Skip to main content

GL Observability

gl-observability is a comprehensive SDK for implementing observability in Python applications. It provides easy-to-use wrappers for OpenTelemetry, Sentry, and custom logging handlers with PII redaction capabilities.

Key Features

  • 📊 OpenTelemetry Integration: simplified initialization for tracing.
  • 🛡️ Sentry Support: easy setup for error tracking and performance monitoring.
  • 🕵️ PII Redaction: custom logging handlers to redact PII using Regex or NER (Named Entity Recognition).
  • 🔌 Framework Support: built-in support for FastAPI, Langchain, HTTPX, Requests, OpenAI, Anthropic, Bedrock, and Google Generative AI instrumentation.

Installation

Prerequisites

1. Installation from Pypi

Choose one of the following methods to install the package:

Using pip

pip install gl-observability-binary[all]

Using Poetry

poetry add gl-observability-binary[all]

Using uv

uv add gl-observability-binary[all]

2. Development Installation (Git)

For development purposes, you can install directly from the Git repository:

poetry add "git+ssh://git@github.com/GDP-ADMIN/gl-sdk.git#subdirectory=libs/gl-observability" --extras all

Optional Dependencies

The OTel instrumentor packages for FastAPI, Langchain, HTTPX, Requests, OpenAI, Anthropic, Bedrock, and Google Generative AI are bundled in core. HTTPX, Requests, and all LLM providers (OpenAI, Anthropic, Bedrock, Google Generative AI) are enabled by default — use_httpx and use_requests default to True, and use_llm (which covers all four LLM providers together) defaults to True. Set any flag to False to disable that integration. Langchain and FastAPI follow the same use_* pattern (use_langchain defaults to False; FastAPI runs when fastapi_config is set).

Each instrumentor must run against a compatible version of the library it traces. If you hit a DependencyConflictError at startup, it means your installed library version falls outside the range the bundled instrumentor supports.

The optional extras solve this by pulling in the instrumented library at a version that is known to be compatible with the bundled instrumentor. Use them as a version resolver, not as a feature flag.

Extra Installs
fastapi fastapi at a compatible version
langchain langchain at a compatible version
httpx httpx at a compatible version
requests requests at a compatible version
llm openai, anthropic, boto3, google-generativeai at compatible versions
all All libraries above

Install a specific extra via gl-observability-binary:

# pip
pip install "gl-observability-binary[langchain]"

# Poetry
poetry add "gl-observability-binary[langchain]"

# uv
uv add "gl-observability-binary[langchain]"

Usage

1. Telemetry Initialization

The library uses a unified init_telemetry function that takes a TelemetryConfig object. You can configure it to send traces to OpenTelemetry (OTLP) or Sentry backend. Multiple backend configuration is supported.

OpenTelemetry Configuration

This setup sends traces to an external OTLP collector (e.g., Jaeger, Tempo).

from fastapi import FastAPI
from gl_observability import init_telemetry, TelemetryConfig, OpenTelemetryBackendConfig, FastAPIConfig

# 1. Setup FastAPI Config (optional, if using FastAPI)
app = FastAPI()
fastapi_config = FastAPIConfig(app=app)

# 2. Configure OpenTelemetryBackendConfig
otel_backend_config = OpenTelemetryBackendConfig(
    endpoint="localhost:4318",                  # OTLP endpoint
    use_grpc=False,                             # Use gRPC or HTTP
    headers={"Authorization": "Bearer ..."},    # Optional headers
)

# 3. Configure TelemetryConfig
otel_config = TelemetryConfig(
    attributes={"service.name": "..."},         # Resource attributes
    backend_config=otel_backend_config,         # Backend configuration
    fastapi_config=fastapi_config,              # FastAPI Instrumentation
    use_langchain=True,                         # Enable Langchain instrumentation (default: False)
    # use_httpx, use_requests, and use_llm default to True; set to False to disable.
)

# 4. Initialize Telemetry
init_telemetry(otel_config)

Sentry Configuration

This setup sends errors and traces to Sentry.

from fastapi import FastAPI
from gl_observability import init_telemetry, TelemetryConfig, SentryBackendConfig, FastAPIConfig

# 1. Setup FastAPI Config (optional, if using FastAPI)
app = FastAPI()
fastapi_config = FastAPIConfig(app=app)

# 2. Configure SentryBackendConfig
sentry_backend_config = SentryBackendConfig(
    dsn="https://...",
    environment="...",
    release="...",
    send_default_pii=True,
    disable_sentry_distributed_tracing=False
)

