Orkestia
Blog
Lumen

Enable Lumen

Provision the org, plan caps, 403/429 codes, mint lumk_/lump_, first POST /api/logs/ingest

Lumen does not collect anything until an org admin or owner provisions it. After that you mint a key in the Lumen app and send events over HTTP — or install the collector in a Kubernetes cluster.

1. Enable it for the organization

  1. Sign in at app.orkestia.dev.
  2. Open Governance → Observability (Lumen) (/governance/lumen).
  3. If Lumen has never been turned on, the page says Lumen is not enabled for this organization.
  4. Choose a plan:
    • Enable Free — on immediately, no checkout.
    • Enable Pro / Enable Enterprise — Stripe checkout, then Lumen is provisioned.

Until this succeeds, every ingest call returns 403 with "code": "LUMEN_NOT_PROVISIONED". Paused orgs use the same code. Auth failures are 401 INGEST_AUTH_REQUIRED / INGEST_AUTH_INVALID. Over the per-minute cap: 429 INGEST_RATE_LIMITED plus Retry-After and X-RateLimit-*. Over the monthly entry cap: 429 { "quota_exceeded": true }.

Plans

PlanIngest cap / minRetentionIncluded entries / monthIncluded storage
Free6007 days1,000,0001 GB
Pro20,00030 days25,000,00025 GB
Enterprise120,00090 days250,000,000250 GB

The per-minute cap comes from the plan; you cannot type a custom rate limit. Retention 0 means the plan default. Paid plans can raise retention through billing. Extra entry packs and storage GB are sold from Billing on the Lumen tab.

You can pause Lumen (ingest is rejected until you resume) or purge all Lumen data. Purge asks you to type the organization id.

2. Mint an ingest key

Keys live in the Lumen app, not on the Governance page.

  1. Open lumen.orkestia.dev and sign in with the same account.
  2. Go to Get started → Connect a source (/onboarding) or Usage & keys (/billing).
  3. Click generate ingest key.
  4. Copy the secret immediately. It is shown once. Lumen stores only a hash.
PrefixScopeUse
lumk_…ingestCollectors and services that write logs and metrics
lumk_…readScripts that query (optional; a signed-in session also works)
lump_…productPulse product analytics only — see Send data

Send ingest keys as X-Api-Key. Never put an ingest key in a browser. The organization is taken from the key — do not send an organization UUID.

3. Send the first event

A project is the project string on the payload. The first accepted event creates it.

curl -X POST https://lumen-api.orkestia.dev/api/logs/ingest \
  -H "X-Api-Key: lumk_REPLACE_ME" \
  -H "Content-Type: application/json" \
  -d '{
    "project": "my-service",
    "level": "ERROR",
    "message": "Hello from Lumen"
  }'

project and message are required. Full fields: Send data.

To stream a cluster instead, install the collector.

4. Confirm it arrived

Onboarding waits until GET /api/projects returns at least one project, then offers view logs. You can also open lumen.orkestia.dev/logs.

A new error is searchable as a log immediately. The error group (and any alert) appears a moment later.

Next

Send data

Ingest schema, fingerprint, status codes.

Query API

GET filters, mutations, rule JSON.

Collector

Helm install for Kubernetes.

Use Lumen

Dashboards, groups, traces, rules.