v1.4.27
Service Heatmap
Agent Overview now opens with a Service Heatmap that combines available log and
incident evidence into a current per-service view. Services can be searched,
filtered, compared in grid or list layouts, and opened for more detail.
The overview also includes Agent Activity and Learning. Desktop shows all three
sections together, while mobile uses compact icon tabs. Missing, partial, stale,
and restricted data remain clearly identified, and installations without live
evidence receive a labeled sample preview with setup guidance.
Service Health is always enabled. Its collection interval and assessment window
can be changed from Settings without restarting Versus.
When the AI Agent is disabled, Agent pages now show enable-and-restart guidance
instead of endpoint 404 errors. Tool Catalog remains available for inspection
and configuration.
Learned Service Health Intelligence
Licensed Enterprise installations with Intelligence enabled can now enrich the
Service Heatmap with learned metric and trace evidence already collected by
Versus. The heatmap adds Latency P99, Request error rate, Throughput, and
Regression views without issuing additional queries to Prometheus, Tempo,
SigNoz, or CloudWatch.
Opening a service now presents a summary-led investigation panel with current
measurements, regression confidence and contributors, incident context, signal
diagnostics, source freshness, and explicit missing-data states. Desktop users
can expand the panel, while mobile receives a full-screen sheet with keyboard
and screen-reader-compatible tabs and focus handling.
Regression assessment only reports adverse deviations supported by mature,
fresh evidence. Low-confidence assessments, unsupported units, unavailable
signals, and unlicensed data are withheld rather than represented as healthy
zeros. Losing entitlement immediately restores the community response shape,
including restricted metric and trace capabilities.
Chat and Analyze can now use describe_baseline to inspect learned service
expectations for a bounded service, signal, and time window. Community
installations receive log-pattern expectations already learned by Versus;
licensed Enterprise installations can additionally receive authorized persisted
metric and trace expectations. Results identify their source and availability,
retain uncertainty where evidence is incomplete, and never expose raw samples,
queries, endpoints, credentials, or provider payloads.
File Model-State Storage
The file backend now uses bounded indexed paging and descriptor-relative,
no-follow access for model-state artifacts. Existing model-state namespaces
created before this release do not have the required index and fail closed until
their artifacts are rewritten through the normal learning and persistence path.
macOS and Linux support this hardened path; other platforms fail file-provider
startup rather than falling back to unsafe pathname access.
Service Dependencies
Agent Overview now shows configured service dependencies beneath the Service
Heatmap. The strip reuses the same operator-authored graph as
describe_dependencies, labels its source, colors services by current health,
and opens the existing service investigation panel when matching health data is
available. Services without a current health snapshot remain visible with an
explicit unknown state.
Topology loads independently from Service Health. A missing graph displays an
honest not-configured state without sample relationships, and truncated or
partial results report omitted services and relationships. Temporary refresh
failures preserve the last successful graph with a Retry action; authorization
loss immediately removes cached graph content and disables retry and polling.
The topology endpoint is protected by the admin gateway and requires
infrastructure:view. Results are bounded to 500 services and 1,000
relationships and never include raw traces, query selectors, credentials, or
provider errors. Licensed Enterprise installations with an eligible SigNoz trace
source can also add bounded cross-service parent-child relationships. These are
derived only from trace and span identity plus service name, are clearly marked
as trace-derived, and never use operation names, URLs, hosts, peer attributes,
or error text. Tempo trace topology remains unavailable until it can safely
provide a bounded span tree; operator-configured dependencies remain available
in all cases.
SigNoz Read Tools
Chat and Analyze can now inspect configured SigNoz data through six bounded,
read-only tools. OSS includes log field discovery and log record reads. Licensed
Enterprise installations additionally receive metric discovery and series reads,
plus trace field discovery and bounded span reads.
SigNoz source kind, organization, entitlement, and infrastructure:view
permissions are enforced for both catalog availability and direct execution.
Scoped sources expose read operations without leaking source-wide discovery.
Response sizes, rows, fields, series, and datapoints are independently bounded,
and exact configured API keys are removed from tool output and ingested signals
before deduplication or persistence.
SigNoz Reader Migration
SigNoz readers retain HTTP and HTTPS compatibility. Verified HTTPS is
recommended for production; HTTP sends the API key in plaintext and should be
limited to trusted networks. insecure_skip_verify: true is an explicit HTTPS
certificate-verification opt-out and is ignored for HTTP. URL userinfo,
redirects, unsafe destinations, and API keys shorter than eight bytes remain
rejected. Private and loopback destinations still require their explicit
network flags. See src/migration/migration-v1.4.27.md for details.
Data Source Read Tools
Chat and Analyze can now use bounded provider-native reads from configured
sources. OSS adds log discovery and record reads for Loki, Graylog, and Splunk;
Elasticsearch retains index, mapping, shard, and search tools. Enterprise adds
metric discovery and series reads for Prometheus and CloudWatch Metrics, trace
discovery and span reads for Tempo, and scoped CloudWatch Logs discovery and
record reads. SigNoz capabilities remain split by signal type as described
above. File sources remain ingestion-only, with no fabricated field discovery.
Tools appear only when their matching data source and required entitlement are
available. Metric and trace tools now derive exclusively from configured
Enterprise data sources; legacy OSS tools.query_metrics and
tools.query_traces blocks are ignored. Provider reads use source-scoped,
bounded requests rather than changing ingestion cursors or budgets.
What's Changed
- feat(agent): add elasticsearch investigation tools by @hoalongnatsu in #366
- feat(agent): add service health heatmap and overview by @hoalongnatsu in #368
- feat(agent): add scoped signoz tools by @hoalongnatsu in #370
- feat(agent): add service health evidence and assessment seams by @hoalongnatsu in #371
- feat(agent): add service topology to service health by @hoalongnatsu in #372
- feat(ui): improve ux/ui service heatmap by @hoalongnatsu in #373
- feat(agent): add bounded learned baseline investigation by @hoalongnatsu in #374
- feat(agent): add source-backed provider read tools by @hoalongnatsu in #375
- docs(agent): illustrate tool catalog and tempo trace flow by @hoalongnatsu in #376
Full Changelog: v1.4.26...v1.4.27