# 3. Configure TelemetryConfig
otel_config = TelemetryConfig(
    attributes={"service.name": "..."},         # Resource attributes
    backend_config=sentry_backend_config,       # Backend configuration
    fastapi_config=fastapi_config,              # FastAPI Instrumentation
    use_langchain=True,                         # Enable Langchain instrumentation (default: False)
    # use_httpx, use_requests, and use_llm default to True; set to False to disable.
)

# 4. Initialize Telemetry
init_telemetry(otel_config)

Multiple Backend Configuration

This setup the OpenTelemetry SDK used for tracing.

from fastapi import FastAPI
from gl_observability import init_telemetry, TelemetryConfig, OpenTelemetryBackendConfig, SentryBackendConfig

jaeger_backend = OpenTelemetryBackendConfig(endpoint="jager...", ...)
init_telemetry(
    TelemetryConfig(
        attributes={"service.name": "..."},
        backend_config=jaeger_backend,
        fastapi_config=fastapi_config,
        use_langchain=True,
        use_httpx=True,
        use_requests=True,
        use_llm=True,
    )
)

langfuse_backend = OpenTelemetryBackendConfig(endpoint="langfuse...", ...)
init_telemetry(
    TelemetryConfig(
        backend_config=langfuse_backend
    )
)

sentry_backend = SentryBackendConfig(dsn="https://...", ...)
init_telemetry(
    TelemetryConfig(
        backend_config=sentry_backend
    )
)

Masking policy and failure reporting

Import the public masking API from gl_observability:

Purpose Public names
Configure scrubbing MaskingConfig, MaskingRule, BuiltInMaskingRule, DenyFields, MaskingMode
Consume failure reports MaskingReport, MaskingFailureGroup, MaskingPatternSource, OnReportHook
Reuse default reporting masking_config_default_on_report
Reuse policy defaults DEFAULT_RULES, DEFAULT_MASKING_CONFIG, EMPTY_DENY_FIELDS
from gl_observability import (
    DEFAULT_RULES,
    EMPTY_DENY_FIELDS,
    BuiltInMaskingRule,
    MaskingConfig,
    MaskingMode,
    MaskingRule,
)

masking_config = MaskingConfig(
    rules=DEFAULT_RULES + (MaskingRule(name="CUSTOM_ID", pattern=r"customer-\d+"),),
    deny_fields=EMPTY_DENY_FIELDS,
    mode=MaskingMode.FAIL_CLOSED,
)
# Select individual built-ins directly; an explicit tuple replaces the defaults.
email_only = MaskingConfig(rules=(BuiltInMaskingRule.EMAIL,))
# Pass masking_config to TelemetryConfig(masking_config=masking_config, ...).

BuiltInMaskingRule.PRIVATE_KEY_BLOCK masks from a recognized BEGIN … PRIVATE KEY header through the first END … PRIVATE KEY delimiter, regardless of label. If no closing delimiter exists, it masks the rest of that string, including any trailing text or serialized JSON punctuation. Text after a complete block is preserved.

Masking is enabled by default. TelemetryConfig(masking_config=None) disables it. A policy with both rules=() and deny_fields.fields=() also skips compilation and installs no masking wrapper or stage: no masking traversal, reports, or FAIL_OPEN warning occurs. Rule-only and deny-only policies remain active, including a deny pattern of "", which matches every attribute key.

OTLP masks span names and span attributes, including string sequences. Sentry masks child-span data, op, and description; root contexts.trace.data, op, and description; root contexts.otel.attributes; the transaction name and its contexts.trace.dynamic_sampling_context.transaction copy; and recursive string leaves in transaction request and user regions. Names, operations, and descriptions use the configured value rules only, without attribute-key denial. SQL and URL text copied into descriptions is masked too. The sampling transaction name is scrubbed before Sentry moves it into the envelope header; other sampling metadata remains unchanged.

Both backends preserve resources. OTLP events, links, status and instrumentation metadata, and Sentry other contexts, tags, extra, breadcrumbs and error events are outside this masking stage. Independent SDK scrubbing and consumer hooks may still change those fields.

Behavior change: Matching text in OTel span names and Sentry operations and transaction names is now redacted; Sentry description masking is retained. For example, both data["db.statement"] and its copied description become SELECT * FROM users WHERE email = '[EMAIL]'. An HTTP description becomes GET api.internal /reset?[GENERIC_CREDENTIAL_KV] when its target contains token=abc123456789. Ordinary operation labels remain unchanged, but matching names/operations may change dashboard grouping. These fields use the same FAIL_CLOSED / FAIL_OPEN behavior as other covered values.

