/generate | Generate fresh advice. |
POST | /api/v1/apps/{app_id}/advice/{advice_id}/dismiss · /implement | Update an advice item's status. |
GET · POST | /api/v1/apps/{app_id}/sessions | List or start conversations. |
POST | /api/v1/apps/{app_id}/sessions/{session_id}/query | Ask a question (streams the answer). |
POST | /api/v1/apps/{app_id}/validate | Validate a proposed change. |
GET | /api/v1/apps/{app_id}/live | Live metrics. |
GET | /healthz | Health check. |
Configuration
advisor-controller configures each instance; you rarely need to change these.
| Variable | Default | Description |
|---|---|---|
TENANT_ID | — | The tenant this instance serves. |
DISCOVERY_INTERVAL | 10m | How often to rediscover apps. |
AUTH_JWT_ACCESS_SECRET | — | Validates tokens. |
AUTH_SERVICE_BASE_URL / AI_CREDENTIAL_INTERNAL_API_KEY | — | AI credential resolution. |
APM_GATEWAY_BASE_URL | http://apm-gateway:8101 | Source of request metrics. |
PORT | 8105 | HTTP port. |