Monitor DigitalOcean.Hear only when it matters.
Know when a Droplet is powered off, archived or destroyed — pair it with an HTTP check for the rest.
What Beaam does with DigitalOcean
Beaam imports Droplets, load balancers, App Platform apps, managed databases, Kubernetes clusters, autoscale pools and certificates. It checks resource state from account snapshots and rotates deeper resource signals within one bounded API budget.
What raises an incident
Curated deliberately: a short list worth your attention, not every metric that exists. Signals that can blip need repeated evidence before Beaam calls them; a reading that is definitive by nature — the provider reporting a failure outright — alerts on the first observation.
| Signal | When Beaam speaks up |
|---|---|
| Droplet not running | Powered off, archived, destroyed, or no longer accessible → broken. Off by default; turn it on per Droplet. |
| Provisioning stuck | Still new after 15 minutes → broken after repeated checks. |
| Filesystem pressure | The fullest matched filesystem is ≥ 90% across repeated samples → degraded. |
| Backup freshness | Configured daily or weekly backups outside their conservative completion window → degraded. |
| High CPU | ≥ 90% over repeated checks → degraded. Off by default to avoid paging on intentional workloads. |
| Managed resource health | Provider errors, missing resources, unhealthy load-balancer backends, node/member deficits, failed scaling, stuck transitions, approaching database version end-of-life and certificate expiry use quiet, type-specific defaults. |
Also collected, but quiet
Charted on the service page and there for context when something does break — but it will not wake you unless you ask it to.
- Droplet state
- Host telemetry availability
- CPU
- Memory
- Load
- Public bandwidth
- Backups
- Load balancers
- App Platform
- Managed databases
- Kubernetes and autoscale
- Certificates
What connecting needs
- Sign in with DigitalOcean:
api:read, the global read-only scope. - Personal access token instead, with read scope; a fine-grained token also needs the
accountread scope. - CPU needs DigitalOcean Monitoring's metrics agent on the Droplet. Database metrics exist for MySQL only.
What Beaam will not tell you
Stated rather than discovered later. Some of these are deliberate — an alert that is not about your system is noise — and some are simply where this integration's view ends.
- DigitalOcean's API reports a Droplet's lifecycle, not whether your app answers. Pair it with an HTTP check.
- Droplet-off, CPU, memory and load alerts are off by default.
- Deeper signals are read in rotation, so a disk crossing 90% alerts within about 20 minutes rather than one.
- DigitalOcean's own Uptime checks are not imported.
- Change correlation does not yet cover databases, Kubernetes, load balancers or certificates.
setup
Designed to stay small
Sign in with DigitalOcean — read-only, no token to create. Beaam imports every Droplet it can see.
Beaam applies sensible defaults. Threshold configuration is optional, not onboarding.
access
Never writes, and revocable
Beaam never writes to DigitalOcean. Credentials are encrypted with AES-256-GCM using a key held as a deploy secret, and are deleted immediately when you disconnect.
Questions
What does Beaam alert on for DigitalOcean?
6 signals can raise an incident: Droplet not running, Provisioning stuck, Filesystem pressure, Backup freshness, High CPU, Managed resource health. Everything else is collected for context but stays quiet until you opt in.
How long does it take to connect DigitalOcean?
Sign in with DigitalOcean — read-only, no token to create. Beaam imports every Droplet it can see. Most connections are watching within a few minutes, and you can send a test alert immediately to prove the path works end to end.
Does Beaam need write access to DigitalOcean?
No. Beaam only ever performs read operations — there is no code path that writes to a connected provider. Worth separating from that: what Beaam *does* and what a token *permits* are different things. Where DigitalOcean offers a read-scoped credential, use it; some providers only issue tokens carrying broader rights than Beaam uses, which is a property of their API rather than of Beaam's behaviour. Scope it as narrowly as the provider allows. Credentials are encrypted with AES-256-GCM before storage and deleted the moment you disconnect.
What does DigitalOcean monitoring cost?
The free plan covers two integrations and five watched services, with email, Slack and webhook alerts. Solo is $19/month flat for unlimited integrations, services and organizations, with collaborators included — there is no per-host, per-check or per-alert metering.
Watching more than DigitalOcean?
Most stacks are several services with seams between them, and the seams are where the damaging failures hide. Beaam correlates across every connected integration, so a database problem reads as one incident rather than five alarms from five tools.
Other integrations
Netlify
Find out a deploy failed before you tell a customer the fix is live.
Neon
Watch project, default-branch, compute, quota, and control-plane health without paging for scale-to-zero.
Resend
Catch a sending domain going unverified before your email quietly stops arriving.
All integrations
Everything Beaam watches today, and what is on the roadmap.