← Back to home@LJH-snow

dsh-tool-monitoring

Prometheus and Alertmanager tool plugin for DeepSeek Harness

Stars
0
Language
TypeScript
Created
Aug 28, 2026
Updated
Aug 30, 2026

Introduction

dsh-tool-monitoring

English | 中文

A Cordis tool plugin that gives DeepSeek Harness (dsh) monitoring and alerting capabilities. Agents can query Prometheus, inspect targets, alerts, rules, series, labels, metric metadata, TSDB, build, runtime, configuration and command-line flag status, inspect discovered Alertmanagers, run Loki LogQL queries and inspect log labels, series, index statistics, rule groups, rules, alerts, index volume, detected patterns and detected fields, inspect Grafana health, admin stats, datasources, plugins, dashboards, folders, annotations, alert rules, alert instances, service accounts, teams, org users, org quotas, folder, dashboard and datasource permissions, access control roles, built-in roles, user and team role assignments, user/team permissions, org preferences, current user context, library elements, playlists, current org, dashboard versions and snapshots, contact points and notification policies, and manage Alertmanager alerts, alert groups, silences and receivers.

It follows the official plugin architecture with ctx.tools.register(defineTool(...)) and the adding-a-tool contract.

Install

Install from npm:

npm install @libai168/dsh-tool-monitoring

Or install directly from GitHub:

npm install github:LJH-snow/dsh-tool-monitoring

Requires @deepseek-ai/cordis (^4.0.1) and @deepseek-ai/dsh-tools (^0.1.0-rc.6) as peer dependencies, provided by the host dsh runtime.

Configuration

Load the plugin in a dsh composition config (cordis.yml):

- name: 'github:LJH-snow/dsh-tool-monitoring'
  config:
    prometheusBaseUrl: 'http://prometheus:9090'       # optional, default http://localhost:9090
    prometheusToken: 'plain_token_or_Bearer_token'    # optional
    alertmanagerBaseUrl: 'http://alertmanager:9093'   # optional, default http://localhost:9093
    alertmanagerToken: 'plain_token_or_Bearer_token'  # optional
    lokiBaseUrl: 'http://loki:3100'                   # optional, default http://localhost:3100
    lokiToken: 'plain_token_or_Bearer_token'          # optional
    lokiTenantId: 'tenant-a'                          # optional, multi-tenant Loki only
    grafanaBaseUrl: 'http://grafana:3000'             # optional, default http://localhost:3000
    grafanaToken: 'plain_token_or_Bearer_token'       # optional
    timeoutMs: 15000                                  # optional, default 15000
    allowWrite: false                                 # optional, write tools are disabled by default

Full example: examples/cordis.yml.

Each component can also use HTTP Basic Auth with prometheusUsername/prometheusPassword, alertmanagerUsername/alertmanagerPassword, lokiUsername/lokiPassword, or grafanaUsername/grafanaPassword. Set a base URL to an empty string to disable that component and return an explicit connected: false business value.

Security: write tools are gated by allowWrite. Keep it false unless the dsh runtime is explicitly allowed to delete Prometheus series, create or delete Alertmanager silences, or send alerts.

Tools

Prometheus tools:

ToolDescriptionWrite
prometheus_queryRun a PromQL instant queryno
prometheus_query_rangeEvaluate a PromQL expression over a time rangeno
prometheus_list_targetsList scrape targets with health and last errorno
prometheus_list_alertsList active alerts with labels, annotations, state and valuesno
prometheus_list_rulesList recording and alerting rulesno
prometheus_list_seriesFind series label sets matching a PromQL selectorno
prometheus_list_labelsList label namesno
prometheus_get_label_valuesList values for one labelno
prometheus_get_build_infoGet version, revision, branch, and Go build metadatano
prometheus_get_runtime_infoGet start time, work directory, reload status, and runtime countersno
prometheus_get_flagsGet Prometheus command-line flagsno
prometheus_get_metric_metadataGet metric type, help, and unit metadata, optionally filtered by metric nameno
prometheus_list_alertmanagersList Prometheus-discovered active and dropped Alertmanagersno
prometheus_get_configGet the current Prometheus YAML configuration as a read-only snapshotno
prometheus_get_tsdb_statusRead TSDB cardinality and head block statisticsno
prometheus_delete_seriesDelete series matching PromQL selectorsyes

Loki tools:

ToolDescriptionWrite
loki_queryRun a LogQL instant queryno
loki_query_rangeQuery Loki logs or metric streams over a rangeno
loki_list_labelsList label names, optionally by selector and time rangeno
loki_get_label_valuesList values for one labelno
loki_list_seriesFind streams matching LogQL selectorsno
loki_get_index_statsRead index statistics for streams, chunks, entries and bytesno
loki_get_statusRead Loki build informationno
loki_list_rule_groupsList ruler rule groups for the tenant as YAMLno
loki_list_rulesList alerting and recording rules exposed by Lokino
loki_list_alertsList active Loki alerting rulesno
loki_get_index_volumeGet index volume for labels or seriesno
loki_get_index_volume_rangeGet index volume as a matrix over a rangeno
loki_get_patternsGet patterns detected in Loki logsno
loki_get_detected_fieldsGet fields detected in matching Loki log linesno
loki_get_detected_field_valuesGet observed values for one detected Loki fieldno

