Operate OCI Monitoring, Logging, APM, OpenTelemetry, Notifications, Service Connector Hub, service/custom logs, metrics, alarms, dashboards, agent traces, and Grafana integrations. Use for telemetry collection, queries, alerting, trace integrity, logging pipelines, or observability inventory. Route Database Management, Operations Insights, Performance Hub, AWR/ADDM/ASH, and DBSNMP to oci-dbm-opsi; route Autonomous Database lifecycle to oci-autonomous-db.
OCI Observability
Preflight the named context, query current telemetry configuration, and search the KB before changing an alarm, log, connector, or APM resource. Run every CLI through oci_cli, every mutation through risk-classified run_action, and every shared output through redaction.
list current → verify metric namespace/query → ensure destination is active → additive action → re-list/test notification
Missing traces
list APM domains → resolve correct domain/key without printing it → verify private OTLP endpoint → send test → re-query
Service logs
list groups/logs → write source config to 0600 file → additive action → verify ingestion and retention
Gate agent traces
query integrity score/state → identify missing spans/attributes → keep prompt capture off → re-score before promotion
Safety
Never expose datakeys, domain IDs, endpoints, OCIDs, IPs, or tenant namespaces.
Store nested configuration in 0600file:// payloads, not argv.
Treat empty results as inconclusive until region, subtree, time window, and permissions are checked.
Re-list after a 409 rather than retrying a create.
Expected output
Report finding, redacted evidence, exact risk-classified action or read, verification, and KB reference. For database telemetry work, state the handoff owner rather than performing DBM/OPSI here.