Sentry resources previously masked by this component now pass through unchanged. Applications relying on resource masking can sanitize contexts.otel.resource in a consumer before_send_transaction hook supplied through SentryBackendConfig. The hook runs after this component's masking stage. Regex rules still have false positives and false negatives; this coverage does not guarantee removal of every sensitive value.

Deny fields apply only to attribute keys, before value rules, using Python re.match prefix semantics. Matching is case-sensitive unless flags are supplied: email does not deny user.email, while user\.email$ does. Denied values keep the configured deny mask without value scanning. Request/user keys are never deny-checked.

FAIL_CLOSED replaces a value whose scrubbing raises with [Dropped]. FAIL_OPEN returns that value unmasked and is intended for non-production debugging. Both modes continue scrubbing the other values normally. EMPTY_DENY_FIELDS disables key-based denial; value rules still apply.

on_report receives one MaskingReport per item with masking failures. It defaults to masking_config_default_on_report; a custom hook replaces it, and None disables reporting. Hooks must return promptly. A hook exception is caught and diagnostic logging is attempted; if diagnostic logging raises, that exception may propagate. During context-manager exit, it may replace a traversal exception, which remains in the exception context chain. Nested report delivery on the same thread is skipped while a hook runs; masking still applies and later independent reports can be delivered.

Compiled policies, MaskingSession, MaskingPatternError, DROPPED_VALUE, exporters, and chain/traversal helpers are internal implementation details. The supported masking API consists of the package-root imports listed above; deep imports of implementation details have no compatibility guarantee.

2. Logging Handlers

The library provides logging handlers to automatically redact Personally Identifiable Information (PII) from logs.

Regex-based PII Redaction

Uses regular expressions to mask common PII patterns like KTP, NPWP, Phone Numbers, and Email.

import logging
from gl_observability.logs.regex_pii_logger_handler import init_regex_pii_logging_handler

# Initialize the handler for a specific logger
init_regex_pii_logging_handler(
    logger_name="my_application_logger",
    pii_regex_process_enabled=True
)

logger = logging.getLogger("my_application_logger")
logger.info("User email is john.doe@example.com and phone is 08123456789")
# Output: User email is jo******om and phone is 0812******6789

NER-based PII Redaction (Named Entity Recognition)

Uses an external API to perform Named Entity Recognition for more advanced PII detection and redaction.

import logging
from gl_observability.logs.ner_pii_logger_handler import init_ner_pii_logging_handler

# Initialize the handler
init_ner_pii_logging_handler(
    logger_name="my_application_logger",
    api_url="https://your-ner-api.com/anonymize",
    api_field="text",  # The field name in API response containing the redacted text
    pii_ner_process_enabled=True
)

logger = logging.getLogger("my_application_logger")
logger.info("My KTP is 3525011212941001")
# Output will be redacted based on API response

Metadata

Release files for gl-observability-binary 0.2.8.post1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for gl-observability-binary 0.2.8.post1
File
gl_observability_binary-0.2.8.post1-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
gl_observability_binary-0.2.8.post1-cp313-cp313-manylinux_2_31_x86_64.whl CPython 3.13 CPython 3.13 Linux glibc 2.31+ x86-64 Details
gl_observability_binary-0.2.8.post1-cp313-cp313-macosx_13_0_arm64.whl CPython 3.13 CPython 3.13 macOS 13.0+ ARM64 Details
gl_observability_binary-0.2.8.post1-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
gl_observability_binary-0.2.8.post1-cp312-cp312-manylinux_2_31_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.31+ x86-64 Details
gl_observability_binary-0.2.8.post1-cp312-cp312-macosx_13_0_arm64.whl CPython 3.12 CPython 3.12 macOS 13.0+ ARM64 Details
gl_observability_binary-0.2.8.post1-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
gl_observability_binary-0.2.8.post1-cp311-cp311-manylinux_2_31_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.31+ x86-64 Details
gl_observability_binary-0.2.8.post1-cp311-cp311-macosx_13_0_arm64.whl CPython 3.11 CPython 3.11 macOS 13.0+ ARM64 Details

