Skip to content
Stackship documentation Svenska

SentinelAdministrators

Sentinel settings

The language model Sentinel needs, the settings that control its runs, rule checks, retention and log evidence, and the defaults.

Sentinel runs as the module-sentinel deployment in stackship-system. One process serves Sentinel's API and does the analysis. Runs and rule checks are coordinated through Sentinel's database, so only one replica analyses at a time; the state of Analyze with logs is kept in the process's memory, so run a single replica.

The language model

Analysis runs need a language model. Sentinel uses the platform's LLM gateways: register one under Settings → Platform Settings, tab LLM gateways, and choose the gateway and model for each of Sentinel's three stages — Triage, Brain and Code — on the Sentinel settings tab. Both are described in the platform's own administration pages, under managing LLM gateways.

Sentinel asks for each stage's gateway at the start of every run and of every Analyze with logs, so a change applies from the next one without a restart. The platform grants Sentinel's client the LLM Gateway Consumer role at the platform root itself.

Situation What happens
No gateway registered Runs are skipped and Sentinel logs why; rule checks still record findings, and no new runs appear on boundaries' Runs tabs
A gateway exists but Sentinel may not use it, or the platform cannot be reached Runs are skipped, and the log line says what to fix
The gateway cannot be reached or answers unusably The run is recorded as Failed, with a reason that names the stages, the HTTP status and what it usually means

The installer adds a network policy that lets Sentinel open TCP connections to ports 8081, 8082, 8083 and 4000, besides what the platform's own network policies allow. When a run fails with the gateway did not answer at all, check that the gateway's port is open to Sentinel.

Settings from before the gateways may still be set on the deployment. Agent__ModelName, Agent__TriageModel, Agent__BrainModel and Agent__CodeModel choose the model for stages that have no model assigned under Sentinel settings. Agent__TriageBaseUrl, Agent__BrainBaseUrl, Agent__CodeBaseUrl and Agent__ApiKey are used only when the platform has no gateway to offer at all; while a gateway exists, Sentinel logs at every run that it ignores them.

Settings

The installer offers these under Agent and Log Evidence. They are environment variables of the module-sentinel deployment, read when Sentinel starts.

Installer label Variable Default Meaning
Analysis Interval (minutes) Agent__IntervalMinutes 30 Time from the end of one run to the start of the next. Findings not seen for twice this long are closed
Rule Detection Interval (seconds) Agent__DetectIntervalSeconds 120 Time between rule checks; 0 turns them off, and rules then run only inside runs
Retention (days) Agent__RetentionDays 30 Findings closed as fixed, and evidence and run records nothing refers to, are deleted after this long; 0 keeps everything. The clean-up follows every run
Run Once Mode Agent__RunOnce false Run once at start, then no further runs or rule checks. The API keeps serving
Evidence Lookback (minutes) Agent__LookbackMinutes 90 Not read by this version: container terminations count for 60 minutes
Send Log Evidence to LLM Agent__LogEvidence false Adds container logs to what runs send — see What Sentinel sends to the model
Log Tail Lines Agent__LogTailLines 200 Lines taken per container, for log evidence and for Analyze with logs
OpenObserve URL Agent__OpenObserve__BaseUrl empty A second place to read logs from for log evidence, used when the platform's own log read fails
OpenObserve Organization Agent__OpenObserve__Organization default Organisation to query
OpenObserve Log Stream Agent__OpenObserve__Stream default Stream to query
OpenObserve Authorization Header Agent__OpenObserve__Authorization empty The whole Authorization header value for OpenObserve; kept in the Secret stackship-sentinel-secrets, key openobserve-authorization

Two more are not offered by the installer:

Variable Default Meaning
Agent__MaxEvidenceCharsPerCard 8000 Largest size of one piece of evidence, in characters; longer ones lose whole list entries
Modules__Monitoring__BaseUrl http://module-monitoring:8080 Where active alerts and the platform's health are read; empty leaves both out, and with them platform findings