@arch:layer(kg_store) @arch:role(substrate) @arch:see(.yah/docs/architecture/A049-yah-scryer.md)
scryer — per-machine event store with tiered retention.
Tier model (this crate — F1 / scryer-1):
- Recent ring: in-memory ring of last 10k events / 64 MB.
- Short disk: per-machine SQLite at
/var/lib/yah/scryer/events.db. - (Long tier / Parquet is R093-F5, off by default, not in this crate.)
Query surface (F1, TaskRun scope only):
Scryer::events(scope, filter)— query events; delegates to task-runs store for TaskRun scope.Scryer::tail(scope, cursor)— cursor-based live follow.Scryer::subscribe(scope)— push stream for tile viewers and gnomes.
F2 adds:
EventScope::Service(MeshIdent)ingestion via [adapters::ContainerdLogsAdapter] (containerd gRPC log API) and [adapters::WardenRpcAdapter] (yubaba's own structured emissions).- [
beholders::ServiceBeholder] trait + bundledvanilla(rfc5424-ish) andunstructured(passthrough) parsers.
F3 adds:
- [
beholders::PinoBeholder] — Node.js pino NDJSON structured parser. - [
beholders::TracingJsonBeholder] — Rust tracing-subscriber JSON parser. - Image-label opt-in (
yah.beholder=<name>) forcing beholder selection. ServiceBeholder::unknown_format_reason()for schema versioning + decline.- [
quota::ServiceQuotaManager] — per-MeshIdentrate limiting (1000 ev/s default) with Synth drop-count events on window rollover.
F7 adds (P2 narrow):
- [
adapters::JournaldAdapter] — host-level systemd units (sshd, kernel, yubaba's own unit). Entries scoped toService(MeshIdent("<unit>.host")). Explicit allow-list; yah-managed services stay oncontainerd_logs.
F8 adds (P2 tier-2):
- [
ingestion::IngestionServer] — Unix socket ingestion server foryah-logservice-scope events. Yubaba injectsYAH_SERVICE_IDENT+YAH_SCRYER_SOCKETinto workload env; the shim connects and writes JSON-lines withscope_kind = "service"scope envelope.
F5 adds (P3 opt-in):
- [
long_tier::LongTierStore] — per-day Parquet shard rollover from short-disk to R2/MinIO, keyed by(machine_id, day). - [
long_tier::ObjectStore] trait — production wires an S3-compat impl; tests use [long_tier::InMemoryObjectStore]. - [
service::Scryer::aggregate] — cross-boundary rollup: routes events older thanshort_disk_retention_msto the Parquet tier.