๐ง This project is actively under development. Features may change. Contributions welcome!
Click to expand
The Autonomous AI-powered SRE Agent is a cutting-edge platform that revolutionizes how engineering teams handle CI/CD failures. It monitors your CI/CD pipelines across 5 major providers, automatically detects failures, performs AI-powered root cause analysis, generates safe code fixes, validates them in isolated sandboxes, and creates detailed pull requests โ all autonomously.
|
|
|
Connect your entire pipeline ecosystem
|
Deterministic fix generation for your stack
|
|
Enterprise-grade multi-provider security
|
Never miss a critical event
|
|
Evidence-based failure analysis with full transparency
|
Complete monitoring, metrics, and distributed tracing
|
|
Modern, full-featured web interface
|
Production-grade resilience and safety
|
|
Multi-layered protection against unsafe changes
|
End-to-end SRE loop validation
|
|
Seamless onboarding and repository configuration
|
Quantified fix quality with structured metrics
|
flowchart TB
subgraph Input["๐ฅ Event Sources"]
GH[GitHub Actions]
GL[GitLab CI]
CCI[CircleCI]
JNK[Jenkins]
ADO[Azure DevOps]
end
subgraph Core["โ๏ธ SRE Agent Core"]
WH[Webhook Handler]
NORM[Event Normalizer]
ES[Event Store]
CTX[Context Builder]
RCA[RCA Engine]
ADAPT[Adapter Registry]
end
subgraph AI["๐ง AI Pipeline"]
PLAN[Plan Generator]
CRITIC[Critic Validator]
PATCH[Patch Generator]
POLICY[Policy Engine]
SCAN[Security Scans]
SANDBOX[Sandbox Validator]
end
subgraph Output["๐ค Output"]
PR[PR Creation]
NOTIFY[Notifications]
DASH[Dashboard SSE]
EXPLAIN[Explainability]
end
subgraph Infra["๐ง Infrastructure"]
DB[(PostgreSQL)]
REDIS[(Redis)]
CELERY[Celery Workers]
PROM[Prometheus]
GRAF[Grafana]
TEMPO[Tempo Traces]
end
GH & GL & CCI & JNK & ADO --> WH
WH --> NORM --> ES --> DB
WH --> CELERY
CELERY --> CTX --> RCA --> ADAPT
ADAPT --> PLAN --> CRITIC --> PATCH --> POLICY --> SCAN --> SANDBOX
SANDBOX --> PR
SANDBOX --> NOTIFY
SANDBOX --> DASH
SANDBOX --> EXPLAIN
CELERY <--> REDIS
PROM --> GRAF
TEMPO --> GRAF
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ DETERMINISTIC FIX PIPELINE โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โ
โ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โ
โ โ 1.ADAPTER โโโโถโ 2. PLAN โโโโถโ 3. PLAN โโโโถโ 4.PATCH โ โ
โ โ SELECT โ โ(LLMโJSON)โ โ SAFETY โ โ(Diff Gen)โ โ
โ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โ
โ โ โ โ โ โ
โ โผ โผ โผ โผ โ
โ Language Fix Plan Policy Check Unified Diff โ
โ Detection JSON Only Intent Eval Constrained โ
โ โ
โ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โ
โ โ 5. PATCH โโโโถโ 6. SCAN โโโโถโ 7. TEST โโโโถโ 8. PR โ โ
โ โ SAFETY โ โ(Security)โ โ (Sandbox) โ โ(Creation)โ โ
โ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โ
โ โ โ โ โ โ
โ โผ โผ โผ โผ โ
โ Path/Secret gitleaks Tests Pass? safe / needs-review โ
โ Size Limits trivy/SBOM โโโโโโโโโโโโ Provenance Attached โ
โ Danger Score Secrets Scan If YES โ PR โ
โ If NO โ Alert โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
| โ | Python 3.11+ | Core runtime |
| โ | Docker & Docker Compose | Container orchestration & sandbox |
| โ | Poetry | Python dependency management |
| โ | Node.js 18+ | Frontend development |
| โ | GitHub PAT | API access for webhooks & log fetching |
# Clone the repository
git clone https://github.com/Mrgig7/Autonomous-Al-powered-SRE-Agent.git
cd Autonomous-Al-powered-SRE-Agent
# Configure environment
cp .env.example .env
# Edit .env with your GitHub token and settings
# Start all services (API, Worker, DB, Redis, Prometheus, Grafana, Tempo, OTel)
docker-compose up -d
# Optional: Start with frontend
docker-compose --profile with-frontend up -d
# Optional: Start with local LLM (requires GPU)
docker-compose --profile local-llm up -d
# Check status
docker-compose ps# Clone the repository
