Service: log-gateway · Port: 8099
log-gateway gives the rest of KubeOpera — the dashboard, AI agents and the RCA engine — a simple way to read logs. You ask for logs by service, namespace and time range; it builds the LogQL, queries Loki and returns normalized results. It stores nothing itself.
What you can do
| Operation | Use it to… |
|---|
| Search | Find log lines for a service or namespace in a time range, optionally filtered by text or level. |
| Patterns | See the recurring shapes of log lines (for example connection refused to <_>:5432) and how often each occurs — the fastest way to spot what changed. |
| Context | Get the most recent lines for one service, for a quick look or for an AI agent's context. |
How queries are built
| Request | LogQL selector |
|---|
/search?service=payments-api | {app="payments-api"} |
/search?namespace=prod&service=api | {namespace="prod", app="api"} |
/search?service=api&contains=timeout | {app="api"} |= "timeout" |
/patterns?service=api | {app="api"} | pattern |
Tenant users only see logs from their own vClusters: log-gateway adds the tenant's namespaces to every selector from the caller's token.
REST API
| Method | Path | Description |
|---|
GET | /api/v1/logs/search | Search logs (?service=&namespace=&contains=&level=&start=&end=&limit=). |
GET | /api/v1/logs/patterns | Recurring patterns and counts (?service=&window=1h). |
GET | /api/v1/logs/context | Recent lines (?service=&namespace=&lines=). |
GET | /api/v1/logs/tail | Stream new lines as they arrive (Server-Sent Events). |
GET | /healthz | Health check. |
Configuration
| Variable | Default | Description |
|---|
LOKI_URL | http://loki-gateway.monitoring:80 | Loki endpoint. |
AUTH_JWT_ACCESS_SECRET | — | Validates tokens. |
PORT | 8099 | HTTP port. |