Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

ย 

History

16 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

Typing SVG

Typing SVG

Status License Last Commit

Python FastAPI React TypeScript

Celery PostgreSQL Redis Docker


๐Ÿšง This project is actively under development. Features may change. Contributions welcome!




๐Ÿ“‹ Table of Contents

Click to expand



๐ŸŒŸ Overview

No more 3 AM debugging sessions. Let the AI agent fix your builds while you sleep.


The Autonomous AI-powered SRE Agent is a cutting-edge platform that revolutionizes how engineering teams handle CI/CD failures. It monitors your CI/CD pipelines across 5 major providers, automatically detects failures, performs AI-powered root cause analysis, generates safe code fixes, validates them in isolated sandboxes, and creates detailed pull requests โ€” all autonomously.

๐ŸŽฏ The Problem

  • โฐ Hours spent debugging CI/CD failures
  • ๐Ÿ”„ Repetitive manual fixes for similar issues
  • ๐Ÿ˜ด Late-night on-call pages
  • ๐Ÿ“‰ Developer productivity drain
  • ๐Ÿ” Root cause analysis is time-consuming

โœ… Our Solution

  • ๐Ÿ” Detects failures in real-time via webhooks from 5 CI providers
  • ๐Ÿง  Diagnoses root causes with AI-powered semantic log analysis
  • ๐Ÿ”ง Generates safe, context-aware fixes for 5 languages
  • โœ… Validates in isolated Docker sandboxes with security scanning
  • ๐Ÿš€ Creates detailed Pull Requests with confidence scores & evidence



โœจ Key Features




๐ŸŽฏ Multi-Provider Detection

Real-time webhooks from GitHub Actions, GitLab CI, CircleCI, Jenkins & Azure DevOps


๐Ÿง  AI-Powered RCA

Semantic log analysis with ML embeddings (FAISS + Sentence Transformers) and pattern matching


๐Ÿ› ๏ธ Autonomous Fixes

LLM-powered code generation for Python, Node.js, Go, Java & Docker with line-level precision


๐Ÿ–๏ธ Sandbox Validation

Isolated Docker environments with gitleaks, trivy & SBOM scanning before any PR



๐Ÿ“‹ Smart PR Management

Auto-generated PRs with changelogs, confidence scores, danger labels & provenance artifacts


๐Ÿ” Enterprise Security

JWT + GitHub/Google OAuth, RBAC, audit logging, CSRF protection & rate limiting


๐Ÿ“Š Modern Dashboard

React 18 + TypeScript with real-time SSE streaming, dark mode & failure detail views


๐Ÿ“ˆ Full Observability

Prometheus metrics, Grafana dashboards, OpenTelemetry tracing & Tempo integration



๐Ÿ†• What's New โ€” Complete Feature Breakdown


๐Ÿ”— 5 CI/CD Provider Integrations

Connect your entire pipeline ecosystem

  • โœ… GitHub Actions โ€” Full webhook verification, workflow_run/job events, log fetching
  • โœ… GitLab CI โ€” Pipeline and job event webhooks with token validation
  • โœ… CircleCI โ€” Job completion webhooks with HMAC signature verification
  • โœ… Jenkins โ€” Build notification webhooks with token-based auth
  • โœ… Azure DevOps โ€” Build/release webhooks with Basic auth verification
  • โœ… Unified event normalization layer across all providers
  • โœ… GitHub Action marketplace support (action.yml) for direct workflow integration

๐ŸŒ 5 Multi-Language Adapters

Deterministic fix generation for your stack

  • โœ… Python โ€” pip/poetry dependency resolution, import fixes, syntax repairs
  • โœ… Node.js โ€” npm/yarn package management, module resolution, config fixes
  • โœ… Go โ€” go.mod/go.sum dependency management, build error fixes
  • โœ… Java โ€” Maven/Gradle dependency resolution, compilation error fixes
  • โœ… Docker โ€” Dockerfile instruction fixes, base image updates, build stage repairs
  • โœ… Automatic adapter selection based on log analysis and repository file detection
  • โœ… Adapter registry with pluggable architecture for easy extension