git clone https://github.com/Mrgig7/Autonomous-Al-powered-SRE-Agent.git
cd Autonomous-Al-powered-SRE-Agent
# Configure environment
cp .env.example .env
# Start infrastructure
docker-compose up -d postgres redis
# Install Python dependencies
poetry install
# Run database migrations
poetry run alembic upgrade head
# Terminal 1: Start API server
poetry run uvicorn sre_agent.main:app --reload --host 0.0.0.0 --port 8000
# Terminal 2: Start Celery worker
poetry run celery -A sre_agent.celery_app worker --loglevel=info
# Terminal 3: Start frontend
cd frontend && npm ci && npm run dev| Service | URL | Description |
|---|---|---|
| ๐ฅ๏ธ Dashboard | http://localhost:3000 | React frontend with SSE streaming |
| ๐ API Docs | http://localhost:8000/docs | Swagger UI (auto-generated) |
| ๐ Prometheus | http://localhost:9090 | Metrics & alerting |
| ๐ Grafana | http://localhost:3001 | Dashboards & trace explorer (admin/admin) |
| ๐ Tempo | http://localhost:3200 | Distributed trace storage |
| ๐ Metrics | http://localhost:8000/metrics | Raw Prometheus metrics endpoint |
Add the SRE Agent to your workflow for automatic failure analysis:
# .github/workflows/sre-agent.yml
name: SRE Agent Analysis
on:
workflow_run:
workflows: ["CI"]
types: [completed]
jobs:
analyze:
if: ${{ github.event.workflow_run.conclusion == 'failure' }}
runs-on: ubuntu-latest
steps:
- uses: Mrgig7/Autonomous-Al-powered-SRE-Agent@main
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
auto-create-pr: 'true'
notify-slack: 'true'
slack-webhook-url: ${{ secrets.SLACK_WEBHOOK_URL }}| Method | Endpoint | Description |
|---|---|---|
POST |
/webhooks/github |
GitHub Actions webhook receiver |
POST |
/webhooks/gitlab |
GitLab CI webhook receiver |
POST |
/webhooks/circleci |
CircleCI webhook receiver |
POST |
/webhooks/jenkins |
Jenkins webhook receiver |
POST |
/webhooks/azure-devops |
Azure DevOps webhook receiver |
๐ฅ Health Check
GET /healthResponse:
{
"status": "healthy",
"version": "1.0.0",
"database": "connected",
"redis": "connected"
}๐ Get Failure Analysis
GET /api/v1/failures/{failure_id}/analysisReturns root cause, category, confidence score, and evidence lines.
๐งพ Get Explanation (Explainability)
GET /api/v1/failures/{failure_id}/explainReturns evidence-based failure explanation with root cause, log evidence with line indices, danger score breakdown, and policy violations.
๐ Get Provenance Artifact
GET /api/v1/runs/{run_id}/artifactReturns full provenance including plan JSON, policy decisions, scan results (gitleaks, trivy, SBOM), and validation results.
๐ Dashboard Stream (SSE)
GET /api/v1/dashboard/streamServer-Sent Events stream with 13 event types: ingest, context, rca, fix_pipeline, adapter_select, plan, policy_plan, clone, patch, policy_patch, validate, pr_create, pipeline.
| Method | Endpoint | Description |
|---|---|---|
POST |
/api/v1/auth/register |
User registration |
POST |
/api/v1/auth/login |
Email/password login |
POST |
/api/v1/auth/github/login |
GitHub OAuth start/exchange |
POST |
/api/v1/auth/logout |
Session logout |
GET |
/api/v1/users/me |
Get current user profile |
GET |
/api/v1/user/repos |
List GitHub repositories |
POST |
/api/v1/integration/install |
Start GitHub App installation |
POST |
/api/v1/integration/install/confirm |
Confirm GitHub App installation |
๐ Full API documentation: http://localhost:8000/docs
The .env.example file contains 156 configurable options organized into sections:
| Section | Key Variables | Description |
|---|---|---|
| Core | GITHUB_TOKEN, GITHUB_WEBHOOK_SECRET |
GitHub API access & webhook verification |
| Database | DATABASE_URL, REDIS_URL |
PostgreSQL and Redis connections |
| LLM | LLM_PROVIDER, OLLAMA_MODEL, OLLAMA_BASE_URL |
AI model configuration (ollama/mock) |
| Auth | JWT_SECRET_KEY, GITHUB_OAUTH_CLIENT_ID/SECRET |
