Orkestia
Blog
Lumen

Lumen

Observability control plane — structured logs, SHA-256 error groups, traces/spans, metrics, Pulse, and a query/MCP API

Lumen is Orkestia's telemetry store and triage engine. It is a separate host from the workflow API: ingest and query live at https://lumen-api.orkestia.dev. The org is off until provisioned; every write then fails with 403 / LUMEN_NOT_PROVISIONED.

Signals are JSON over HTTP (not OTLP protobuf). Grouping is async: ingest persists first, then a fingerprint processor links ERROR / WARNING / CRITICAL lines into error groups and evaluates alert rules.

This section is the contract: provision, keys, ingest schema, query API, collector, app, MCP. Start at Enable or jump to Send data / Query API.

Surfaces

SurfaceURLAuth
Provision / planapp.orkestia.dev/governance/lumenOrg admin session
Applumen.orkestia.devSame Orkestia session
APIhttps://lumen-api.orkestia.devX-Api-Key: lumk_… (ingest/read) or lump_… (Pulse); query also accepts org Bearer
MCPhttps://mcp-lumen.orkestia.dev/mcpAuthorization: Bearer (org token). Separate from mcp.orkestia.dev
HealthGET https://lumen-api.orkestia.dev/healthnone → {"status":"healthy"}

Pipeline

producer  --POST /api/logs|metrics|product/ingest[--/batch]-->  Lumen API
                |  optional: Kafka topic lumen.logs (same JSON as HTTP logs)
                v
         normalize / redact / ingest-rules (drop|sample)
                v
         persist  →  201 { id, received_at }   |  200 { dropped: true }  |  429 quota
                v
         fingerprint (sync hash) + queue
                v
         processor: error groups · alert rules · lumen.alert.fired (ticket channel)
                v
         GET /api/logs · /error-groups · /traces/{id} · /metrics · MCP
SignalWriteRead
LogsPOST /api/logs/ingest[/batch]GET /api/logs, /logs/stats, /logs/pulse
Error groupsderived from logs (not a write API)GET /api/error-groups; mutations PATCH …/resolve|ignore|reopen|assign|severity
Traces / spanslog fields trace_id/span_id, and/or POST /api/traces + …/spansGET /api/traces/{trace_id}, /spans/stats|slow|errors
MetricsPOST /api/metrics/ingest[/batch]GET /api/metrics, /aggregate, /names, /dimensions
PulsePOST /api/product/ingest[/batch] with lump_GET /api/product/events, /stats

Batch bodies are { "items": [ … ] } (Pulse also accepts "events"). Max 1000 items; browser Pulse keys cap at 50.

Keys

PrefixScopeHeaderAllowed
lumk_…ingestX-Api-KeyLog + metric writes
lumk_…readX-Api-KeyGET/HEAD query only (403 WRITE_ACCESS_REQUIRED on mutations)
lump_…productX-Api-Key or Authorization: BearerPulse only

The key binds the org. Do not send organization_uuid / X-Lumen-Organization-UUID on customer keys. Never put lumk_ ingest keys in a browser; Pulse browser keys can be origin- and project-locked.

In this section

Enable

Provision, plans, rate limits, mint lumk_ / lump_.

Send data

Ingest schema, status codes, fingerprint algorithm, SDK, Kafka.

Query API

Filters, pagination, traces, metrics aggregate, rule JSON.

Collector

DaemonSet → /api/logs/ingest/batch + /api/metrics/ingest/batch.

App

UI paths mapped to the same API.

MCP

Tool inventory on mcp-lumen.orkestia.dev.

Custody

Lumen stores telemetry you sent (lines, fingerprints, spans, series, triage notes) plus what grouping derived. It does not store source or App Data rows. A secret in message / traceback / context is stored. Use structured fields, ingest drop rules, and keep credentials out of logs. See Security & compliance.