๐Ÿ” Authentication & Authorization

Enterprise-grade multi-provider security

  • โœ… JWT-based authentication (access + refresh tokens via HttpOnly cookies)
  • โœ… GitHub OAuth login with state validation, CSRF protection & scope verification
  • โœ… Google OAuth integration
  • โœ… Email/password registration with secure session management
  • โœ… Role-based access control (RBAC) with granular permissions
  • โœ… Redis-backed session management with configurable TTLs
  • โœ… Comprehensive audit logging for all auth events

๐Ÿ“ข 5-Channel Notification System

Never miss a critical event

  • โœ… Slack โ€” Rich Block Kit messages, dedicated channels for alerts/critical/approvals
  • โœ… Microsoft Teams โ€” Adaptive Card notifications with action buttons
  • โœ… Email โ€” SMTP and SendGrid support with HTML templates
  • โœ… PagerDuty โ€” Incident creation/resolution with severity-based routing
  • โœ… Generic Webhook โ€” Bearer/Basic/HMAC auth for custom integrations
  • โœ… Parallel dispatch with rate limiting and configurable minimum severity
  • โœ… Pluggable factory pattern for adding custom notification channels

๐Ÿงพ Explainability + Trust Dashboard

Evidence-based failure analysis with full transparency

  • โœ… Root cause + log evidence with line indices and tags
  • โœ… Patch preview (unified diff) with DiffViewer component
  • โœ… FixPlan JSON preview with interactive JsonViewer
  • โœ… Danger score breakdown + policy violations surfaced
  • โœ… Scan summaries (gitleaks/trivy/SBOM + sandbox status)
  • โœ… Provenance artifact viewer with full pipeline timeline
  • โœ… Severity badges and visual risk indicators

๐Ÿ“Š Production Observability Stack

Complete monitoring, metrics, and distributed tracing

  • โœ… Prometheus metrics at /metrics (HTTP request rates, durations, pipeline outcomes)
  • โœ… 4 pre-built Grafana dashboards: API Health, Pipeline Overview, Safety & Risk, Security
  • โœ… OpenTelemetry tracing via OTLP with spans for every pipeline stage
  • โœ… Tempo trace storage with Grafana Explore integration
  • โœ… Correlation ID middleware linking logs โ†” metrics โ†” traces
  • โœ… Key metrics: webhook dedup, pipeline runs/retries/throttled, policy violations
  • ๐Ÿ“– Docs: observability.md

๐Ÿ–ฅ๏ธ React Dashboard & Landing Page

Modern, full-featured web interface

  • โœ… React 18 + TypeScript + Vite with hot module replacement
  • โœ… Landing page with hero section, feature blocks & GitHub login CTA
  • โœ… Real-time dashboard with SSE event streaming (13 event types)
  • โœ… Interactive failure detail views with log evidence
  • โœ… DiffViewer, JsonViewer, Timeline, and SeverityBadge components
  • โœ… Dark mode support with responsive design
  • โœ… Session guard layer with automatic redirect on JWT expiry
  • โœ… OAuth callback handler for GitHub login flow

โšก Pipeline Reliability & Operations

Production-grade resilience and safety

  • โœ… Idempotent webhook ingestion (duplicate deliveries ignored)
  • โœ… Redis-locked concurrent pipeline execution per repo
  • โœ… Configurable concurrency limits (default: 2 per repo)
  • โœ… Exponential backoff retries with cooldown periods
  • โœ… Loop protection โ€” blocks PR churn after max attempts
  • โœ… Per-repo webhook rate limiting (default: 30/min)
  • โœ… Post-merge monitoring with automatic re-validation
  • โœ… Incident playbooks for webhook storms, queue backlogs & scanner failures
  • ๐Ÿ“– Docs: ops.md

๐Ÿ”’ Safety & Security Engine

Multi-layered protection against unsafe changes

  • โœ… Configurable safety policy (config/safety_policy.yaml)
  • โœ… Dual policy checks โ€” plan-level AND patch-level validation
  • โœ… Danger score computation with breakdown per risk factor
  • โœ… Path allow/deny lists (protect critical infrastructure files)
  • โœ… Secret detection patterns (blocks API keys, passwords, tokens)
  • โœ… Patch size limits (max files, lines added, lines removed)
  • โœ… Critic model validation โ€” checks reasoning before execution
  • โœ… Supply-chain scanning: gitleaks (secrets), trivy (vulnerabilities), syft (SBOM)
  • โœ… PRs labeled safe or needs-review based on danger score threshold