Authentication & OAuth settings |
| Google OAuth | GOOGLE_OAUTH_CLIENT_ID/SECRET |
Google login integration |
| Sandbox | SANDBOX_DOCKER_IMAGE, ENABLE_SCANS, FAIL_ON_SECRETS |
Sandbox & security scanning |
| Slack | SLACK_ENABLED, SLACK_WEBHOOK_URL, SLACK_BOT_TOKEN |
Slack notification channel |
| Teams | TEAMS_ENABLED, TEAMS_WEBHOOK_URL |
Microsoft Teams notifications |
EMAIL_ENABLED, SMTP_HOST, SENDGRID_API_KEY |
Email notifications (SMTP/SendGrid) | |
| PagerDuty | PAGERDUTY_ENABLED, PAGERDUTY_ROUTING_KEY |
Incident management integration |
| Webhook | WEBHOOK_ENABLED, WEBHOOK_URL, WEBHOOK_AUTH_TYPE |
Generic webhook notifications |
| GitLab | GITLAB_ENABLED, GITLAB_TOKEN |
GitLab CI provider |
| CircleCI | CIRCLECI_ENABLED, CIRCLECI_TOKEN |
CircleCI provider |
| Jenkins | JENKINS_ENABLED, JENKINS_URL, JENKINS_TOKEN |
Jenkins provider |
| Azure DevOps | AZURE_DEVOPS_ENABLED, AZURE_DEVOPS_PAT |
Azure DevOps provider |
| Reliability | MAX_PIPELINE_ATTEMPTS, COOLDOWN_SECONDS |
Retry/backoff/loop protection |
| Phase Flags | PHASE1_ENABLE_DASHBOARD, PHASE1_ENABLE_INSTALL_FLOW |
Feature flag toggles |
# config/safety_policy.yaml
paths:
allowed:
- "src/**"
- "tests/**"
forbidden:
- ".github/workflows/**" # Never edit workflows
secrets:
forbidden_patterns:
- "(?i)api[_-]?key"
- "(?i)password"
patch_limits:
max_files: 10
max_lines_added: 500
max_lines_removed: 200
danger:
safe_max: 25 # Score < 25 = "safe" labelAdd .sre-agent.yaml to your repository root:
automation_mode: suggest # suggest | auto_pr | auto_merge
protected_paths:
- infra/**
- payments/**
retry_limit: 3# Run all tests
poetry run pytest
# Run with coverage
poetry run pytest --cov=src/sre_agent --cov-report=html
# Run specific tests
poetry run pytest tests/test_api.py -v# Run 35-case evaluation with mock LLM
python -m evals.run --limit 35 --model mock --out evals/results/run_local| Model | Cases | Fix Success | Safe Fix Rate | Avg Danger | Avg MTTR |
|---|---|---|---|---|---|
| mock | 35 | 71.4% | 71.4% | 13.0 | 0.00s |
Validates the full end-to-end SRE loop: push failure โ CI fails โ webhook โ pipeline โ fix โ PR.
cd test-harness
make setup # Install dependencies
python run_harness.py --failures all # Run all failure scenarios
python run_harness.py --failures 1,4,7 # Run specific scenarios
python run_harness.py --failures all --cleanup # Run + cleanup GitHub repoReports generated at:
- Per-case:
test-harness/reports/validator-failure-XX.json - Aggregate:
test-harness/reports/harness-report.json
๐ฆ Autonomous-AI-powered-SRE-Agent
โโโ ๐ action.yml # GitHub Action marketplace definition
โโโ ๐ docker-compose.yml # 10-service container orchestration
โโโ ๐ Dockerfile # API/Worker container build
โโโ ๐ pyproject.toml # Python dependencies (Poetry)
โ
โโโ ๐ src/sre_agent/ # Main application package (23 sub-packages)
โ โโโ ๐ adapters/ # Multi-language: Python, Node, Go, Java, Docker
โ โโโ ๐ ai/ # LLM integration (plan generation, embeddings, critic)
โ โโโ ๐ api/ # FastAPI routes (14 route modules)
โ โ โโโ ๐ webhooks/ # GitHub, GitLab, CircleCI, Jenkins, Azure DevOps
โ โโโ ๐ auth/ # JWT, OAuth, RBAC, session management
โ โโโ ๐ core/ # Logging, Redis service
โ โโโ ๐ explainability/ # Evidence-based failure explanations
โ โโโ ๐ fix_pipeline/ # 8-step deterministic fix orchestrator
โ โโโ ๐ intelligence/ # RCA engine, failure pattern matching
โ โโโ ๐ knowledge/ # Knowledge base & FAISS embeddings
โ โโโ ๐ middleware/ # Request processing middleware
โ โโโ ๐ models/ # SQLAlchemy database models
โ โโโ ๐ notifications/ # Slack, Teams, Email, PagerDuty, Webhook
โ โโโ ๐ observability/ # Prometheus metrics, OTel tracing, middleware
โ โโโ ๐ ops/ # Operational reliability (rate limit, concurrency)
โ โโโ ๐ pr/ # Pull request creation & management
โ โโโ ๐ providers/ # CI/CD provider abstractions
โ โโโ ๐ safety/ # Policy engine, danger scoring, diff parsing
