Observe the system
Connect commands, workflows, attempts, runtimes, artifacts, and claims without logging secrets.
Outcome
Operators can distinguish process liveness from dependency readiness and correlate persisted product events with stable IDs without exposing credentials. Both backend roles export redacted traces and bounded metrics through one sink-neutral OTLP/HTTP route. A provisionable Grafana dashboard and Prometheus-compatible alert rules cover the signals the product can currently emit honestly.
Prerequisites
Choose approved trace and metric destinations, retention, and incident access before setting an OTLP endpoint. The app never sends prompts, outputs, headers, bodies, provider payloads, exception text, or hidden reasoning through infrastructure telemetry. Exporter headers are secret configuration and are never returned by health endpoints.
Steps
- Query
/health/liveto test only the process event loop. Do not use liveness as dependency proof. - Query
/health/readybefore admitting traffic or work. Read its boundedchecksandcodefields; the response intentionally omits connection targets, credentials, and raw provider errors. - Set
OTEL_EXPORTER_OTLP_ENDPOINTto one approved OTLP/HTTP base URL. Non-loopback endpoints must use HTTPS. If the collector requires authentication, set percent-encoded comma-separatedOTEL_EXPORTER_OTLP_HEADERSvalues in the role's secret manager. - Configure the collector to send metrics to a Prometheus-compatible store and traces to the
approved trace store. Load the checked-in Grafana dashboard and alert rules from
deploy/observability/. - Correlate sanitized traces using stable project, run, task, attempt, execution, and trace IDs. Metric labels remain low-cardinality: bounded routes, outcome classes, transport kinds, the two selected sandbox-provider names, and fixed signal classes only.
- Export approved provider telemetry because provider dashboards are not canonical retention. Store a reasoning summary only when the provider explicitly supplies one; never hidden chain of thought.
The app role exposes redacted /health/live and /health/ready reports. The worker exposes the same
paths on its private health listener: liveness is process-only, while readiness requires PostgreSQL,
the Temporal poller, and a fresh reconciliation/outbox cursor. The reconciliation window defaults to
90 seconds and is configurable from 5 through 3,600 seconds. Optional runtime or provider activation
status is diagnostic and does not make the worker unavailable by itself.
The app readiness report additionally checks database connectivity, the exact repository migration head, and required artifact/auth configuration. In filesystem mode it also verifies that the artifact root is readable and traversable. When OTLP is configured, readiness remains pending until both trace and metric export have succeeded and becomes unavailable after either exporter fails. An absent OTLP endpoint leaves telemetry disabled without constructing a network exporter.
The dashboard covers request/rejection latency, Temporal workflow/activity failures, outbox delivery, workflow-intent outcomes, approval state and age, sandbox reconciliation, attempt/kernel state, artifact publication and finalization, model/tool settlements, model tokens, usage-cost variance, claim-validation age, sandbox lifecycle latency/resources/drift, per-execution kernel output volume, and active/closed SSE and WebSocket connections. The worker rebuilds current state gauges from PostgreSQL every 30 seconds, so process restart does not reset them.
Local Docker and Daytona pass through the same instrumented SandboxProvider. Ready sandboxes use one
fixed five-second, 2 KiB probe that reads cgroup CPU/memory and workspace statvfs only. It performs
no filesystem or process walk and returns no paths, identities, environment, or user content. Lumen
verifies the ExecResult digest and byte accounting, requires exactly one JSON line, and rejects
duplicate keys, non-finite values, extra fields, and impossible resource totals. Provider failures
and protocol rejection remain visible as separate fixed outcomes.
Kernel output volume is observed after the durable execution path accepts each event. Inline bytes come from normalized output JSON and externalized bytes from the verified staged-output size. One histogram sample represents one execution, while labels contain only terminal outcome and storage class—never execution identity or output content.
Verify
Confirm app readiness fails on database, migration, artifact-root, or configured exporter failure.