Total release size: 4.7 MB

Release files / gl_observability_binary-0.2.8.post1-cp313-cp313-win_amd64.whl

Download URL gl_observability_binary-0.2.8.post1-cp313-cp313-win_amd64.whl
Size 418.2 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
5e83617a846fa960d97832a3a1cf98dd93b111d64e40ba5cf1bb098034154585
BLAKE2b-256 checksum
How to use checksums
15047f2496a60dae2fee2255ad7b93f1910089c1a7eecdfedea93281680b1c9d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_observability_binary-0.2.8.post1-cp313-cp313-manylinux_2_31_x86_64.whl

Download URL gl_observability_binary-0.2.8.post1-cp313-cp313-manylinux_2_31_x86_64.whl
Size 712.9 kB
Tags CPython 3.13 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
d97bc3da8055c026f9dc01fa8444f162d525013fb0f5bfc1dea9bbfb7e54d107
BLAKE2b-256 checksum
How to use checksums
9a81da201632ebcefff452673304ad192d12df3ffdc5e0dba4fdd1586af74a6d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gl_observability_binary-0.2.8.post1-cp313-cp313-macosx_13_0_arm64.whl

Download URL gl_observability_binary-0.2.8.post1-cp313-cp313-macosx_13_0_arm64.whl
Size 475.8 kB
Tags CPython 3.13 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
1723d1cbc93254932c92c42df29f8c5a8e5841b00b43ad5acdeab186b2c0ace9
BLAKE2b-256 checksum
How to use checksums
27bf952c9991649c700a0a50bfa7a6c201dcd313c057944e68c3576b7e955676
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_observability_binary-0.2.8.post1-cp312-cp312-win_amd64.whl

Download URL gl_observability_binary-0.2.8.post1-cp312-cp312-win_amd64.whl
Size 418.7 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
89761248fcea3cfb9de0e176042818884b1eaffae75f99e71fc3bbe7dc40e096
BLAKE2b-256 checksum
How to use checksums
dd9a336827ec00fd3307311238f067ece6ec92f11feea896a3e5043eb3fe65a0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_observability_binary-0.2.8.post1-cp312-cp312-manylinux_2_31_x86_64.whl

Download URL gl_observability_binary-0.2.8.post1-cp312-cp312-manylinux_2_31_x86_64.whl
Size 708.7 kB
Tags CPython 3.12 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
a72bb44bdf7da828be4f2a454e05f8166576ada9b71ed108510b673a1d627485
BLAKE2b-256 checksum
How to use checksums
ceaacf51513d665af389be19550b6d73d42b1a94ce05936fb8cf377757e311c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gl_observability_binary-0.2.8.post1-cp312-cp312-macosx_13_0_arm64.whl

Download URL gl_observability_binary-0.2.8.post1-cp312-cp312-macosx_13_0_arm64.whl
Size 462.8 kB
Tags CPython 3.12 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
acd8bfa691395a783c2f507dd8edfb5101d3d5ac58526dc1d3e08c964f87744d
BLAKE2b-256 checksum
How to use checksums
561a757a307fe44db261e2f9449958997a4352af0ba00680c9304ec92ca02874
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_observability_binary-0.2.8.post1-cp311-cp311-win_amd64.whl

Download URL gl_observability_binary-0.2.8.post1-cp311-cp311-win_amd64.whl
Size 435.9 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
d3851493503ff921cd98ea9b43d49b92e54286ff392a25bf16ddcb781fc8eac6
BLAKE2b-256 checksum
How to use checksums
a3c7ed4286902c924bd58523e9cc1cfb3dae9798774883caecde08f8e37fe8e8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_observability_binary-0.2.8.post1-cp311-cp311-manylinux_2_31_x86_64.whl

Download URL gl_observability_binary-0.2.8.post1-cp311-cp311-manylinux_2_31_x86_64.whl
Size 646.6 kB
Tags CPython 3.11 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
6e6312e617c0e2da7d82d6999edf5b1155a894f771df473fbd557b9239a9b16e
BLAKE2b-256 checksum
How to use checksums
f6fe969f40617fa8e0cf298d97a2a5fd3fb3561256ab360dbcf87ca4ef231ea9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gl_observability_binary-0.2.8.post1-cp311-cp311-macosx_13_0_arm64.whl

Download URL gl_observability_binary-0.2.8.post1-cp311-cp311-macosx_13_0_arm64.whl
Size 461.1 kB
Tags CPython 3.11 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
aa9fafc6da47a0ed17b6b98246640c6c9091dfa712763a2d8b8c74f0ccfce286
BLAKE2b-256 checksum
How to use checksums
775291d0645b0e62f46d20c94d3b28bafbc9fabe89f1127f2e9b6369fe61a82b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page