What it does

FrameGuard investigates a render-pipeline incident for a coordinator deciding what to check before restarting work. Given one shot ID and a bounded time window, its hosted Google ADK agent reads Grafana metrics and logs through the official Grafana MCP server and produces six sections: Incident, Correlated evidence, Root-cause hypothesis, Confidence, Recovery proposal, and Human approval required.

It proposes checks; it has no recovery-execution tool. The public React demo uses synthetic fixtures and makes no Gemini or Grafana request. The Google Cloud agent is a separate, authenticated runtime.

Verified hosted result

The preserved request is:

Investigate SH090 from 2026-08-26T05:05:00Z to 2026-08-26T05:15:00Z

The September 1 verification returned one Prometheus series and 13 Loki lines. The unchanged Agent Engine made exactly two tool calls, received both responses, and produced all six sections. It correlated queue depth rising from 12 to 47 at 05:06:00Z with synthetic write failures at 05:05:39Z, 05:08:50Z, and 05:14:00Z. It proposed checking storage and network conditions around render-worker-07. No telemetry or recovery action was written.

The required 59-second video records a different, August 25 window with no useful matching Loki event. Its low-confidence result is not the September 1 result. The trace fixture is available locally but was not loaded into the hosted stack. These checks establish behavior on synthetic incidents, not operational performance at a studio.

Implementation and lessons

Gemini 2.5 Flash runs through Google ADK on Vertex AI Agent Engine. The official grafana/mcp-grafana image is pinned by digest on private Cloud Run. The Agent Engine service identity is its only invoker. Grafana credentials stay in Secret Manager and do not enter model context.

A deterministic controller permits query_prometheus, then query_loki_logs, then a text response. It binds each query to the requested shot and UTC window, limits result sizes, and redacts tool results before giving them to the model as untrusted evidence.

Five recorded failures shaped this implementation: free-choice calling skipped tools; an assumed Tempo tool did not exist on the selected server; long-lived MCP sessions exhausted concurrency; thinking consumed the response budget; and overbroad redaction removed useful log structure. The fixes were an explicit two-tool controller, the advertised server tool set, bounded concurrency, an explicit output budget, and narrower structural-label handling. Each addresses an observed failure rather than adding another prompt instruction.

Inspect and reproduce

Open the hosted demo, inspect a timeline event, and select Inspect evidence. Its Request producer approval action belongs to the synthetic demonstration and does not contact a person.

The README provides locked backend installation, offline tests, and a deterministic fixture command. It separately lists both required service URLs and the authorized Google Cloud identity needed for live invocation. A developer login alone does not grant access to the submitted private MCP service. The public source includes the ADK runtime, Grafana MCP integration, and MIT license.

Built With

Share this project:

Updates

Submission history