From Observability to Agentic Operations

Career BLOG
5
min read

Investigation in a distributed estate is mostly clerical. The evidence exists, but it sits in systems that do not talk to each other, and the first twenty minutes of an incident go on assembling it rather than thinking about it — a PromQL query in one tab, a log search in another, a trace viewer in a third, audit records elsewhere. Every pivot is manual, and it falls under time pressure on whoever picked the incident up, support analyst or on-call engineer.

What We built

Kagent runs the agents on Kubernetes and OpenShift, declared as resources alongside the workloads they investigate. It owns the agent loop, the tool wiring and the agent's Kubernetes workload identity, so an agent is deployed, versioned and governed like any other workload.

The MCP servers are the integration layer. Each one exposes only the bounded operations a support investigation needs, against one system, scoped to a tenant, with a read-only credential of its own. Those systems vary by engagement: metrics in Prometheus, logs and often traces in Elastic, traces in Jaeger elsewhere, audit records in a database of their own. The agent asks the same question regardless and absorbing that variation is what the layer is for.

The reason to put an agent there is narrow but real. A dashboard answers a question somebody already knew to ask. An investigation is an evolving question: the second query depends on what the first returned. An agent chooses that next query, runs it against a different system, and returns a hypothesis with the evidence behind it.

What an Investigation Looks Like

Latency rises on a payment API. The agent starts in Prometheus. The regression is real and bounded to one service, but the metric cannot say which requests were slow. It pivots through an exemplar to a trace ID, pulls that trace, and locates the span where the time went. A downstream call, not the service that raised the alert. It then runs an ES|QL query for the downstream service's logs on the same trace ID, and checks audit records for changes in the window.

What comes back is not a verdict. It is a prioritized list: the regression, the implicated span, the correlated log entries, and a change that landed nine minutes earlier — proximity, not proof — each with the query that produced it, so the engineer can disagree with any step. The agent removed the assembly, not the judgement.

Why the Telemetry Has to be Disciplined First

Metrics should not use request identifiers as high-cardinality labels: Prometheus's own documentation warns against them, because every distinct value becomes another time series. So, the route from a metric anomaly to a single request runs through exemplars and trace IDs. Traces span only the services that propagate trace context, and one hop that drops the header fragments the trace permanently. Logs join only where the trace ID was injected at write time.

The agent correlates what the platform recorded. It cannot recover context that was never instrumented, and an estate without propagation or exemplars does not become investigable by adding an agent.

Security, and Where the Model Lives.

Operational telemetry is not trusted input. Headers, error messages, trace attributes and event text can carry content an attacker influenced, and that content becomes part of the model's context, the mechanism behind prompt injection, the top-ranked entry in OWASP's Top 10 for Large Language Model Applications across consecutive editions.

So, the controls live in the architecture around the protocol. MCP standardizes how tools are described, invoked and returned; authorization, validation and audit are enforced around it. Tenant isolation is enforced in the query layer rather than asserted in a prompt, and we log what the model was shown, not only the tool it called.

The same architecture supports either deployment model. Where a client's regulations or contracts require inference to stay inside the controlled environment, the models run locally; where policy permits a public service, we use one, and nothing else changes. Local inference is not itself a security control, it governs where content travels, not whether a tool call can carry data out, but how it satisfies a requirement that is often absolute.

Controlled Autonomy

This system automates investigation, not remediation. Its agents hold read access to operational evidence and cannot restart a pod, scale a service, roll back a deploy or modify a workload. That is a boundary we engineered rather than one we ran into: acting on infrastructure is a different risk class from reading it, and the controls that would make it safe — reversible actions, blast radius fixed by the credential, a measured false-lead rate — belong in place before that boundary moves.

What we built is an agent that reasons across real operational signals, drawn from systems that were never designed to be queried together. Which makes the interesting question not how autonomous it could become, but how much authority should be engineered into it, and under what controls.

