Design principle
Kanari is built for production environments where task arguments, queue payloads, and worker names can contain sensitive data. The agent applies privacy transformations before any data leaves your infrastructure. Task arguments are never accessed. The agent reads queue messages only to extract metadata (timestamps, task name, task ID). Payload content is never parsed, stored, or transmitted.What gets collected
Queue metrics
Worker metrics
Task metadata
Sanitization rules
Worker names
Worker hostnames are hashed with SHA-256 (first 8 hex chars) and prefixed withw-:
Task IDs
Task IDs (UUIDs) are hashed with SHA-256 (first 12 hex chars) and prefixed witht-:
Task signatures
Task names are sanitized to remove patterns that commonly contain PII:Queue names
Queue names are also sanitized for emails and UUIDs:Disabling sanitization
If your task names contain no PII (e.g., all names are static identifiers likemyapp.tasks.send_invoice), you can disable sanitization:
Verifying what gets sent
Run in local mode with JSON output to inspect exactly what the agent collects in your environment before connecting to any external service:Data in transit
When usingkanari agent in API mode, data is sent over HTTPS to api.getkanari.com. The agent uses Python’s stdlib urllib (no third-party HTTP library). No data is stored locally between cycles.