What Sentinel sends to the model
Which tenant data Sentinel sends to the LLM gateway, when log lines are included, and what is removed first.
Sentinel sends what it knows about every boundary to the LLM gateway chosen for it, so the gateway sees tenant data from the whole platform. Choose a gateway that may receive that data, and decide deliberately whether it may also receive logs.
Every run
For each boundary with something to report, a run sends:
- pod state: names, namespaces, labels, container names, resource requests and limits, container states, termination reasons and exit codes, owner references and conditions;
- Kubernetes warning events and their messages;
- Deployments and StatefulSets with fewer ready copies than wanted;
- the platform's active alerts for the boundary's resources;
- connections the platform blocked in the last 24 hours, as the platform describes them;
- the titles of the findings the rule checks made.
The platform's own health — node load, platform alerts and volume health — goes in requests of its own, without anything that names a boundary.
Sentinel never reads environment variables, command lines, arguments or annotations, and it does not read Secrets. A container's termination message is dropped unless log evidence is on, because it can hold the end of the container's log. Every request carries one boundary's data only.
Turning Sentinel monitoring off on a resource does not change any of this: it only stops findings about the resource from being recorded.
Log evidence
With Send Log Evidence to LLM (Agent__LogEvidence) on, a run also sends, for up to ten
crashing containers, the last lines of the instance that crashed — 200 by default — and keeps
termination messages. Sentinel reads them through the platform, which limits and redacts them, or
from OpenObserve when that is configured and the platform's read fails. The lines are stored on the
findings as evidence.
Analyze with logs
Analyze with logs sends a resource's recent log lines whenever a tenant asks for it, whatever Send Log Evidence to LLM says. The lines are read with the tenant's own permissions, so only someone who may read those logs can send them.
Important
Log lines sent either way are stored on the finding, where everyone with
sentinel/readin the boundary can read them — including people who may not read that resource's logs.
What is removed first
Before anything is stored or sent, Sentinel replaces with [REDACTED]: credentials of known shapes
(cloud and source-hosting tokens, JSON web tokens, private-key headers, bearer tokens, credentials
in URLs, values after password=, secret=, token=, api_key= and similar), the local part of
e-mail addresses, IPv4 addresses other than 127.0.0.1 and 0.0.0.0, and all but the last two
parts of host names with three parts or more.
Caution
Redaction recognises shapes, not meaning. A secret that looks like ordinary text passes through to the gateway. Resource names, labels and namespaces are not redacted.