Dzone iconDzoneOct 2, 2026 ~1 min source read

Part 3: End-to-End Tracing and Observability Across Goose, agentgateway, and Quarkus

SOC 2 CC7 (system monitoring) requires that Acme can detect and investigate anomalous activity. When an agent-driven workflow touches customer data at 2 AM, "we have logs somewhere" is not an answer an auditor accepts.

Part 3: End-to-End Tracing and Observability Across Goose, agentgateway, and Quarkus

Share this story

Send the public story page.

Useful takeaways from this story.

SOC 2 CC7 (system monitoring) requires that Acme can detect and investigate anomalous activity.

When an agent-driven workflow touches customer data at 2 AM, "we have logs somewhere" is not an answer an auditor accepts.

In Part 2, we secured it with agentgateway's JWT authentication, RBAC, and ExtMCP guardrails.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

SOC 2 CC7 (system monitoring) requires that Acme can detect and investigate anomalous activity. When an agent-driven workflow touches customer data at 2 AM, "we have logs somewhere" is not an answer an auditor accepts. In Part 2, we secured it with agentgateway's JWT authentication, RBAC, and ExtMCP guardrails.

How it works

  • The architecture works — but when something goes wrong in production, you're flying blind.
  • The distributed trace built in this part is the forensic evidence trail: a single trace ID that ties the Goose prompt to every agentgateway policy decision and every Quarkus tool call, so a post-incident...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app