โ โโโ ๐ sandbox/ # Docker sandbox, test runner, scanners
โ โ โโโ ๐ scanners/ # gitleaks, trivy, syft integrations
โ โโโ ๐ schemas/ # Pydantic models (14 schema modules)
โ โโโ ๐ services/ # Business logic (18 service modules)
โ โโโ ๐ tasks/ # Celery async tasks (dispatch, context, fix)
โ
โโโ ๐ frontend/ # React 18 + TypeScript + Vite
โ โโโ ๐ src/
โ โโโ ๐ pages/ # Landing, Login, OAuthCallback, Dashboard, FailureDetails
โ โโโ ๐ components/ # DiffViewer, JsonViewer, SeverityBadge, Timeline
โ โโโ ๐ api/ # API client
โ โโโ ๐ styles/ # CSS styles
โ
โโโ ๐ test-harness/ # Real-time end-to-end test system
โ โโโ ๐ sample-app/ # Failure-prone test application
โ โโโ ๐ testing-agent/ # API-driven subsystem validators
โ โโโ ๐ reports/ # Generated JSON test reports
โ
โโโ ๐ observability/ # Infrastructure configurations
โ โโโ ๐ grafana/ # Dashboard provisioning & JSON dashboards
โ โโโ ๐ prometheus/ # Scrape config & alert rules
โ โโโ ๐ otel-collector/ # OpenTelemetry Collector config
โ โโโ ๐ tempo/ # Tempo trace storage config
โ
โโโ ๐ evals/ # Offline evaluation harness (35 test cases)
โโโ ๐ tests/ # Unit & integration test suite
โโโ ๐ alembic/ # Database migration scripts
โโโ ๐ config/ # Safety policy YAML
โโโ ๐ docs/ # Documentation
โ โโโ ๐ pipeline.md # Pipeline flow documentation
โ โโโ ๐ ops.md # Reliability & operations guide
โ โโโ ๐ observability.md # Monitoring & tracing setup
โ โโโ ๐ phase1_onboarding.md # OAuth & onboarding runbook
โ โโโ ๐ phase2_repo_integration.md # Repository integration guide
โ โโโ ๐ PUBLISHING.md # Publishing guidelines
โโโ ๐ .github/ # CI/CD workflows
- ๐๏ธ Project foundation & architecture
- ๐ก Event ingestion API (5 CI/CD providers)
- ๐ง AI fix generation engine with critic validation
- ๐๏ธ Sandbox validation engine with supply-chain scanning
- ๐ PR creation service with danger scoring & labels
- ๐ React 18 Dashboard with landing page & SSE streaming
- ๐ JWT + GitHub OAuth + Google OAuth + RBAC
- ๐ 5-Channel Notification System (Slack, Teams, Email, PagerDuty, Webhook)
- ๐ Dashboard API, analytics & real-time SSE (13 event types)
- ๐ Comprehensive audit logging system
- ๐งพ Explainability + Trust Dashboard with evidence & provenance
- ๐ Full Observability Stack (Prometheus, Grafana, OTel, Tempo)
- ๐ Multi-Language Adapters (Python, Node, Go, Java, Docker)
- ๐ Security Scans (gitleaks, trivy, syft SBOM)
- โก Pipeline reliability (idempotent ingestion, concurrency locks, retry/backoff, loop protection)
- ๐ GitHub App integration &
.sre-agent.yamlrepo config - ๐งช Real-time test harness with testing agent
- ๐ Offline evaluation harness (35 cases)
- ๐ฎ GitHub Action marketplace support (
action.yml) - ๐ Post-merge monitoring & re-validation
- ๐ Production website with full onboarding flow
- ๐ Advanced analytics & reporting dashboards
- ๐ Enhanced security features (token encryption, HMAC-signed artifacts)
- ๐ฑ Mobile-responsive PWA
- ๐ค AI model fine-tuning on proprietary failure data
- ๐ Multi-region deployment support
- ๐ Custom dashboard widgets
- ๐ Slack/Teams interactive approval workflows
- ๐ Live LLM provider switching (OpenAI, Anthropic, Gemini)
We welcome contributions! Here's how to get started:
# 1. Fork the repository
# 2. Create your feature branch
git checkout -b feature/AmazingFeature
# 3. Commit your changes
git commit -m 'Add some AmazingFeature'
# 4. Push to the branch
git push origin feature/AmazingFeature
# 5. Open a Pull Request- โ Follow PEP 8 for Python (enforced by Ruff)
- โ Use TypeScript strict mode for frontend
- โ Add tests for new features
- โ Update documentation
- โ All PRs must pass safety policy checks
This project is licensed under the MIT License - see the LICENSE file for details.
Built with โค๏ธ for SRE teams everywhere
๐ Report Bug โข ๐ก Request Feature โข โญ Star the Repo