opsobs

package
v1.141.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package opsobs holds the recorder the platform's own operations report through (#1898): authentication attempts, configuration warnings and the domain operations a tool call sets off (knowledge, memory, search, the call catalog, the config store, managed resources, table registration, prompts). Those sites sit in a dozen packages, several constructed with no handle to the observability layer, so they read the one recorder the layer installs here instead of having it threaded through every constructor -- the shape internal/outbound uses for the HTTP clients.

Index

Constants

View Source
const (
	AuthMethodOIDC    = "oidc"
	AuthMethodAPIKey  = "api_key"
	AuthMethodOAuth   = "oauth"
	AuthMethodBrowser = "browser"
)

Authentication methods auth_attempts_total names.

View Source
const (
	AuthResultSuccess = "success"
	AuthResultFailure = "failure"
)

Authentication results.

View Source
const (
	AuthReasonNone           = "none"
	AuthReasonExpired        = "expired"
	AuthReasonRevoked        = "revoked"
	AuthReasonBadSignature   = "bad_signature"
	AuthReasonUnknownKey     = "unknown_key"
	AuthReasonIDPUnavailable = "idp_unavailable"
	AuthReasonInvalidClaims  = "invalid_claims"
	AuthReasonMalformed      = "malformed"
	// AuthReasonCodeRejected is a browser sign-in whose authorization code the
	// identity provider refused with a 4xx: a code that expired or was already
	// used (a refreshed callback, the back button), or a client the provider
	// does not accept. The provider answered, so it is not idp_unavailable.
	AuthReasonCodeRejected = "code_rejected"
)

Authentication failure reasons. A reason is a class, never the error text: the text can carry a token's claims or a key's prefix.

View Source
const (
	DenialToolDenied       = "tool_denied"
	DenialConnectionDenied = "connection_denied"
	DenialNoPersona        = "no_persona"
)

Tool-call denial reasons mcp_tool_call_denials_total records.

View Source
const (
	DependencyDatabase      = "database"
	DependencySemantic      = "semantic"
	DependencyQuery         = "query"
	DependencyObjectStorage = "object_storage"
	DependencyIDP           = "idp"
	DependencyRenderer      = "renderer"
)

Dependencies dependency_up reports.

View Source
const (
	ConnectionConfigured  = "configured"
	ConnectionHealthy     = "healthy"
	ConnectionUnreachable = "unreachable"
	ConnectionAuthFailed  = "auth_failed"
)

Connection states mcp_platform_connections reports. A connection whose kind has no probe is configured; one that answered its probe is healthy; one whose upstream refused the platform's credential is auth_failed; any other failure is unreachable.

View Source
const (
	OpKnowledgeApply   = "knowledge.apply"
	OpMemoryCapture    = "memory.capture"
	OpMemoryManage     = "memory.manage"
	OpSearchQuery      = "search.query"
	OpSearchFetch      = "search.fetch"
	OpCallRecord       = "calls.record"
	OpCallReuse        = "calls.reuse"
	OpCallPromote      = "calls.promote"
	OpCallSweep        = "calls.sweep"
	OpConfigStoreRead  = "configstore.read"
	OpConfigStoreWrite = "configstore.write"
	OpResourceUpload   = "resource.upload"
	OpResourceExtract  = "resource.extract"
	OpTableRegister    = "table.register"
	OpPromptServe      = "prompt.serve"
)

Operations domain_operations_total counts. Each is also the name of the span the operation opens.

View Source
const (
	SinkDataHub           = "datahub"
	SinkKnowledgePage     = "knowledge_page"
	SinkAgentInstructions = "agent_instructions"
	SinkInsight           = "insight"

	KnowledgeCreated  = "created"
	KnowledgeApplied  = "applied"
	KnowledgeApproved = "approved"
	KnowledgeRejected = "rejected"
	KnowledgeFailed   = "failed"
)

apply_knowledge sinks and outcomes knowledge_changes_total records. SinkInsight is the captured insight itself: created by memory_capture, approved or rejected by a review.

Variables

This section is empty.

Functions

func EndTool

func EndTool(ctx context.Context, op *observability.Op, res *mcp.CallToolResult, err error)

EndTool ends op for a tool handler's outcome: an error, or a result the handler answered as a tool error, counts as error; anything else as ok.

func Metrics

func Metrics() *observability.Metrics

Metrics is the installed recorder, nil (and nil-safe) until one is set.

func SetMetrics

func SetMetrics(m *observability.Metrics)

SetMetrics installs the recorder. Nil-safe; a nil recorder records nothing.

func Start

func Start(ctx context.Context, name string) (context.Context, *observability.Op)

Start opens operation name on the installed recorder: a span under ctx's trace and the start of its duration. The caller ends it with End or EndResult.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL