alphaswarm-observe
alphaswarm-observe receives normalized application spans and OTLP traffic,
enforces tenant/scope policy, redacts sensitive attributes, and writes to the
configured ClickHouse, PostgreSQL, or forwarding sink. It is private to the
platform network; browser access flows through an authenticated BFF.
Wire and operations
| Field | Value |
|---|---|
| Container port | 8080 |
| Health | GET /healthz, GET /readyz |
| Metrics | GET /metrics (Prometheus request, error, ingest, drop, and latency series) |
| Logs | Structured service/request events; secret and payload redaction applies before export |
| Release | alphaswarm_devops/deployments/services/alphaswarm-observe Helm chart, selected by the platform alphaswarm-services ApplicationSet |
The chart uses prometheus.io/* pod annotations for metrics discovery. Runtime
credentials must come from the configured existing Secret/ExternalSecret path;
raw secret values must never be committed to chart values.