๐Ÿงช Real-Time Test Harness

End-to-end SRE loop validation

  • โœ… Controlled failure-prone sample repository with GitHub Actions CI
  • โœ… Automated failure scenario injection (push branch โ†’ CI fails โ†’ webhook โ†’ fix โ†’ PR)
  • โœ… Testing Agent with API-driven subsystem validators
  • โœ… Per-scenario and aggregate structured JSON reports
  • โœ… Support for running all failures or selective subsets (--failures 1,4,7)
  • โœ… Cleanup mode to remove test GitHub repos after validation
  • โœ… Makefile convenience commands (setup, dry-run)
  • ๐Ÿ“– Docs: test-harness/README.md

๐Ÿ”Œ GitHub App & Repo Integration

Seamless onboarding and repository configuration

  • โœ… GitHub App installation flow with state persistence
  • โœ… Repository selector with permission validation (admin/maintain)
  • โœ… Per-repo .sre-agent.yaml configuration file support
  • โœ… Automation modes: suggest, auto_pr, auto_merge
  • โœ… Protected paths โ€” directories that must never be modified
  • โœ… Configurable retry limits per repository
  • โœ… Onboarding state tracking (oauth โ†’ repo_selected โ†’ app_installed โ†’ dashboard_ready)
  • ๐Ÿ“– Docs: phase1_onboarding.md

๐Ÿ“ˆ Offline Evaluation Harness

Quantified fix quality with structured metrics

  • โœ… 35 curated test cases across multiple failure categories
  • โœ… Mock LLM mode for deterministic, reproducible evaluations
  • โœ… Metrics: Fix Success Rate, Safe Fix Rate, Average Danger Score, Mean Time to Repair
  • โœ… Structured results output to evals/results/
  • โœ… CLI: python -m evals.run --limit 35 --model mock --out evals/results/run_local



๐Ÿ—๏ธ Architecture


flowchart TB
    subgraph Input["๐Ÿ“ฅ Event Sources"]
        GH[GitHub Actions]
        GL[GitLab CI]
        CCI[CircleCI]
        JNK[Jenkins]
        ADO[Azure DevOps]
    end
    
    subgraph Core["โš™๏ธ SRE Agent Core"]
        WH[Webhook Handler]
        NORM[Event Normalizer]
        ES[Event Store]
        CTX[Context Builder]
        RCA[RCA Engine]
        ADAPT[Adapter Registry]
    end
    
    subgraph AI["๐Ÿง  AI Pipeline"]
        PLAN[Plan Generator]
        CRITIC[Critic Validator]
        PATCH[Patch Generator]
        POLICY[Policy Engine]
        SCAN[Security Scans]
        SANDBOX[Sandbox Validator]
    end
    
    subgraph Output["๐Ÿ“ค Output"]
        PR[PR Creation]
        NOTIFY[Notifications]
        DASH[Dashboard SSE]
        EXPLAIN[Explainability]
    end
    
    subgraph Infra["๐Ÿ”ง Infrastructure"]
        DB[(PostgreSQL)]
        REDIS[(Redis)]
        CELERY[Celery Workers]
        PROM[Prometheus]
        GRAF[Grafana]
        TEMPO[Tempo Traces]
    end
    
    GH & GL & CCI & JNK & ADO --> WH
    WH --> NORM --> ES --> DB
    WH --> CELERY
    CELERY --> CTX --> RCA --> ADAPT
    ADAPT --> PLAN --> CRITIC --> PATCH --> POLICY --> SCAN --> SANDBOX
    SANDBOX --> PR
    SANDBOX --> NOTIFY
    SANDBOX --> DASH
    SANDBOX --> EXPLAIN
    
