Deploy trace analysis
Deploy the trace analyzer in your infrastructure to analyze agent sessions using your model provider. Session data lives in your PostgreSQL database and trace bucket. The Promptless Dashboard shows findings, remediations, analyzer status, and agent instruction health.
Register your analyzer in the Dashboard, prepare your cloud infrastructure, then bootstrap PIG with Helm. The analyzer and its update controller, the supervisor, follow stable releases automatically. You can pause updates or pin a release.
The 0.3.0 release targets clean installations on AWS/EKS. Azure/AKS and Google Cloud/GKE are experimental and are not covered by the first release’s cloud acceptance.
Choose an installation path
Section titled “Choose an installation path”The cloud guides create dedicated PIG infrastructure in your existing network. They finish with the same Helm installation. Use manual Helm management if your team needs to apply every application upgrade itself.
Before you begin
Section titled “Before you begin”| Requirement | What to prepare |
|---|---|
| Kubernetes | An existing cluster, kubectl, Helm 3 or later, and permission to install the PIG custom resource definition and scoped RBAC. |
| PostgreSQL | A dedicated database, schema-owner credentials, TLS, backups, and private connectivity from the analyzer and migration Jobs. |
| Trace bucket | Private S3, Azure Blob Storage, or Google Cloud Storage with a dedicated prefix and a workload identity that can read and write objects. |
| HTTPS endpoint | A hostname, certificate, and ingress reachable from enrolled hosts. Every proxy must accept encoded uploads of at least 10 MiB. |
| Promptless registration | An organization admin account and an analyzer credential stored in your secret manager. |
| Instruction repositories | GitHub repositories with a readable main branch, selected in PIG Settings and reachable through the connected GitHub App with Contents read access. |
| Model access | A supported Responses API endpoint, model name, authorization, and enough quota for analysis. |
To have a coding agent check these requirements and recommend a path without changing anything, copy this prompt. Set up PIG with a coding agent covers the whole setup.
Check whether we are ready to deploy the PIG trace analyzer, and recommend aninstallation path. Followhttps://promptless.ai/docs/governance/deploy-the-worker/plan-your-deployment.mdand phase 1 of https://promptless.ai/docs/governance/agent-setup-guide.md
Scope: read-only inspection. Do not create, change, or delete anything.Inputs (discover these before you ask me):- Cloud account and region: [for example, AWS account 123456789012, us-west-2]- Kubernetes context: [context name]- Instruction repositories: [GitHub repositories the analyzer should read]- Model provider: [OpenAI, Azure OpenAI, or AWS Bedrock]
Report each "Before you begin" requirement as ready, missing, or unknown,with evidence. Recommend a supported path, say if it is experimental, andlist the steps that need me or another admin.Select infrastructure regions to meet your data residency requirements. The model provider can be in a different cloud; choose it independently from your trace bucket. See model providers for supported endpoints.
Register an analyzer
Section titled “Register an analyzer”Sign in to the Promptless Dashboard as an organization admin and select the organization that will own the analyzer.
- In the PIG sidebar, open Settings → Workers. Under Add analyzer, enter a name such as
production-us-east-2and select Add analyzer. - Copy the credential into your secret manager. It is shown once and cannot be retrieved after you dismiss it, leave the Workers page, or switch organizations.
- Deliver the credential through the Kubernetes Secret referenced by
spec.hosted.installTokenSecretRef. Follow the installation instructions for your cluster.
The installation appears as Awaiting connection until the analyzer checks in. The analyzer uses the credential to discover its installation identity and connects to Promptless’s hosted endpoint by default. You do not need to copy a deployment ID or configure a Runtime URL. Creating an installation does not start workloads in your cluster.
After the analyzer checks in, an organization administrator chooses which repositories it reads in Select instruction repositories. Instruction repositories are selected on the PIG Workers settings page, not configured in Helm.
Keep the credential out of Git and chat. It grants access only to this analyzer installation; prepare your database and model credentials separately. All replicas of this installation use the same credential.
If you lose the credential, choose Rotate credential on the same installation. Rotation immediately revokes the previous credential, so hosted access is interrupted until you update your Secret and the analyzer restarts. The installation, its history, and enrolled hosts keep their identities. You can rotate again if the replacement is lost. Revoke credential disables the credential without deleting the installation or its history.
Use spec.hosted.runtimeURL only when connecting to another Promptless environment, such as a dedicated deployment. The default is https://api.gopromptless.ai. This endpoint is separate from the analyzer’s customer-managed HTTPS hostname.
Assign ownership
Section titled “Assign ownership”| Owner | Maintains |
|---|---|
| Your platform team, using Terraform | Cloud databases and their capacity, trace storage, networking, IAM, encryption keys, backup and retention policies. |
| Your Kubernetes configuration and secret manager | Namespaces, analyzer workload identity, desired PIGDeployment configuration, secret delivery, and certificates. |
| PIG | Analyzer and supervisor application releases, generated workloads, and database schema migrations within the installed permissions. |
Keep the one-time Helm bootstrap outside Terraform’s ongoing reconciliation. After bootstrap, PIG updates its own workloads. A second controller restoring the original chart would undo those updates. GitOps ownership explains the handoff.
A release that needs more infrastructure capacity or access reports a blocked update. Your team reviews and applies the Terraform change; PIG resumes when its live checks and any required release-specific confirmations pass. PIG does not resize cloud databases or change IAM and backup policies.
Plan for production
Section titled “Plan for production”Before expanding beyond a pilot, measure compute and capacity, configure coordinated database and object-storage recovery, and confirm network access.
Finish installation by verifying a complete session. A ready pod or successful health check alone does not verify trace analysis.