Modernizing Legacy Apps​

Maecenas mollis sagittis ante, eleifend ultricies sapien. Nam ultricies risus et augue auctor vulputate gravida eget sem. Quisque mollis gravida magna, eu semper eros pharetra in. Sed et elit sit amet odio rutrum consectetur vel vel ante. Praesent vitae elementum lacus. Vivamus efficitur nunc tortor, cursus lobortis purus placerat ut. Maecenas ut aliquet ante, vel finibus lorem. Nulla facilisi. Donec maximus elementum pulvinar.

Impact

Sample article featured image
Pellentesque posuere sem in ipsum venenatis, at bibendum lorem aliquam. Nullam condimentum tempus orci nec commodo. Maecenas malesuada elementum metus, non aliquam est elementum sed. Integer ac finibus ligula, id venenatis lectus. Mauris non eleifend enim. Pellentesque eu congue justo. In ornare dapibus nisi, sit amet feugiat neque. Vivamus mollis, lectus quis gravida viverra, risus ligula congue felis, ut laoreet sem nisi in tortor. Sed vel ligula nulla.
“Quisque mollis purus nec pulvinar rutrum. Duis faucibus sed orci vel pellentesque. Interdum et malesuada fames ac ante ipsum primis in faucibus. Donec non volutpat eros, nec placerat mi. Praesent porta felis ut urna sagittis, sit amet placerat nisl porttitor.”

Nunc tempor molestie velit id dictum. Aenean ac venenatis ipsum, sit amet sodales tortor. Pellentesque habitant morbi tristique senectus et netus et malesuada fames ac turpis egestas. Pellentesque posuere sem in ipsum venenatis, at bibendum lorem aliquam.

Nullam condimentum tempus orci nec commodo. Maecenas malesuada elementum metus, non aliquam est elementum sed. Integer ac finibus ligula, id venenatis lectus. Mauris non eleifend enim. Pellentesque eu congue justo. In ornare dapibus nisi, sit amet feugiat neque. Vivamus mollis, lectus quis gravida viverra, risus ligula congue felis, ut laoreet sem nisi in tortor. Sed vel ligula nulla.

data-acc-source-start

Ensure that Modernizing your Legacy Application is the Right Decision

Our expert consultants work closely with you to understand you organization's business drivers, then conduct an in-depth business goals and that every dollar invested is directed towards the right solution

Depend on a Tailored, Phased Application Modernization Strategy

Our expert consultants work closely with you to understand you organization's business drivers, then conduct an in-depth business goals and that every dollar invested is directed towards the right solution

Streamline the Transition from Old to New

Our expert consultants work closely with you to understand you organization's business drivers, then conduct an in-depth business goals and that every dollar invested is directed towards the right solution

data-acc-source-end

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur elementum, elit a pellentesque placerat, nisl quam blandit orci, at maximus eros nunc nec lacus. Nullam euismod consequat libero, eget suscipit ligula lacinia nec. Nunc finibus dapibus quam, eu convallis magna. Nulla finibus ut risus in sodales. Cras tristique nisi non mattis volutpat. Nullam venenatis varius nisl, dictum ornare lorem dictum rhoncus. Nulla sem nunc, lobortis et massa sed, ultrices convallis justo. Quisque laoreet nibh sit amet arcu rhoncus accumsan. Proin at elementum lacus, at maximus mi. Curabitur vulputate urna mollis lacinia auctor. Donec venenatis finibus magna id tempor. Duis at mattis odio. Aenean eu tempus justo. Donec est arcu, vulputate quis risus et, pharetra imperdiet velit.

Vivamus ut dignissim quam.

No items found.
Author
Ahmed Anwar
Posted on
Sep 17, 2026
Topics
We’re your partner in addressing

real human needs.

Align IT Initiatives with Strategic Business Goals
Plus sign iconMinus sign icon
10X
Increase in transactions
per second