    CELERY <--> REDIS
    PROM --> GRAF
    TEMPO --> GRAF
Loading

๐Ÿ”„ 8-Step Deterministic Fix Pipeline

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                         DETERMINISTIC FIX PIPELINE                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                                 โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                    โ”‚
โ”‚  โ”‚ 1.ADAPTER โ”‚โ”€โ”€โ–ถโ”‚ 2. PLAN  โ”‚โ”€โ”€โ–ถโ”‚ 3. PLAN  โ”‚โ”€โ”€โ–ถโ”‚ 4.PATCH  โ”‚                   โ”‚
โ”‚  โ”‚  SELECT   โ”‚   โ”‚(LLMโ†’JSON)โ”‚   โ”‚  SAFETY  โ”‚   โ”‚(Diff Gen)โ”‚                   โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                    โ”‚
โ”‚       โ”‚              โ”‚              โ”‚              โ”‚                            โ”‚
โ”‚       โ–ผ              โ–ผ              โ–ผ              โ–ผ                            โ”‚
โ”‚   Language       Fix Plan      Policy Check    Unified Diff                     โ”‚
โ”‚   Detection      JSON Only     Intent Eval     Constrained                      โ”‚
โ”‚                                                                                 โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                    โ”‚
โ”‚  โ”‚ 5. PATCH โ”‚โ”€โ”€โ–ถโ”‚ 6. SCAN  โ”‚โ”€โ”€โ–ถโ”‚  7. TEST  โ”‚โ”€โ”€โ–ถโ”‚ 8. PR    โ”‚                   โ”‚
โ”‚  โ”‚  SAFETY  โ”‚   โ”‚(Security)โ”‚   โ”‚ (Sandbox) โ”‚   โ”‚(Creation)โ”‚                   โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                    โ”‚
โ”‚       โ”‚              โ”‚              โ”‚              โ”‚                            โ”‚
โ”‚       โ–ผ              โ–ผ              โ–ผ              โ–ผ                            โ”‚
โ”‚   Path/Secret    gitleaks      Tests Pass?     safe / needs-review              โ”‚
โ”‚   Size Limits    trivy/SBOM    โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€    Provenance Attached              โ”‚
โ”‚   Danger Score   Secrets Scan  If YES โ†’ PR                                      โ”‚
โ”‚                                If NO โ†’ Alert                                    โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ› ๏ธ Tech Stack

Layer Technology Purpose
๐ŸŒ API Async REST API framework with auto-generated docs
๐Ÿ–ฅ๏ธ Frontend Modern reactive UI with SSE streaming & dark mode
โšก Task Queue Async pipeline processing with concurrency locking
๐Ÿ’พ Database Event store, pipeline runs, audit logs with migrations
๐Ÿง  AI/LLM Fix plan generation (JSON-only output with critic validation)
๐Ÿ” Embeddings Semantic log analysis & knowledge base retrieval
๐Ÿ”’ Security Secrets detection, vulnerability scanning, SBOM generation
๐Ÿ“Š Observability Metrics, dashboards, distributed tracing, trace storage
๐Ÿณ Container Containerization, orchestration & sandbox isolation



๐Ÿš€ Quick Start


Prerequisites

โœ… Python 3.11+ Core runtime
โœ… Docker & Docker Compose Container orchestration & sandbox
โœ… Poetry Python dependency management
โœ… Node.js 18+ Frontend development
โœ… GitHub PAT API access for webhooks & log fetching

๐Ÿณ Option 1: Docker (Recommended)

# Clone the repository
git clone https://github.com/Mrgig7/Autonomous-Al-powered-SRE-Agent.git
cd Autonomous-Al-powered-SRE-Agent

# Configure environment
cp .env.example .env
# Edit .env with your GitHub token and settings

# Start all services (API, Worker, DB, Redis, Prometheus, Grafana, Tempo, OTel)
docker-compose up -d

# Optional: Start with frontend
docker-compose --profile with-frontend up -d

# Optional: Start with local LLM (requires GPU)
docker-compose --profile local-llm up -d

# Check status
docker-compose ps

๐Ÿ’ป Option 2: Local Development

# Clone the repository
git clone https://github.com/Mrgig7/Autonomous-Al-powered-SRE-Agent.git
cd Autonomous-Al-powered-SRE-Agent

