Repository navigation
feat(lens): analyze agent activity with a separate worker - #43889
Merged
Merged
Conversation
moe-berri
requested a deployment
to
e2e-changed
September 30, 2026 18:37 — with
GitHub Actions
Waiting
yujonglee-berri
force-pushed
the
litellm_trace_spend_enrichment
branch
from
September 30, 2026 18:37
8d323d9 to
5e4f8be
Compare
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
devin-ai-integration
Bot
force-pushed
the
litellm_trace_spend_enrichment
branch
from
September 30, 2026 19:03
55edb12 to
0841d91
Compare
moe-berri
force-pushed
the
litellm_agent_engine
branch
from
September 30, 2026 19:20
d598c85 to
1d371ca
Compare
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 19:20 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 19:24 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 19:26 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 19:40 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 19:43 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 19:48 — with
GitHub Actions
Error
yujonglee-berri
added this pull request to stack #43912
September 30, 2026 19:49
moe-berri
force-pushed
the
litellm_agent_engine
branch
from
September 30, 2026 21:23
f330e45 to
641f037
Compare
moe-berri
removed this pull request from stack #43912
September 30, 2026 21:25
moe-berri
changed the base branch from
litellm_trace_spend_enrichment
to
main
September 30, 2026 21:25
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 21:25 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 21:38 — with
GitHub Actions
Error
Contributor
Author
|
@greptileai please review this PR for correctness and merge readiness. |
Contributor
Author
|
@veria-ai please review this PR for correctness and merge readiness. |
Contributor
Author
|
bugbot run |
Contributor
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
Contributor
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 21:50 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 21:56 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 21:58 — with
GitHub Actions
Error
Contributor
Author
Contributor
Author
|
@veria-ai |
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 22:01 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 22:05 — with
GitHub Actions
Error
Contributor
Author
|
bugbot run |
Contributor
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
moe-berri
marked this pull request as ready for review
September 30, 2026 22:07
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 22:11 — with
GitHub Actions
Error
moe-berri
had a problem deploying
to
e2e-changed
September 30, 2026 22:13 — with
GitHub Actions
Error
moe-berri
enabled auto-merge (squash)
September 30, 2026 22:15
moe-berri
disabled auto-merge
September 30, 2026 22:23
tin-berri
approved these changes
Sep 30, 2026
yujonglee-berri
approved these changes
Sep 30, 2026
moe-berri
enabled auto-merge (squash)
September 30, 2026 22:29
moe-berri
requested a deployment
to
e2e-changed
September 30, 2026 22:31 — with
GitHub Actions
Waiting
8 of 9 tasks
2 of 5 tasks
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TLDR
Problem this solves:
How it solves it:
Targets main directly. The trace-ingestion foundation is merged; this PR does not depend on #43865 or #43864
Intentional product change: adds Lens Beta under Observability for proxy admins and admin viewers. Setup previews recorded runs and defaults to a single scan. Issues and patterns have separate views; original evidence is expandable. Admins control setup and spending; existing Logs and trace inspection remain available
User Flow
Before: an admin can inspect recorded activity but cannot run Lens analysis
http://127.0.0.1:18443/ui/lens/with recorded release-review tracesAfter: the admin configures a lens and reviews findings with source evidence
http://127.0.0.1:18443/ui/lens/with recorded release-review tracesImplementation
The worker runs on the proxy host or another server and only needs outbound access to LiteLLM. It has a revocable Lens credential, no provider keys or database credentials. The proxy handles scoped storage reads and model calls
Each scan samples matching executions, screens content in chunks, consolidates observations across batches, then investigates up to ten patterns with a bounded read-only model loop. Both worker and proxy validate exact evidence quotes. Model responses include schema limits and get one repair attempt if validation fails. Findings can be resolved or dismissed, and new supporting executions can reopen resolved findings
PostgreSQL stores lenses, jobs, worker credentials, and findings. ClickHouse reads use scoped queries in the shared Rust storage layer. Jobs have leases and bounded retries; each model call reserves budget before inference. Setup and limits are in deploy/lens/README.md
Pre-Submission checklist
Validation
Local
make checkpasses, including Python lint, type budgets, dashboard lint, test quality and generated API types. All 60 focused Python tests pass. All 19 Lens UI tests pass, including duration-unit and analyzer setup regressions. A real ClickHouse test confirms caller-tagged requests remain eligible while server-marked analysis calls are excludedGreptile’s Linux connectivity, duration conversion and later-page evidence findings are fixed. Veria’s caller-tag exclusion bypass is fixed using server-owned context that overwrites caller metadata. The UI selects a published worker image containing the evidence fix
A fresh paid scan reviewed the known Release-19 error, completed for $0.081326 and produced a finding with four evidence quotes. Greptile’s repeat review scored 5/5 and Veria reports no open security findings. Required Python CI and coverage remain pending. GitHub frontend lint and Dashboard build pass. The documentation check fails on the same three ClickHouse environment variables as main, so that failure is pre-existing. Bugbot could not run because the team’s spending limit was reached
Setup
Open Lens and choose Set up analysis. The URL is your existing LiteLLM deployment. Generate and copy the Docker command, then run it on a machine with Docker. The analyzer polls LiteLLM for manually started or scheduled scans. It needs no public URL, incoming port, provider keys or database credentials
Earlier end-to-end evidence, current-tip verification pending
Shared setup: PostgreSQL, ClickHouse, separate Docker workers, and real paid inference. A controlled three-agent workflow used researcher, verifier, and lead roles across 21 release-review runs, with clean inputs, injected timeouts, conflicting evidence, prompt-injection notes, long content, redacted outputs, and dropped handoffs. The agents made 188 successful model calls and stored 440 spans. Tool faults were deliberately injected; model outputs were not mocked
Before (0841d91)
http://127.0.0.1:18443/ui/lens/with the same recorded activityAfter (f330e45)
lens-live-swarm, and metadataswarmisrelease-review. The preview shows 21 named runs with timestamps and links to their original traceslens-real, a budget, and a sample limit. New lenses run once unless background monitoring is enabledType
New Feature
Caveats
Medium
Low
Final Attestation
Latest integration validation
Merged main through 52b9fa2 and reconciled named trace reads with Lens queries. Lens preview metadata excludes the authentication attribute server-side, with a regression test for opaque tokens
Added a real Postgres scan lifecycle test covering creation, worker authentication, claiming, progress, budget settlement, completion, reruns, cancellation and credential revocation. The existing Postgres CI job now uploads this coverage. The Rust extension builds locally; current-commit CI and updated combined Codecov coverage are pending
The batch-metadata and interactions OpenAPI failures also occur on main's unit test run. Documentation and code quality both fail on main's undocumented ClickHouse environment variables. These unrelated baseline failures are unchanged