Sentinel settings
The language model Sentinel needs, the settings that control its runs, rule checks, retention and log evidence, and the defaults.
Sentinel runs as the module-sentinel deployment in stackship-system. One process serves
Sentinel's API and does the analysis. Runs and rule checks are coordinated through Sentinel's
database, so only one replica analyses at a time; the state of Analyze with logs is kept in the
process's memory, so run a single replica.
The language model
Analysis runs need a language model. Sentinel uses the platform's LLM gateways: register one under Settings → Platform Settings, tab LLM gateways, and choose the gateway and model for each of Sentinel's three stages — Triage, Brain and Code — on the Sentinel settings tab. Both are described in the platform's own administration pages, under managing LLM gateways.
Sentinel asks for each stage's gateway at the start of every run and of every Analyze with logs, so a change applies from the next one without a restart. The platform grants Sentinel's client the LLM Gateway Consumer role at the platform root itself.
| Situation | What happens |
|---|---|
| No gateway registered | Runs are skipped and Sentinel logs why; rule checks still record findings, and no new runs appear on boundaries' Runs tabs |
| A gateway exists but Sentinel may not use it, or the platform cannot be reached | Runs are skipped, and the log line says what to fix |
| The gateway cannot be reached or answers unusably | The run is recorded as Failed, with a reason that names the stages, the HTTP status and what it usually means |
The installer adds a network policy that lets Sentinel open TCP connections to ports 8081, 8082, 8083 and 4000, besides what the platform's own network policies allow. When a run fails with the gateway did not answer at all, check that the gateway's port is open to Sentinel.
Settings from before the gateways may still be set on the deployment. Agent__ModelName,
Agent__TriageModel, Agent__BrainModel and Agent__CodeModel choose the model for stages that
have no model assigned under Sentinel settings. Agent__TriageBaseUrl,
Agent__BrainBaseUrl, Agent__CodeBaseUrl and Agent__ApiKey are used only when the platform has
no gateway to offer at all; while a gateway exists, Sentinel logs at every run that it ignores them.
Settings
The installer offers these under Agent and Log Evidence. They are environment variables of
the module-sentinel deployment, read when Sentinel starts.
| Installer label | Variable | Default | Meaning |
|---|---|---|---|
| Analysis Interval (minutes) | Agent__IntervalMinutes |
30 |
Time from the end of one run to the start of the next. Findings not seen for twice this long are closed |
| Rule Detection Interval (seconds) | Agent__DetectIntervalSeconds |
120 |
Time between rule checks; 0 turns them off, and rules then run only inside runs |
| Retention (days) | Agent__RetentionDays |
30 |
Findings closed as fixed, and evidence and run records nothing refers to, are deleted after this long; 0 keeps everything. The clean-up follows every run |
| Run Once Mode | Agent__RunOnce |
false |
Run once at start, then no further runs or rule checks. The API keeps serving |
| Evidence Lookback (minutes) | Agent__LookbackMinutes |
90 |
Not read by this version: container terminations count for 60 minutes |
| Send Log Evidence to LLM | Agent__LogEvidence |
false |
Adds container logs to what runs send — see What Sentinel sends to the model |
| Log Tail Lines | Agent__LogTailLines |
200 |
Lines taken per container, for log evidence and for Analyze with logs |
| OpenObserve URL | Agent__OpenObserve__BaseUrl |
empty | A second place to read logs from for log evidence, used when the platform's own log read fails |
| OpenObserve Organization | Agent__OpenObserve__Organization |
default |
Organisation to query |
| OpenObserve Log Stream | Agent__OpenObserve__Stream |
default |
Stream to query |
| OpenObserve Authorization Header | Agent__OpenObserve__Authorization |
empty | The whole Authorization header value for OpenObserve; kept in the Secret stackship-sentinel-secrets, key openobserve-authorization |
Two more are not offered by the installer:
| Variable | Default | Meaning |
|---|---|---|
Agent__MaxEvidenceCharsPerCard |
8000 |
Largest size of one piece of evidence, in characters; longer ones lose whole list entries |
Modules__Monitoring__BaseUrl |
http://module-monitoring:8080 |
Where active alerts and the platform's health are read; empty leaves both out, and with them platform findings |