# Configure environment
cp .env.example .env

# Start infrastructure
docker-compose up -d postgres redis

# Install Python dependencies
poetry install

# Run database migrations
poetry run alembic upgrade head

# Terminal 1: Start API server
poetry run uvicorn sre_agent.main:app --reload --host 0.0.0.0 --port 8000

# Terminal 2: Start Celery worker
poetry run celery -A sre_agent.celery_app worker --loglevel=info

# Terminal 3: Start frontend
cd frontend && npm ci && npm run dev

๐ŸŒ Access Points

Service URL Description
๐Ÿ–ฅ๏ธ Dashboard http://localhost:3000 React frontend with SSE streaming
๐Ÿ“š API Docs http://localhost:8000/docs Swagger UI (auto-generated)
๐Ÿ“Š Prometheus http://localhost:9090 Metrics & alerting
๐Ÿ“ˆ Grafana http://localhost:3001 Dashboards & trace explorer (admin/admin)
๐Ÿ” Tempo http://localhost:3200 Distributed trace storage
๐Ÿ“‰ Metrics http://localhost:8000/metrics Raw Prometheus metrics endpoint

๐ŸŽฎ GitHub Action Usage

Add the SRE Agent to your workflow for automatic failure analysis:

# .github/workflows/sre-agent.yml
name: SRE Agent Analysis
on:
  workflow_run:
    workflows: ["CI"]
    types: [completed]

jobs:
  analyze:
    if: ${{ github.event.workflow_run.conclusion == 'failure' }}
    runs-on: ubuntu-latest
    steps:
      - uses: Mrgig7/Autonomous-Al-powered-SRE-Agent@main
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}
          auto-create-pr: 'true'
          notify-slack: 'true'
          slack-webhook-url: ${{ secrets.SLACK_WEBHOOK_URL }}



๐Ÿ”Œ API Reference


Webhook Endpoints

Method Endpoint Description
POST /webhooks/github GitHub Actions webhook receiver
POST /webhooks/gitlab GitLab CI webhook receiver
POST /webhooks/circleci CircleCI webhook receiver
POST /webhooks/jenkins Jenkins webhook receiver
POST /webhooks/azure-devops Azure DevOps webhook receiver

Core Endpoints

๐Ÿฅ Health Check
GET /health

Response:

{
  "status": "healthy",
  "version": "1.0.0",
  "database": "connected",
  "redis": "connected"
}
๐Ÿ” Get Failure Analysis
GET /api/v1/failures/{failure_id}/analysis

Returns root cause, category, confidence score, and evidence lines.

๐Ÿงพ Get Explanation (Explainability)
GET /api/v1/failures/{failure_id}/explain

Returns evidence-based failure explanation with root cause, log evidence with line indices, danger score breakdown, and policy violations.

๐Ÿ“œ Get Provenance Artifact
GET /api/v1/runs/{run_id}/artifact

Returns full provenance including plan JSON, policy decisions, scan results (gitleaks, trivy, SBOM), and validation results.

๐Ÿ“Š Dashboard Stream (SSE)
GET /api/v1/dashboard/stream

Server-Sent Events stream with 13 event types: ingest, context, rca, fix_pipeline, adapter_select, plan, policy_plan, clone, patch, policy_patch, validate, pr_create, pipeline.

Auth Endpoints

Method Endpoint Description
POST /api/v1/auth/register User registration
POST /api/v1/auth/login Email/password login
POST /api/v1/auth/github/login GitHub OAuth start/exchange
POST /api/v1/auth/logout Session logout
GET /api/v1/users/me Get current user profile
GET /api/v1/user/repos List GitHub repositories
POST /api/v1/integration/install Start GitHub App installation
POST /api/v1/integration/install/confirm Confirm GitHub App installation

๐Ÿ“– Full API documentation: http://localhost:8000/docs




โš™๏ธ Configuration


Environment Variables

The .env.example file contains 156 configurable options organized into sections:

