Performance Characteristics
Latency Breakdown
Total overhead (excluding tool calls): ~10-25ms for typical scripts.
Worker Pool Mode
When using Worker Pool adapter for OS-level isolation, latency changes slightly:
Worker Pool adds ~2-3ms latency per execution due to message passing overhead, but provides OS-level isolation and hard halt capability.
Throughput
Throughput depends heavily on script complexity and tool call latency. These numbers assume simple scripts with 1-3 tool calls.
Worker Pool Scaling Guidelines
Performance Optimization
1. Use TF-IDF for Most Cases
Unless you have 100+ tools with similar descriptions, TF-IDF provides excellent relevance with minimal overhead:2. Enable HNSW for Large Toolsets
For 1000+ tools with embedding strategy, enable HNSW indexing:3. Warm the Search Index on Startup
Pre-index tools during server initialization:4. Use Direct Invoke for Simple Calls
Bypass VM overhead for single-tool operations:5. Cache Describe Results
Tool schemas rarely change. Enable caching:Multi-Instance Deployment
CodeCall is stateless and scales horizontally.Architecture
Shared Cache (Redis)
For consistent search results across instances:Kubernetes Deployment
Resource Recommendations
Monitoring
Metrics to Track
Execution Latency
Track p50, p95, p99 of
codecall:execute durationError Rate
Monitor validation errors, timeouts, and tool failures
Tool Call Count
Average tool calls per script execution
Search Latency
Track search response times for index health
Logging
CodeCall emits structured logs for observability:Health Checks
Expose CodeCall health via your health endpoint:Alerting Recommendations
Cost Optimization
Token Savings
CodeCall dramatically reduces token usage:Compute Costs
Cost vs. Performance Tradeoffs
Minimize Latency
Minimize Latency
- Use TF-IDF search
- Enable caching for describe/search
- Use direct invoke for simple calls
- Increase VM timeout for complex scripts
Minimize Compute
Minimize Compute
- Use locked_down preset (shorter timeouts)
- Limit maxToolCalls aggressively
- Cache aggressively
- Use fewer instances with more resources
Minimize Tokens
Minimize Tokens
- Use codecall_only mode
- Hide all tools from list_tools
- Return minimal data from tools
- Let scripts filter server-side
Security in Production
Checklist
1
Use secure or locked_down preset
Never use
experimental in production.2
Enable audit logging
Log all script executions and security events.
3
Configure rate limiting
Prevent abuse via aggressive rate limits.
4
Monitor security events
Alert on validation failures and self-reference attempts.
5
Regular security reviews
Review tool allowlists and filter rules quarterly.
Rate Limiting
Audit Logging
CodeCall provides comprehensive audit logging for compliance and security monitoring.What Gets Logged
Enabling Audit Logging
Audit Event Schema
Integration Examples
Datadog
Datadog
AWS CloudWatch
AWS CloudWatch
Database
Database
Multi-Tenancy Patterns
CodeCall supports multiple isolation strategies for multi-tenant deployments.Tenant Context
Pass tenant information viacodecallContext:
Per-Tenant Tool Filtering
Restrict tools based on tenant:Per-Tenant Configuration
Different security levels per tenant:Isolation Strategies
Per-Tenant Resource Quotas
Audit Trail Separation
Separate audit logs by tenant:Troubleshooting
Common Issues
Scripts timing out
Scripts timing out
Symptoms: Frequent
TIMEOUT errorsCauses:- Script too complex
- Tool calls too slow
- Timeout too aggressive
- Profile tool call latency
- Increase
vm.timeoutMsif tools are slow - Break complex scripts into smaller pieces
- Use
Promise.all()for independent tool calls
Search returning irrelevant results
Search returning irrelevant results
Symptoms: Low relevance scores, wrong tools returnedCauses:
- Poor tool descriptions
- Threshold too low
- TF-IDF limitations
- Improve tool descriptions
- Increase
similarityThreshold - Switch to embedding strategy for semantic matching
- Add more specific keywords to descriptions
High memory usage
High memory usage
Symptoms: OOM errors, pod restartsCauses:
- Embedding model loaded
- Large tool index
- Scripts returning large data
- Use TF-IDF instead of embeddings
- Increase memory limits
- Configure output sanitization limits
- Enable HNSW for large indexes
Validation errors for valid code
Validation errors for valid code
Symptoms: Scripts rejected that should workCauses:
- Using blocked constructs
- Reserved prefix collision
- Unicode issues
- Check for
eval,Function, etc. - Avoid
__ag_and__safe_prefixes - Use ASCII identifiers
- Review AST Guard rules
Migration & Rollback
Gradual Rollout
-
Phase 1: Deploy with
mode: 'metadata_driven'- All tools visible normally
- Mark select tools for CodeCall
- Monitor for issues
-
Phase 2: Switch to
mode: 'codecall_opt_in'- Tools opt into CodeCall
- Both access methods work
- Measure token savings
-
Phase 3: Move to
mode: 'codecall_only'- Hide tools from list_tools
- Full CodeCall experience
- Maximum token savings
Rollback Plan
Related
Configuration
All configuration options
Security Model
Security architecture and settings
VectoriaDB
Embedding and search internals
Deployment Guide
General FrontMCP production deployment