RootTrace / Integrations / DNS & ping
Endpoints & certificates
The layer under HTTP: resolution and reachability.
When HTTP checks fail, the first question is whether DNS or the network went first. The collector answers it continuously: resolution latency and address counts per hostname, ICMP round-trip per target. The vantage point is your own hosts, not a third-party probe.
What RootTrace watches
Every reading is checked continuously; bad readings become grouped issues with the evidence attached. RootTrace also remembers whether it has seen the same incident before.
- DNS resolution latencyMilliseconds to resolve each hostname, with warn/fail thresholds.
- Resolved addressesAddress count and the addresses themselves. An empty or shrunken answer is evidence.
- ICMP round-tripPing RTT in milliseconds per target, with its own thresholds.
- From your vantage pointChecks run on your hosts, so they see what your services see.
Warn and fail thresholds, prefilled
Sensible defaults out of the box, overridable per host with environment variables. No threshold spreadsheet required on day one.
- DNS warn / fail ms
ROOTTRACE_DNS_WARN_MS - Ping warn / fail ms
ROOTTRACE_PING_WARN_MS
Setup
$ export ROOTTRACE_DNS_TARGETS='app.example.com,db.internal.example' $ export ROOTTRACE_PING_TARGETS='10.0.0.12,gateway.internal.example'
Read-only by architecture: no write path, no remediation executor, no inbound ports. Credential-like evidence is redacted before it leaves the host.
One collector, live in minutes
Everything on this page comes from the same read-only collector: one command per host, then point it at your targets.
$ # after adding the signed RootTrace dnf or apt repository:
sudo dnf install roottrace-collector # apt: sudo apt install roottrace-collector
sudoedit /etc/roottrace/collector.env # set ROOTTRACE_COLLECTOR_TOKEN and API URL
sudo roottrace-collector-setup apply
sudo systemctl enable --now roottrace-collector
Questions, answered honestly
Why not just use an external probe service?
External probes tell you what the internet sees. These checks tell you what your own fleet sees: the resolver your services actually use, the route they actually take. Both have their place; this one explains your incidents.
Is this safe to run next to production?
The collector is read-only by architecture, not by policy: there is no write path, no remediation executor, and no privileged mode to switch on. It sends short-lived outbound HTTPS requests, opens no inbound ports, and redacts credential-like evidence before anything leaves the host.
Do I need a separate agent for this?
No. One RootTrace collector per host covers every integration on this site: databases, web servers, containers, endpoints, and the Linux host itself, all from one signed package or container. You point it at targets with environment variables; there is nothing else to deploy.
Related integrations
Free on 5 hosts. Live in minutes.
Create a workspace, install one collector, and watch issues explain themselves.
RootTrace