Section Key Variables Description
Core GITHUB_TOKEN, GITHUB_WEBHOOK_SECRET GitHub API access & webhook verification
Database DATABASE_URL, REDIS_URL PostgreSQL and Redis connections
LLM LLM_PROVIDER, OLLAMA_MODEL, OLLAMA_BASE_URL AI model configuration (ollama/mock)
Auth JWT_SECRET_KEY, GITHUB_OAUTH_CLIENT_ID/SECRET Authentication & OAuth settings
Google OAuth GOOGLE_OAUTH_CLIENT_ID/SECRET Google login integration
Sandbox SANDBOX_DOCKER_IMAGE, ENABLE_SCANS, FAIL_ON_SECRETS Sandbox & security scanning
Slack SLACK_ENABLED, SLACK_WEBHOOK_URL, SLACK_BOT_TOKEN Slack notification channel
Teams TEAMS_ENABLED, TEAMS_WEBHOOK_URL Microsoft Teams notifications
Email EMAIL_ENABLED, SMTP_HOST, SENDGRID_API_KEY Email notifications (SMTP/SendGrid)
PagerDuty PAGERDUTY_ENABLED, PAGERDUTY_ROUTING_KEY Incident management integration
Webhook WEBHOOK_ENABLED, WEBHOOK_URL, WEBHOOK_AUTH_TYPE Generic webhook notifications
GitLab GITLAB_ENABLED, GITLAB_TOKEN GitLab CI provider
CircleCI CIRCLECI_ENABLED, CIRCLECI_TOKEN CircleCI provider
Jenkins JENKINS_ENABLED, JENKINS_URL, JENKINS_TOKEN Jenkins provider
Azure DevOps AZURE_DEVOPS_ENABLED, AZURE_DEVOPS_PAT Azure DevOps provider
Reliability MAX_PIPELINE_ATTEMPTS, COOLDOWN_SECONDS Retry/backoff/loop protection
Phase Flags PHASE1_ENABLE_DASHBOARD, PHASE1_ENABLE_INSTALL_FLOW Feature flag toggles

๐Ÿ›ก๏ธ Safety Policy

# config/safety_policy.yaml
paths:
  allowed:
    - "src/**"
    - "tests/**"
  forbidden:
    - ".github/workflows/**"  # Never edit workflows
    
secrets:
  forbidden_patterns:
    - "(?i)api[_-]?key"
    - "(?i)password"
    
patch_limits:
  max_files: 10
  max_lines_added: 500
  max_lines_removed: 200
  
danger:
  safe_max: 25  # Score < 25 = "safe" label

๐Ÿ“‚ Repository Configuration

Add .sre-agent.yaml to your repository root:

automation_mode: suggest   # suggest | auto_pr | auto_merge
protected_paths:
  - infra/**
  - payments/**
retry_limit: 3



๐Ÿงช Testing & Evaluation


Unit Tests

# Run all tests
poetry run pytest

# Run with coverage
poetry run pytest --cov=src/sre_agent --cov-report=html

# Run specific tests
poetry run pytest tests/test_api.py -v

Offline Evaluation Harness

# Run 35-case evaluation with mock LLM
python -m evals.run --limit 35 --model mock --out evals/results/run_local

๐Ÿ“Š Evaluation Metrics

Model Cases Fix Success Safe Fix Rate Avg Danger Avg MTTR
mock 35 71.4% 71.4% 13.0 0.00s

Real-Time Test Harness

Validates the full end-to-end SRE loop: push failure โ†’ CI fails โ†’ webhook โ†’ pipeline โ†’ fix โ†’ PR.

cd test-harness
make setup                                  # Install dependencies
python run_harness.py --failures all        # Run all failure scenarios
python run_harness.py --failures 1,4,7      # Run specific scenarios
python run_harness.py --failures all --cleanup  # Run + cleanup GitHub repo

Reports generated at:

  • Per-case: test-harness/reports/validator-failure-XX.json
  • Aggregate: test-harness/reports/harness-report.json