Make the worker reconciliation state stale and confirm readiness returns 503 with redacted checks
while liveness remains 200. Exercise one command, one outbox delivery, one Temporal operation, one
SSE reconnect, and one WebSocket close; confirm the dashboard changes and alerts evaluate against the
expected bounded labels. Search the sink for canary credentials and sensitive fixture content; any
match blocks activation.
Recover
On leakage, stop the sink, revoke exposed credentials, preserve access-controlled incident evidence, fix redaction at the source, and replay only sanitized diagnostics where policy permits.
For alert-specific triage, follow the checked-in docs/runbooks/observability-alerts.md runbook. Do
not weaken authentication, fencing, idempotency, or redaction to clear an alert.
Alert response
LumenApiErrorRateHigh
Check app readiness, split errors by bounded route, and roll back the app artifact when a route regressed. Keep schema at the migrated version and verify the five-minute ratio remains below 5% for ten minutes.
LumenOutboxDeliveryUnhealthy
Check worker and Temporal readiness, then split delivery outcomes by operation. Allow classified transient retries; investigate operator-required or claim-lost outcomes before redriving anything.
LumenOutboxOperatorRequired
Pause the affected operation class, inspect its canonical outbox fence and provider state, and reconcile by deterministic identity. Redrive only through the product command after ruling out an already accepted side effect.
LumenTemporalWorkflowFailure
Pause affected workflow admission, classify the sanitized failure, and retain the compatible worker for open histories. Replay representative history before deploying a workflow-code fix.
LumenTemporalActivityFailures
Inspect retry state, the activity dependency, and its canonical idempotency/fence record. Stop automatic work when the result is ambiguous, non-retryable, or consuming budget without progress.
LumenWorkflowIntentUnapplied
Compare aggregate version, run generation, plan revision, and deterministic Temporal destination. Treat a stale fence as a safe rejection; reconcile unexplained unapplied intent before redrive.
LumenSandboxReconciliationDrift
Stop new assignment to a repeatedly drifting provider class, compare canonical lease/generation with provider labels, and retry as a new immutable attempt from the last canonical checkpoint.
LumenTransportErrors
Split SSE from WebSocket errors. Verify proxy limits, Origin/Host policy, ticket consumption, and SSE cursor replay; never weaken authentication or ticket scope to restore connectivity.
LumenOperationalSnapshotStale
Restore worker database access or its control loop, then wait for snapshot age to fall below 90 seconds before trusting current approval, queue, cost, and claim gauges.
LumenApprovalStuck
Inspect the canonical request and immutable attempt. Resolve or expire it through the authenticated approval command and verify the pending count falls on the next snapshot.
LumenOutboxBacklog
Check worker and Temporal readiness, preserve deterministic destination IDs, and use the fenced repair/redrive path. Verify both backlog depth and oldest age recover.
LumenKernelQueueStuck
Check the Temporal poller, runtime availability, execution generation, and cancellation fence. Retry or cancel through product commands rather than changing canonical rows directly.
LumenArtifactFinalizationFailures
Check storage availability and exact manifest verification. Preserve rejected staging evidence and retry idempotently after repair; never overwrite canonical bytes or weaken digest checks.
LumenExternalOperationFailures
Split model from tool outcomes and inspect sanitized traces plus canonical settlements. Reconcile an ambiguous provider result by its existing identity before retrying, with no implicit paid fallback.
LumenSandboxTelemetryFailures
Split by the fixed provider and provider/protocol reason. Re-run the exact image smoke; do not weaken the fixed timeout, output cap, digest check, or strict schema to restore a graph.
LumenSandboxResourcePressure
Confirm cgroup memory/RSS and workspace disk against the selected class. Reduce admission or choose an approved class within the current budget, preserve canonical artifacts, and verify pressure remains below 90% for a full lookback.
LumenSandboxLifecycleLatencyHigh
Split create/start/stop latency by fixed provider. Reconcile ambiguous creation by deterministic labels, pause affected admission, and never introduce an implicit provider fallback.
LumenKernelOutputVolumeHigh
Compare inline and externalized volume with output count and artifact finalization. Interrupt runaway work through the product command, preserve committed evidence, and move large results to paged artifacts rather than weakening limits.