Connectors
Configure the read-only sources: Kubernetes, Prometheus, Loki, Tempo, Prefect, PostgreSQL, recent changes from Git and rollouts, and snapshots.
Sources at a glance
Instrument your application with standard telemetry. Lumis is configured outside it, reads through these connectors, and never imports your code. All connectors are read-only and bounded by item, byte and time limits, with no hidden retries or pagination.
| Source | Gives Lumis |
|---|---|
| Kubernetes | Services, deployments, pods and ReplicaSets in one context and namespace; links resources to logical services. |
| Prometheus | Instant scalar observations; optional service-graph topology from an existing metric. |
| Loki | Log entries or counts in the incident window, with up to five allowlisted structured-metadata fields. |
| Tempo | Scoped TraceQL searches, span reads and observed topology. |
| Prefect | Allowlisted flow and task runs; optional workflow topology. |
| SQL | One read-only scalar from PostgreSQL (sql extra). |
| Changes | Recent Git commits on mapped paths and Kubernetes rollouts. |
| Snapshots and OTLP exports | Normalized topology, observations and local OpenTelemetry trace exports, for offline replay. |
Install lumis-sdk[http] for the HTTP connectors. All of these were exercised live on the GridCast estate; qualify scope, identities, permissions and query meaning on your own.
Kubernetes
sources:
kubernetes:
enabled: true
context: my-approved-context
namespace: my-estateUses kubectl with your read access. No all-namespace scan, no secret or environment extraction, no kubeconfig edits and no workload changes. If the source fails, preparation stops.
Prometheus
sources:
prometheus:
enabled: true
endpoint: http://localhost:9090
queries:
- id: service-up
provider: prometheus
entity_id: service:demo
key: up
description: Availability at the end of the incident
parameters:
promql: 'min(up{job="demo"})'The query runs at the end of the incident and must return one finite scalar or one vector series; aggregate explicitly. An outage, malformed response or empty result supplies no fact. To add call topology from an existing service-graph metric, set discover_service_graph: true with an explicit service_namespace.
Loki, Tempo and Prefect
sources:
loki:
enabled: true
endpoint: https://approved-log-gateway.example
headers_env:
Authorization: LUMIS_LOKI_AUTHORIZATION
X-Scope-OrgID: LUMIS_LOKI_TENANT
max_results: 50
tempo:
enabled: true
endpoint: http://localhost:3200
max_results: 50
prefect:
enabled: true
endpoint: http://localhost:4200/api
flow_names: [daily-forecast]
max_results: 50| Provider | Parameters and outputs |
|---|---|
loki | logql with an exact stream label matcher; output entries or count; optional fields (up to five structured-metadata fields). |
tempo | traceql with exact resource scope; output entries, duration_ms or spans; or trace_id for explicit spans. |
prefect | Allowlisted flow_name; flow_runs or task_runs; output entries, failed_count or max_duration_ms. |
Point Loki and Tempo at query frontends, and Prefect at its API base (including /api). Credentials in URLs are refused; header values come from environment variables and fail closed when missing. Log counts are not failure rates, and capped results are marked degraded.
Read-only SQL
sources:
sql:
enabled: true
dsn_env: ESTATE_READONLY_DSN
statement_timeout_ms: 5000
connect_timeout_seconds: 5
queries:
- id: incident-events
provider: sql
entity_id: service:demo
key: event_count
description: Registered event count during the incident
parameters:
sql: >-
SELECT count(*) FROM operational_events
WHERE at >= %(started_at)s AND at <= %(ended_at)sEach query is one SELECT or WITH statement returning exactly one row and column. Only started_at and ended_at parameters are accepted. Transactions are read-only and rolled back, but that is not a permission boundary: use a database role that can only read the approved tables. NULL supplies no fact.
Recent changes
Many incidents follow a change. sources.changes attributes recent Git commits and Kubernetes rollouts to graph entities, so a check or the investigator can ask “what changed here, and when?”. A change is evidence about an entity, never proof that it caused the incident.
sources:
changes:
enabled: true
lookback_seconds: 3600
max_records: 50
git:
- id: gitops
root: ../gitops
paths:
services/demo/: ["service:demo"]
queries:
- id: demo-changes
provider: changes
entity_id: service:demo
key: release_changes_30m
description: Recent mapped changes before incident end
parameters: {output: count, lookback_seconds: "1800"}count returns the number of mapped changes in the lookback; seconds_since_latest returns the age of the newest one. Set kubernetes_rollouts: true (with the Kubernetes source enabled) to include rollouts, including re-activations seen through ScalingReplicaSet events. Git is the durable record; Kubernetes event history expires.
Source: Connector reference ↗ in the SDK repository.