Observability & Alerts

The opt-in alert bundle, what each alert means, and the scraping you must configure.

The bundle

A Prometheus alert bundle for the operational silent-failure patterns this system has hit in production ships under config/observability/. It is not part of config/default — the alerts are opt-in so that installs without prometheus-operator CRDs are not affected by an unknown apiVersion.

kubectl apply -k config/observability

This ships four resources in the inference-cache-system namespace:

  • a ServiceMonitor — scrapes inference-cache-server:8080/metrics;
  • a PodMonitor — scrapes the controller pod’s :8080/metrics (required for the controller-side alerts to have a series to evaluate — the controller has no Service in front of it);
  • a second PodMonitor — discovers successfully injected PodLocal LMCache native sidecars across workload namespaces and scrapes lmcache-http:8080/metrics;
  • a PrometheusRule — the alerts.

make verify-prometheus lints and unit-tests the rules.

For vanilla Prometheus (ConfigMap mounts, prometheus.serverFiles), use the flat config/observability/alerting-rules.yaml and configure scraping yourself — for the server, controller pod, and injected PodLocal LMCache sidecars. Scope per install with kubernetes_sd_configs + a relabel_configs that copies __meta_kubernetes_namespace to namespace (the alerts scope per install by that label).

The alerts

AlertSeverityForFires when
IndexEmptycritical2mThe server is up but the index is empty while lookups are flowing — ingestion is broken.
LookupRouteDegeneratewarning5mMore than 90% of lookups return NO_HINT over 10m for a model — no reuse, or a client sending wrong contract keys.
LookupRouteHighTimeoutwarning5mMore than 5% of lookups return TIMEOUT over 10m for a model.
IndexEvictionsSpikeinfo10mMore than 10 cap-evictions/sec (reason="cap"; TTL evictions excluded) — the index is over budget.
ServerProbeFailcritical5mTwo or more functional-probe failures in 5m (controller-emitted — needs the PodMonitor).
LMCacheT2NoHitswarning5mMore than 1000 tier-2 query tokens/sec but zero hit tokens — a silently-degraded offload tier.

Five of these (IndexEmpty, LookupRouteDegenerate, LookupRouteHighTimeout, IndexEvictionsSpike, ServerProbeFail) become active as soon as the operator is installed and the selectors match; they stay quiet on a healthy or idle install (each is gated by traffic/rate/eviction thresholds).

Last modified August 13, 2026: LMCache MP mode (#187) (40a9806)