Documentation
¶
Overview ¶
Package opsobs holds the recorder the platform's own operations report through (#1898): authentication attempts, configuration warnings and the domain operations a tool call sets off (knowledge, memory, search, the call catalog, the config store, managed resources, table registration, prompts). Those sites sit in a dozen packages, several constructed with no handle to the observability layer, so they read the one recorder the layer installs here instead of having it threaded through every constructor -- the shape internal/outbound uses for the HTTP clients.
Index ¶
Constants ¶
const ( AuthMethodOIDC = "oidc" AuthMethodAPIKey = "api_key" AuthMethodOAuth = "oauth" AuthMethodBrowser = "browser" )
Authentication methods auth_attempts_total names.
const ( AuthResultSuccess = "success" AuthResultFailure = "failure" )
Authentication results.
const ( AuthReasonNone = "none" AuthReasonExpired = "expired" AuthReasonRevoked = "revoked" AuthReasonBadSignature = "bad_signature" AuthReasonUnknownKey = "unknown_key" AuthReasonInvalidClaims = "invalid_claims" AuthReasonMalformed = "malformed" // AuthReasonCodeRejected is a browser sign-in whose authorization code the // identity provider refused with a 4xx: a code that expired or was already // used (a refreshed callback, the back button), or a client the provider // does not accept. The provider answered, so it is not idp_unavailable. AuthReasonCodeRejected = "code_rejected" )
Authentication failure reasons. A reason is a class, never the error text: the text can carry a token's claims or a key's prefix.
const ( DenialToolDenied = "tool_denied" DenialConnectionDenied = "connection_denied" DenialNoPersona = "no_persona" )
Tool-call denial reasons mcp_tool_call_denials_total records.
const ( DependencyDatabase = "database" DependencySemantic = "semantic" DependencyQuery = "query" DependencyObjectStorage = "object_storage" DependencyIDP = "idp" DependencyRenderer = "renderer" )
Dependencies dependency_up reports.
const ( ConnectionConfigured = "configured" ConnectionHealthy = "healthy" ConnectionUnreachable = "unreachable" ConnectionAuthFailed = "auth_failed" )
Connection states mcp_platform_connections reports. A connection whose kind has no probe is configured; one that answered its probe is healthy; one whose upstream refused the platform's credential is auth_failed; any other failure is unreachable.
const ( OpKnowledgeApply = "knowledge.apply" OpMemoryCapture = "memory.capture" OpMemoryManage = "memory.manage" OpSearchQuery = "search.query" OpSearchFetch = "search.fetch" OpCallRecord = "calls.record" OpCallReuse = "calls.reuse" OpCallPromote = "calls.promote" OpCallSweep = "calls.sweep" OpConfigStoreRead = "configstore.read" OpConfigStoreWrite = "configstore.write" OpResourceUpload = "resource.upload" OpResourceExtract = "resource.extract" OpTableRegister = "table.register" OpPromptServe = "prompt.serve" )
Operations domain_operations_total counts. Each is also the name of the span the operation opens.
const ( SinkDataHub = "datahub" SinkKnowledgePage = "knowledge_page" SinkAgentInstructions = "agent_instructions" SinkInsight = "insight" KnowledgeCreated = "created" KnowledgeApplied = "applied" KnowledgeApproved = "approved" KnowledgeRejected = "rejected" KnowledgeFailed = "failed" )
apply_knowledge sinks and outcomes knowledge_changes_total records. SinkInsight is the captured insight itself: created by memory_capture, approved or rejected by a review.
Variables ¶
This section is empty.
Functions ¶
func EndTool ¶
func EndTool(ctx context.Context, op *observability.Op, res *mcp.CallToolResult, err error)
EndTool ends op for a tool handler's outcome: an error, or a result the handler answered as a tool error, counts as error; anything else as ok.
func Metrics ¶
func Metrics() *observability.Metrics
Metrics is the installed recorder, nil (and nil-safe) until one is set.
func SetMetrics ¶
func SetMetrics(m *observability.Metrics)
SetMetrics installs the recorder. Nil-safe; a nil recorder records nothing.
Types ¶
This section is empty.