Platform Logging
All Zelkor platform components (Aegra, MCP servers, Envoy interceptors, and guardrails) emit structured JSON logs to stdout.
Configuration
Logging is controlled via Helm values and injected as environment variables into the pods.
yaml
logging:
level: INFO
format: jsonZELKOR_LOG_LEVEL: Controls the verbosity. Valid values areDEBUG,INFO,WARNING,ERROR,CRITICAL. The default isINFO.ZELKOR_LOG_FORMAT: Controls the output format. Valid values arejsonandtext. The default isjson.
Note: The
textformat is intended only for local development viaprofiles/values-local.yaml. Production deployments should always usejson.
Security Guarantees
Zelkor enforces strict log hygiene to prevent data leaks:
- Secrets: Tokens, JWTs, API keys, and
Authorizationheaders are never logged atINFOor higher. - Payloads: Prompt bodies and model completions are not logged to stdout. (They are captured as OpenTelemetry traces and sent to Langfuse, which has its own retention and masking rules).
- Health Probes: Liveness and readiness probes are silenced at
INFOlevel to prevent log spam.
Troubleshooting with Logs
If a test or run fails, inspect the component logs for ERROR or WARNING lines. Unexpected ERROR logs indicate a system failure, such as an unreachable database, a failed MCP tool execution, or a crashed sandbox worker.
bash
kubectl logs -n zelkor deploy/zelkor-platform-mcp