๐Ÿ“ Project Structure


๐Ÿ“ฆ Autonomous-AI-powered-SRE-Agent
โ”œโ”€โ”€ ๐Ÿ“„ action.yml                   # GitHub Action marketplace definition
โ”œโ”€โ”€ ๐Ÿ“„ docker-compose.yml           # 10-service container orchestration
โ”œโ”€โ”€ ๐Ÿ“„ Dockerfile                   # API/Worker container build
โ”œโ”€โ”€ ๐Ÿ“„ pyproject.toml               # Python dependencies (Poetry)
โ”‚
โ”œโ”€โ”€ ๐Ÿ“‚ src/sre_agent/               # Main application package (23 sub-packages)
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ adapters/                # Multi-language: Python, Node, Go, Java, Docker
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ ai/                      # LLM integration (plan generation, embeddings, critic)
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ api/                     # FastAPI routes (14 route modules)
โ”‚   โ”‚   โ””โ”€โ”€ ๐Ÿ“‚ webhooks/            # GitHub, GitLab, CircleCI, Jenkins, Azure DevOps
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ auth/                    # JWT, OAuth, RBAC, session management
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ core/                    # Logging, Redis service
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ explainability/          # Evidence-based failure explanations
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ fix_pipeline/            # 8-step deterministic fix orchestrator
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ intelligence/            # RCA engine, failure pattern matching
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ knowledge/              # Knowledge base & FAISS embeddings
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ middleware/              # Request processing middleware
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ models/                  # SQLAlchemy database models
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ notifications/          # Slack, Teams, Email, PagerDuty, Webhook
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ observability/          # Prometheus metrics, OTel tracing, middleware
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ ops/                     # Operational reliability (rate limit, concurrency)
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ pr/                      # Pull request creation & management
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ providers/              # CI/CD provider abstractions
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ safety/                  # Policy engine, danger scoring, diff parsing
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ sandbox/                # Docker sandbox, test runner, scanners
โ”‚   โ”‚   โ””โ”€โ”€ ๐Ÿ“‚ scanners/           # gitleaks, trivy, syft integrations
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ schemas/                # Pydantic models (14 schema modules)
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ services/               # Business logic (18 service modules)
โ”‚   โ””โ”€โ”€ ๐Ÿ“‚ tasks/                   # Celery async tasks (dispatch, context, fix)
โ”‚
โ”œโ”€โ”€ ๐Ÿ“‚ frontend/                    # React 18 + TypeScript + Vite
โ”‚   โ””โ”€โ”€ ๐Ÿ“‚ src/
โ”‚       โ”œโ”€โ”€ ๐Ÿ“‚ pages/               # Landing, Login, OAuthCallback, Dashboard, FailureDetails
โ”‚       โ”œโ”€โ”€ ๐Ÿ“‚ components/          # DiffViewer, JsonViewer, SeverityBadge, Timeline
โ”‚       โ”œโ”€โ”€ ๐Ÿ“‚ api/                 # API client
โ”‚       โ””โ”€โ”€ ๐Ÿ“‚ styles/             # CSS styles
โ”‚
โ”œโ”€โ”€ ๐Ÿ“‚ test-harness/                # Real-time end-to-end test system
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ sample-app/             # Failure-prone test application
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ testing-agent/          # API-driven subsystem validators
โ”‚   โ””โ”€โ”€ ๐Ÿ“‚ reports/                # Generated JSON test reports
โ”‚
โ”œโ”€โ”€ ๐Ÿ“‚ observability/               # Infrastructure configurations
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ grafana/                # Dashboard provisioning & JSON dashboards
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ prometheus/             # Scrape config & alert rules
โ”‚   โ”œโ”€โ”€ ๐Ÿ“‚ otel-collector/         # OpenTelemetry Collector config
โ”‚   โ””โ”€โ”€ ๐Ÿ“‚ tempo/                  # Tempo trace storage config
โ”‚
โ”œโ”€โ”€ ๐Ÿ“‚ evals/                       # Offline evaluation harness (35 test cases)
โ”œโ”€โ”€ ๐Ÿ“‚ tests/                       # Unit & integration test suite
โ”œโ”€โ”€ ๐Ÿ“‚ alembic/                     # Database migration scripts
โ”œโ”€โ”€ ๐Ÿ“‚ config/                      # Safety policy YAML
โ”œโ”€โ”€ ๐Ÿ“‚ docs/                        # Documentation
โ”‚   โ”œโ”€โ”€ ๐Ÿ“„ pipeline.md             # Pipeline flow documentation
โ”‚   โ”œโ”€โ”€ ๐Ÿ“„ ops.md                  # Reliability & operations guide
โ”‚   โ”œโ”€โ”€ ๐Ÿ“„ observability.md        # Monitoring & tracing setup
โ”‚   โ”œโ”€โ”€ ๐Ÿ“„ phase1_onboarding.md    # OAuth & onboarding runbook
โ”‚   โ”œโ”€โ”€ ๐Ÿ“„ phase2_repo_integration.md  # Repository integration guide
โ”‚   โ””โ”€โ”€ ๐Ÿ“„ PUBLISHING.md          # Publishing guidelines
โ””โ”€โ”€ ๐Ÿ“‚ .github/                     # CI/CD workflows