Grafana tools:

ToolDescriptionWrite
grafana_get_healthGet health, database status, version and commitno
grafana_list_datasourcesList datasources with safe connection metadatano
grafana_get_datasourceGet one datasource by UIDno
grafana_list_datasource_permissionsList datasource permissions by UID with user, team, built-in role, and actionsno
grafana_search_dashboardsSearch dashboards by query, tag, starred status, limit and pageno
grafana_get_dashboardGet dashboard JSON, metadata and panel count by UIDno
grafana_list_dashboard_permissionsList dashboard permissions by UID with user, team, and built-in role grantsno
grafana_list_foldersList folders with UID, title and URLno
grafana_list_folder_permissionsList folder permissions by UID with user, team, and built-in role grantsno
grafana_list_annotationsList annotations by time, dashboard, panel, type and tagsno
grafana_list_alert_instancesList current Grafana-managed alert instancesno
grafana_list_alert_rulesList Grafana alert rules with folder, group, condition and state settingsno
grafana_get_alert_ruleGet one Grafana alert rule by UID with query data JSONno
grafana_get_access_control_roleGet one Grafana access control role by UID with permissions and scopesno
grafana_list_access_control_rolesList Grafana access control roles, optionally including hidden rolesno
grafana_list_access_control_user_permissionsList effective access control permissions for one Grafana user, optionally filtered by scopeno
grafana_list_access_control_team_permissionsList effective access control permissions for one Grafana team, optionally filtered by scopeno
grafana_list_builtin_rolesList Grafana built-in roles with assigned permissionsno
grafana_get_builtin_roleGet one Grafana built-in role by name with assigned permissionsno
grafana_list_user_rolesList access control roles directly assigned to one userno
grafana_list_contact_pointsList Grafana contact points with safe settings metadatano
grafana_get_notification_policyGet the current Grafana notification policy treeno
grafana_list_teamsSearch Grafana teams by query, exact name, sort and paginationno
grafana_get_teamGet one Grafana team by IDno
grafana_list_team_membersList members for one Grafana teamno
grafana_list_org_usersList Grafana org users with roles and last seen infono
grafana_list_orgsList Grafana organizations with id, name and timestampsno
grafana_get_orgGet one Grafana organization by ID with address and timestampsno
grafana_list_org_users_by_orgList users in one Grafana organization by organization IDno
grafana_get_org_preferencesGet current Grafana organization preferences with theme, home dashboard, timezone, and week startno
grafana_get_current_userGet the current Grafana user profile and admin flagsno
grafana_list_current_user_orgsList Grafana organizations available to the current userno
grafana_list_library_elementsSearch Grafana library panels and variables with name, type, kind, and pagination filtersno
grafana_get_library_elementGet one Grafana library element by UID with model metadatano
grafana_list_playlistsList Grafana playlists with name, interval, items and paginationno
grafana_get_playlistGet one Grafana playlist by UID with items serialized as JSONno
grafana_get_current_orgGet the current Grafana organization id, name and addressno
grafana_list_service_accountsSearch Grafana service accounts by query and pagination, with role, token count, and access control metadatano
grafana_get_service_accountGet one Grafana service account by ID with role, token count, and access control metadatano
grafana_list_service_account_tokensList tokens for one Grafana service account with creation, expiration, and expired stateno
grafana_list_org_quotasList current Grafana organization quotas with target, limit, and used valuesno
grafana_get_admin_statsRead Grafana instance admin stats for users, orgs, dashboards, snapshots, datasources, and active sessionsno
grafana_list_pluginsList installed Grafana plugins with version, enabled state, update availability, and signature stateno
grafana_list_dashboard_versionsList version history for a Grafana dashboard by UIDno
grafana_list_dashboard_snapshotsList Grafana dashboard snapshots with owner, external state, and expirationno
grafana_list_team_rolesList access control roles directly assigned to one team, optionally including hidden rolesno

Alertmanager tools:

ToolDescriptionWrite
alertmanager_get_statusGet version, uptime and status payloadno
alertmanager_list_alertsList alerts with filters and receiverno
alertmanager_list_alert_groupsList alert groups by receiverno
alertmanager_list_silencesList silences with matchers and scheduleno
alertmanager_list_receiversList receiver namesno
alertmanager_create_silenceCreate a silence with JSON matchersyes
alertmanager_delete_silenceDelete a silence by IDyes
alertmanager_send_alertsSend an alert batch as JSONyes

Behavior Contract

  • If a component base URL is not configured, read tools return { connected: false, reason }.
  • Write tools return { ok: false, reason } when allowWrite is disabled or when the monitoring service rejects the request with a validation error.
  • Prometheus and Loki API-level errors plus HTTP 400 write validation errors are mapped to business failure values.
  • Infrastructure errors such as invalid credentials (401), forbidden access (403), rate limiting (429), or server failures (5xx) throw MonitoringError.
  • Every request forwards exec.signal and uses a configurable timeout (default 15 seconds).

Development

npm install
npm run typecheck
npm test
npm run build

See DEVELOPMENT.md for architecture and coverage.

License

MIT