Orkestia
Blog
Lumen

Collector

Install the Kubernetes collector so pod logs, events, and cluster metrics land in your Lumen organization

The Lumen collector runs in your cluster. It tails pod logs, can scrape Kubernetes Events and CPU/memory usage, and POSTs batches to https://lumen-api.orkestia.dev.

The collector chart lives in a private repository. Your Orkestia account team gives you a checkout (or a chart package) and a pinned image. You do not need the repository to be public to install it.

Enable Lumen and mint an ingest key first — Enable Lumen.

What it collects

SourceDefaultWhere it lands
Pod logsOn (WARNING and above in this install)POST /api/logs/ingest/batch, source=kubernetes
Kubernetes EventsOffSame log path, source=kubernetes-event
CPU / memoryOff (needs Metrics API)POST /api/metrics/ingest/batch (k8s.node.*, k8s.pod.*, k8s.container.*)
Collector healthOnMetrics, project lumen-collector (collector.up, collector.pipeline.*)

Skipped namespaces by default: kube-*, lumen-collector, local-path-storage, ingress-nginx, cert-manager, metrics-server.

Payloads are the same JSON as Send data (RawLog / MetricIngest). With metadata enrichment on, project is app.kubernetes.io/name, then app, then the namespace. Optional Kafka publish uses topic lumen.logs (same body as HTTP logs). Metrics are HTTP-only.

Install

You need kubectl, Helm 3, cluster access, the chart, and the image tag you were given.

1. Auth Secret

The Secret value is the full header line:

kubectl create namespace lumen-collector

kubectl -n lumen-collector create secret generic lumen-collector-auth \
  --from-literal=requestHeader='X-Api-Key: lumk_REPLACE_ME'

Rotate by minting a new key in Usage & keys, updating this Secret, restarting the DaemonSet, then revoking the old key.

2. Helm

From the chart directory:

helm upgrade --install lumen-collector ./deploy/helm/lumen-collector \
  --namespace lumen-collector \
  --create-namespace \
  --set clusterName=my-cluster \
  --set environment=production \
  --set rbac.create=true \
  --set image.repository=<registry-you-were-given>/lumen-collector \
  --set image.tag=<pinned-tag> \
  --set sources.podLogs.parser=cri \
  --set sources.podLogs.minLevel=WARNING \
  --set sources.podLogs.metadataEnabled=true \
  --set sink.type=http \
  --set sink.http.endpoint=https://lumen-api.orkestia.dev/api/logs/ingest/batch \
  --set sink.http.metricsEndpoint=https://lumen-api.orkestia.dev/api/metrics/ingest/batch \
  --set sink.http.requestHeaderSecret.name=lumen-collector-auth
ValueSet to
clusterNameStable name for this cluster
environmentproduction, staging, … (becomes Lumen environment)
sources.podLogs.parsercri for containerd / most managed Kubernetes; docker for Docker json-file
sources.podLogs.metadataEnabledtrue so project is the workload name, not the namespace
sources.podLogs.startAtend skips old files; beginning backfills
image.repository / image.tagThe release you were given. Pin the tag.

Do not put an organization UUID in values. The key selects the org.

3. Optional: events and usage metrics

helm upgrade lumen-collector ./deploy/helm/lumen-collector \
  --namespace lumen-collector \
  --reuse-values \
  --set rbac.create=true \
  --set sources.events.enabled=true \
  --set sources.metrics.enabled=true

Leave metrics off if kubectl get --raw /apis/metrics.k8s.io/v1beta1 fails.

Logs run as DaemonSet lumen-collector-logs (hostPath for files and offsets under /var/lib/lumen-collector). Events run as a Deployment when enabled.

Confirm

kubectl -n lumen-collector rollout status daemonset/lumen-collector-logs --timeout=180s
kubectl -n lumen-collector get pods -o wide
kubectl -n lumen-collector logs daemonset/lumen-collector-logs --since=10m

Then open lumen.orkestia.dev/logs (source=kubernetes) and Metrics for collector.up under project lumen-collector.

Treat the collector as degraded if collector.up is missing for more than a minute, or if collector.pipeline.failed / .dropped is above zero, even when pods are Running.

Settings worth knowing

Helm valuePurpose
sources.podLogs.minLevelDrop lines below this level
sources.podLogs.excludeNamespacesExact or * filters
sources.podLogs.excludePods / excludeContainersSame for names
sources.metrics.intervalDefault 30s
selfMetrics.enabledCollector health (default on; needs the metric URL)
sink.http.requestHeaderSecret.*Auth. Secret key defaults to requestHeader

Prefer the Secret over putting X-Api-Key in Helm values. The log container reads node log files (uid 0, read-only root filesystem).

Troubleshooting

SymptomLikely cause
403 LUMEN_NOT_PROVISIONEDOrg not enabled, or Lumen is paused. Enable first.
401Secret is not X-Api-Key: lumk_…, or the key is not scope ingest / was revoked
429Plan ingest cap
Pods Running, empty LogsminLevel too high, namespace excluded, wrong parser (cri vs docker), nothing new since startAt=end
Projects are namespace namesmetadataEnabled is false, or the ServiceAccount cannot list pods
No k8s.* metricsMetrics source is off, or Metrics API is missing

Next

Send data

Exact log and metric fields + fingerprint.

Query API

How those lines are queried.