๐Ÿ—บ๏ธ Roadmap


โœ… Completed

  • ๐Ÿ—๏ธ Project foundation & architecture
  • ๐Ÿ“ก Event ingestion API (5 CI/CD providers)
  • ๐Ÿง  AI fix generation engine with critic validation
  • ๐Ÿ–๏ธ Sandbox validation engine with supply-chain scanning
  • ๐Ÿ“‹ PR creation service with danger scoring & labels
  • ๐ŸŒ React 18 Dashboard with landing page & SSE streaming
  • ๐Ÿ” JWT + GitHub OAuth + Google OAuth + RBAC
  • ๐Ÿ”” 5-Channel Notification System (Slack, Teams, Email, PagerDuty, Webhook)
  • ๐Ÿ“Š Dashboard API, analytics & real-time SSE (13 event types)
  • ๐Ÿ“ Comprehensive audit logging system
  • ๐Ÿงพ Explainability + Trust Dashboard with evidence & provenance
  • ๐Ÿ“ˆ Full Observability Stack (Prometheus, Grafana, OTel, Tempo)
  • ๐ŸŒ Multi-Language Adapters (Python, Node, Go, Java, Docker)
  • ๐Ÿ”’ Security Scans (gitleaks, trivy, syft SBOM)
  • โšก Pipeline reliability (idempotent ingestion, concurrency locks, retry/backoff, loop protection)
  • ๐Ÿ”Œ GitHub App integration & .sre-agent.yaml repo config
  • ๐Ÿงช Real-time test harness with testing agent
  • ๐Ÿ“ˆ Offline evaluation harness (35 cases)
  • ๐ŸŽฎ GitHub Action marketplace support (action.yml)
  • ๐Ÿ”— Post-merge monitoring & re-validation

๐Ÿšง In Progress

  • ๐ŸŒ Production website with full onboarding flow
  • ๐Ÿ“Š Advanced analytics & reporting dashboards
  • ๐Ÿ” Enhanced security features (token encryption, HMAC-signed artifacts)

๐Ÿ”ฎ Planned

  • ๐Ÿ“ฑ Mobile-responsive PWA
  • ๐Ÿค– AI model fine-tuning on proprietary failure data
  • ๐ŸŒ Multi-region deployment support
  • ๐Ÿ“Š Custom dashboard widgets
  • ๐Ÿ”— Slack/Teams interactive approval workflows
  • ๐Ÿ”„ Live LLM provider switching (OpenAI, Anthropic, Gemini)



๐Ÿค Contributing


We welcome contributions! Here's how to get started:

# 1. Fork the repository

# 2. Create your feature branch
git checkout -b feature/AmazingFeature

# 3. Commit your changes
git commit -m 'Add some AmazingFeature'

# 4. Push to the branch
git push origin feature/AmazingFeature

# 5. Open a Pull Request

๐Ÿ“ Code Standards

  • โœ… Follow PEP 8 for Python (enforced by Ruff)
  • โœ… Use TypeScript strict mode for frontend
  • โœ… Add tests for new features
  • โœ… Update documentation
  • โœ… All PRs must pass safety policy checks



๐Ÿ“„ License


This project is licensed under the MIT License - see the LICENSE file for details.




Built with โค๏ธ for SRE teams everywhere

๐Ÿ› Report Bug โ€ข ๐Ÿ’ก Request Feature โ€ข โญ Star the Repo

Stars Forks Watchers

About

SRE Agent transforms CI/CD pipelines into self-healing systems. โœ… Auto Failure Detection ๐Ÿ” AI Root Cause Analysis ๐Ÿ”ง Intelligent Fix Suggestions ๐Ÿ“ข Slack, Teams, Email, PagerDuty alerts ๐Ÿ” Enterprise Ready - RBAC & audit logs

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages