NORMA eResearch @NCI Library

Machine Learning based Ensemble Anomaly Detection in Kubernetes Environments

Korlahalli, Rohit (2025) Machine Learning based Ensemble Anomaly Detection in Kubernetes Environments. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (2MB) | Preview

Abstract

The emergence of containerised workloads and the concept of microservice have changed application deployment but has equally complicated the task of monitoring because of dynamic and distributed nature of Kubernetes environments. The traditional threshold-based monitoring tools are generally not able to give proactive scaleable or interpretable information about system behavior. The presented research is a lightweight ensemble machine learning model that is intended to identify an anomaly in real-time through Kubernetes telemetry. This system is a combination of Isolation Forest, XGBoost, and Long Short-Term Memory (LSTM) models which model distributional, structural and temporal patterns in Prometheus metrics. Such individual predictions are combined by using an ensemble of majority votes to become more robust to a variety of anomalies. The ensemble inference service which is deployed on Google Kubernetes Engine (GKE) with FastAPI handles live metrics and makes its resulting publications again through Pushgateway to Prometheus. Grafana dashboards visualize trends of anomalies and the health of the system, and a natural-language assistant (not compulsory but may be added) can give natural-language explanations and recommendations on how systems should work. Notifications and insights are also sent to Slack to assist with intervening before it is too late. Analysis based on real and synthetic workloads shows that the ensemble is superior to single models with regard to stability and the general reliability of detection, overcoming the most critical limitations revealed in the literature. The results prove that the use of lightweight ML models together with existing observability pipelines could be used to deliver accurate, interpretable, and operationally viable anomaly detection to cloud-native environments.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Heeney, Sean
UNSPECIFIED
Uncontrolled Keywords: Kubernetes; Anomaly Detection; Ensemble Learning; Isolation Forest; XGBoost; LSTM; Prometheus; Grafana; Google Cloud; Cloud Native
Subjects: T Technology > T Technology (General) > Information Technology > Cloud computing
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning
Divisions: School of Computing > Master of Science in Cloud Computing
Depositing User: Ciara O'Brien
Date Deposited: 31 Aug 2026 15:50
Last Modified: 31 Aug 2026 15:50
URI: https://norma.ncirl.ie/id/eprint/9716

Actions (login required)

View Item View Item