Build

Connectors

Configure the read-only sources: Kubernetes, Prometheus, Loki, Tempo, Prefect, PostgreSQL, recent changes from Git and rollouts, and snapshots.

v0.1.0 · experimentalPython 3.11+Updated 2026-10-05

Sources at a glance

Instrument your application with standard telemetry. Lumis is configured outside it, reads through these connectors, and never imports your code. All connectors are read-only and bounded by item, byte and time limits, with no hidden retries or pagination.

SourceGives Lumis
KubernetesServices, deployments, pods and ReplicaSets in one context and namespace; links resources to logical services.
PrometheusInstant scalar observations; optional service-graph topology from an existing metric.
LokiLog entries or counts in the incident window, with up to five allowlisted structured-metadata fields.
TempoScoped TraceQL searches, span reads and observed topology.
PrefectAllowlisted flow and task runs; optional workflow topology.
SQLOne read-only scalar from PostgreSQL (sql extra).
ChangesRecent Git commits on mapped paths and Kubernetes rollouts.
Snapshots and OTLP exportsNormalized topology, observations and local OpenTelemetry trace exports, for offline replay.

Install lumis-sdk[http] for the HTTP connectors. All of these were exercised live on the GridCast estate; qualify scope, identities, permissions and query meaning on your own.

Kubernetes

yaml
sources:
  kubernetes:
    enabled: true
    context: my-approved-context
    namespace: my-estate

Uses kubectl with your read access. No all-namespace scan, no secret or environment extraction, no kubeconfig edits and no workload changes. If the source fails, preparation stops.

Prometheus

yaml
sources:
  prometheus:
    enabled: true
    endpoint: http://localhost:9090
queries:
  - id: service-up
    provider: prometheus
    entity_id: service:demo
    key: up
    description: Availability at the end of the incident
    parameters:
      promql: 'min(up{job="demo"})'

The query runs at the end of the incident and must return one finite scalar or one vector series; aggregate explicitly. An outage, malformed response or empty result supplies no fact. To add call topology from an existing service-graph metric, set discover_service_graph: true with an explicit service_namespace.

Loki, Tempo and Prefect

yaml
sources:
  loki:
    enabled: true
    endpoint: https://approved-log-gateway.example
    headers_env:
      Authorization: LUMIS_LOKI_AUTHORIZATION
      X-Scope-OrgID: LUMIS_LOKI_TENANT
    max_results: 50
  tempo:
    enabled: true
    endpoint: http://localhost:3200
    max_results: 50
  prefect:
    enabled: true
    endpoint: http://localhost:4200/api
    flow_names: [daily-forecast]
    max_results: 50
ProviderParameters and outputs
lokilogql with an exact stream label matcher; output entries or count; optional fields (up to five structured-metadata fields).
tempotraceql with exact resource scope; output entries, duration_ms or spans; or trace_id for explicit spans.
prefectAllowlisted flow_name; flow_runs or task_runs; output entries, failed_count or max_duration_ms.

Point Loki and Tempo at query frontends, and Prefect at its API base (including /api). Credentials in URLs are refused; header values come from environment variables and fail closed when missing. Log counts are not failure rates, and capped results are marked degraded.

Read-only SQL

yaml
sources:
  sql:
    enabled: true
    dsn_env: ESTATE_READONLY_DSN
    statement_timeout_ms: 5000
    connect_timeout_seconds: 5
queries:
  - id: incident-events
    provider: sql
    entity_id: service:demo
    key: event_count
    description: Registered event count during the incident
    parameters:
      sql: >-
        SELECT count(*) FROM operational_events
        WHERE at >= %(started_at)s AND at <= %(ended_at)s

Each query is one SELECT or WITH statement returning exactly one row and column. Only started_at and ended_at parameters are accepted. Transactions are read-only and rolled back, but that is not a permission boundary: use a database role that can only read the approved tables. NULL supplies no fact.

Recent changes

Many incidents follow a change. sources.changes attributes recent Git commits and Kubernetes rollouts to graph entities, so a check or the investigator can ask “what changed here, and when?”. A change is evidence about an entity, never proof that it caused the incident.

yaml
sources:
  changes:
    enabled: true
    lookback_seconds: 3600
    max_records: 50
    git:
      - id: gitops
        root: ../gitops
        paths:
          services/demo/: ["service:demo"]
queries:
  - id: demo-changes
    provider: changes
    entity_id: service:demo
    key: release_changes_30m
    description: Recent mapped changes before incident end
    parameters: {output: count, lookback_seconds: "1800"}

count returns the number of mapped changes in the lookback; seconds_since_latest returns the age of the newest one. Set kubernetes_rollouts: true (with the Kubernetes source enabled) to include rollouts, including re-activations seen through ScalingReplicaSet events. Git is the durable record; Kubernetes event history expires.

Source: Connector reference ↗ in the SDK repository.