Observability
Alien gives you two separate views of a deployment:
deployment state release, rollout, health, last check-in, resources
logs application, system, AI Gateway, Encryption GatewayStart with deployment state. Move to logs when you know which deployment or request path needs inspection.
Check deployment state
# All deployments in the linked project
alien status
# One deployment
alien status acme/production
# Stable output for an agent or script
alien status acme/production --jsonFor a safe resource summary without resource configuration or secrets:
alien deployments resources acme/production --jsonFor machine-based deployments:
alien deployments machines acme/production --jsonSearch application logs
alien logs --deployment acme/production --since 1h
alien logs --deployment acme/production --follow
alien logs --deployment acme/production --level error --jsonalien logs hides Alien system records by default. Add --system when you are debugging the platform components themselves.
Application log bodies remain application log bodies. Alien can detect common structured severity fields without replacing the body with a nested message or msg field. See Structured log severity.
Search gateway diagnostics
Gateway diagnostics are routing and outcome metadata. They do not contain AI prompts, AI responses, encryption plaintext, or ciphertext.
alien logs --source ai-gateway \
--status provider-error \
--since 24h
alien logs --source encryption-gateway \
--operation decrypt \
--status failedSend telemetry to your backend
Deployments send their telemetry to the manager: the Operator collects container logs, and your code's OpenTelemetry logs, traces and metrics go to it as well. A manager you run yourself forwards everything to one OTLP/HTTP endpoint, so it lands next to the rest of your telemetry in Datadog, Grafana, Honeycomb, Axiom, Coralogix, New Relic, or any backend that accepts OTLP. Records carry alien.deployment_id, so you can filter and alert per customer environment.
[telemetry]
otlp-endpoint = "https://api.honeycomb.io"
[telemetry.headers]
x-honeycomb-team = "your-api-key"The manager appends /v1/logs, /v1/traces and /v1/metrics to otlp-endpoint. Use the base URL and authentication headers your backend documents for OTLP/HTTP. Some examples:
| Backend | otlp-endpoint | Headers |
|---|---|---|
| Honeycomb | https://api.honeycomb.io | x-honeycomb-team |
| Axiom | https://api.axiom.co | Authorization = "Bearer <token>", X-Axiom-Dataset |
| Datadog | Your Datadog Agent or OpenTelemetry Collector's OTLP receiver, e.g. http://datadog-agent:4318 | |
| Anything else | An OpenTelemetry Collector that exports to it |
Pointing the manager at an OpenTelemetry Collector also lets you sample, redact, or fan out to several backends.
This works the same for air-gapped sites: the logs arrive when the site's report reaches your manager.
See Configuration for all settings.