RootTrace / Integrations / Kubernetes
Containers & orchestration
Kubernetes monitoring that says which pod and why.
The collector checks the API server, verifies its service account, and walks pod health. Failing pods are reported with namespaces, phases, and reasons, and EKS clusters get the same treatment.
What RootTrace watches
Every reading is checked continuously; bad readings become grouped issues with the evidence attached. RootTrace also remembers whether it has seen the same incident before.
- API reachabilityThe API server checked from inside the cluster or from the host.
- Authentication & service accountToken presence and auth verified, so RBAC drift is an issue, not a mystery.
- Pod healthFailing and pending pods counted, with names, phases, and reasons in the evidence.
- System pod startupkube-system pods checked with a startup grace window.
- Node healthPer-node checks alongside the host metrics of each node running a collector.
Warn and fail thresholds, prefilled
Sensible defaults out of the box, overridable per host with environment variables. No threshold spreadsheet required on day one.
- Failing-pod counts and API reachability drive severity
Setup
# in-cluster: deploy the non-root collector DaemonSet (read-only host mounts) from the dashboard's setup page. # on a node: the host collector picks up kubelet and API context automatically.
Read-only by architecture: no write path, no remediation executor, no inbound ports. Credential-like evidence is redacted before it leaves the host.
One collector, live in minutes
Everything on this page comes from the same read-only collector: one command per host, then point it at your targets.
$ # after adding the signed RootTrace dnf or apt repository:
sudo dnf install roottrace-collector # apt: sudo apt install roottrace-collector
sudoedit /etc/roottrace/collector.env # set ROOTTRACE_COLLECTOR_TOKEN and API URL
sudo roottrace-collector-setup apply
sudo systemctl enable --now roottrace-collector
Questions, answered honestly
Does it replace Prometheus and Grafana?
No. Keep them. RootTrace sits beside your metrics stack and turns cluster signals into grouped issues, similar-incident recall, and postmortem drafts.
Is this safe to run next to production?
The collector is read-only by architecture, not by policy: there is no write path, no remediation executor, and no privileged mode to switch on. It sends short-lived outbound HTTPS requests, opens no inbound ports, and redacts credential-like evidence before anything leaves the host.
Do I need a separate agent for this?
No. One RootTrace collector per host covers every integration on this site: databases, web servers, containers, endpoints, and the Linux host itself, all from one signed package or container. You point it at targets with environment variables; there is nothing else to deploy.
Related integrations
Free on 5 hosts. Live in minutes.
Create a workspace, install one collector, and watch issues explain themselves.
RootTrace