AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Principle Observability

skill-lugassawan-swe-workbench-principle-observability · by lugassawan

Observability principles — logs vs metrics vs traces, structured logging, distributed tracing, span/trace context, cardinality control, OpenTelemetry, SLI/SLO/SLA, RED method, USE method, alerting on symptoms vs causes. Auto-load when adding logging, choosing a metric, instrumenting distributed tracing, debating cardinality, defining SLIs/SLOs, designing alerts, or discussing observability budget…

No reviews yet
0 installs
48 views
0.0% view→install

Install

$ agentstack add skill-lugassawan-swe-workbench-principle-observability

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-lugassawan-swe-workbench-principle-observability)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Principle Observability? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Observability

Three signals, each with a distinct job. Use the right one for the right question.

The Three Pillars

Logs — discrete events with context. Right for: debugging specific incidents, audit trails, free-text search.

  • Emit at decision points and error boundaries, not in loops.
  • Use structured key-value format; never interpolate variables into free-form strings.
  • Include a correlation ID on every line — trace parent ID if a trace exists.

Metrics — numeric aggregations over time. Right for: dashboards, SLOs, alerting thresholds.

  • Pre-aggregate; do not stream raw events into a metrics backend.
  • Label only stable, low-cardinality dimensions (region, status_code, service) — never user ID, request ID, or email.

Traces — causal chain of operations across services. Right for: latency attribution, dependency mapping.

  • A span represents one unit of work; parent/child links form the trace.
  • Propagate context headers at every service boundary — OpenTelemetry W3C trace context.
  • Put high-cardinality attributes (user ID, document ID) in span attributes, not metric labels.

Structured Logging

Emit events as key-value pairs. The log processor should never parse a free-form string.

  • Correlation ID ties log lines to a trace and to a business operation.
  • Log level discipline: DEBUG (local dev), INFO (normal flow), WARN (recoverable anomaly), ERROR (action required).
  • No log.debug("entering function X") in hot paths — cost without signal.

Cardinality

High-cardinality labels explode time-series count and kill metrics backends.

  • Safe: status_code, method, region, environment — bounded sets.
  • Unsafe: user_id, request_id, session_token — unbounded.
  • Move high-cardinality context to span attributes or structured log fields.
  • Rule of thumb: if a label's value count exceeds 1 000, it does not belong in a metric.

SLI / SLO / Error Budget

Define SLIs around user-visible behavior, not internal mechanics.

  • SLI — the measurement: request success rate, p99 latency, data freshness.
  • SLO — the target: 99.9% success rate over a rolling 28-day window.
  • Error budget — 1 − SLO; spend it on risk, protect it by slowing releases.
  • Track error budgets as a team policy, not as an on-call metric.
  • Never use CPU utilization or memory as SLIs — users do not feel CPU.

RED Method (request-driven services)

Three questions for every service:

  • Rate — how many requests per second?
  • Errors — what fraction are failing?
  • Duration — how long are they taking? (histogram, not average)

USE Method (resource-driven services)

Three questions per resource (CPU, memory, disk, network):

  • Utilization — how busy is the resource?
  • Saturation — how much demand is queued?
  • Errors — is the resource reporting errors?

Alert on Symptoms, Not Causes

Page humans for user-visible pain. Let dashboards explain why.

  • Page-worthy: error rate exceeds SLO budget burn rate; p99 latency exceeds user threshold.
  • Not page-worthy: CPU > 80%, heap > 70% — correlate these in post-mortems.
  • Symptom alerts reduce alert fatigue; cause alerts create it.

When Observability is Overkill

  • Internal scripts, batch jobs, one-off migrations — structured logs suffice.
  • Single-process services owned by one developer — standard library logging, no tracing.
  • Prototypes: instrument later; premature instrumentation shapes API decisions before the design is stable.

Red Flags

| Flag | Problem | |------|---------| | Alerts fire on CPU or memory thresholds | Cause alert — pages without confirmed user impact | | log.debug("value: " + obj.toString()) | String interpolation breaks log parsing; expensive in hot paths | | Metric labels include user ID or request ID | High-cardinality explosion; will saturate the metrics backend | | Dashboard added for every new feature | Dashboards-as-product; nobody reads them; builds false confidence | | On-call only reacts when paged | No error-budget tracking; SLO erosion invisible until breach |

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.