Skip to content

About

Autonomous SRE incident triage and runbook memory agent pairing Groq LPU sub-second inference with Hindsight biomimetic 4-channel persistent memory.

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

IncidentOps: Autonomous SRE Root-Cause & Runbook Memory Agent.

Enterprise autonomous incident triage copilot pairing Groq LPU ultra-low latency inference (openai/gpt-oss-120b) with Hindsight biomimetic 4-channel persistent memory (incidentops-bank) to retrieve verified post-mortems at $0.00 cost (zero LLM tokens) and output instant, executable CLI fixes.

πŸ‘₯ Authors & Collaborators

  • Sai Bhavani Yedla
  • Bhargavi Endla

πŸ“Œ Executive Summary & Problem Statement

Modern Site Reliability Engineering (SRE) and DevOps teams suffer from operational amnesia:

  1. Recurring Outages: Production incidents often repeat weeks or months later with mutated pod names, different timestamps, or reworded telemetry logs.
  2. Context Loss: Past incident resolutions remain buried across fragmented Slack threads, Google Docs, Notion wikis, or lost with departing engineers.
  3. High MTTR & High Cognitive Burden: On-call engineers facing 2:00 AM outages waste 45 minutes to 4+ hours running trial-and-error commands on bastion nodes.
  4. Flaws in Naive Vector RAG: Standard vector databases rely purely on text cosine similarity. They cannot handle port-level lexical precision, fail to comprehend cron/release timelines, miss cause-and-effect relationships, and consume costly LLM tokens on every vector re-index and retrieval.

IncidentOps solves this by establishing an autonomous operational memory loop. Live alerts are cross-examined against Hindsight's 4-channel biomimetic memory bank. Verified post-mortems provide deterministic root-cause diagnosis and pre-approved bash fixes in under 450 milliseconds with $0.00 memory retrieval cost.

⚑ Core Architecture & The 4 Brain Lobes

                                  LIVE PRODUCTION OUTAGE
                      (HTTP 504, Kafka Lag >50k, Postgres Slot Exhaustion)
                                             β”‚
                                             β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚       HINDSIGHT 4-CHANNEL BIOMIMETIC RECALL            β”‚
                 β”‚              (Bank: incidentops-bank)                  β”‚
                 β”‚                 $0.00 / 0 LLM Tokens                   β”‚
                 β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                        β”‚            β”‚             β”‚             β”‚
                        β–Ό            β–Ό             β–Ό             β–Ό
                   Channel 1     Channel 2     Channel 3     Channel 4
                     BM25          Vector       Temporal       Causal
                    Lexical       Semantic     Chronology      Graph
                 (Exact Ports)  (Synonyms)    (Cron / Time)   (TEMPER)
                        β”‚            β”‚             β”‚             β”‚
                        β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                               β”‚ Recalled Operational Context
                               β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚         GROQ LPU REASONING             β”‚
                 β”‚        openai/gpt-oss-120b             β”‚
                 β”‚         Sub-450ms Latency              β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                    β”‚
                                    β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚       AUTOMATED STATIC SAFETY GUARD    β”‚
                 β”‚   πŸ›‘οΈ SAFE / DRY-RUN vs 🚨 HIGH RISK    β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                    β”‚
                                    β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚        INTERACTIVE SRE TERMINAL        β”‚
                 β”‚ (redis-cli kill / offset shift / psql) β”‚
                 β”‚      Cluster Health -> HEALTHY         β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                    β”‚
                                    β–Ό
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β”‚    POST-MORTEM RETENTION (TEMPER)      β”‚
                 β”‚    hindsight.retain() Knowledge Graph   β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The 4 Memory Lobes

  1. Lobe 1: BM25 Lexical Keyword Search: Performs zero-hallucination exact matching for infrastructure identifiers, socket ports (6379, 5432, 9092), container exit codes (Exit 137), and error tokens.
  2. Lobe 2: Vector Semantic Similarity: Detects semantic equivalence across phrasing differences (e.g., mapping "socket pool full" to "unreleased client leases").
  3. Lobe 3: Temporal Ordering & Chronology: Correlates failures with operational time patterns, such as scheduled nightly rollups (04:00 UTC) or recent deployments.
  4. Lobe 4: Causal Knowledge Graph (TEMPER): Navigates cause-and-effect graphs:

$$\text{Trigger} \longrightarrow \text{Mechanism} \longrightarrow \text{Impact} \longrightarrow \text{Verified Runbook}$$

πŸ› οΈ Tech Stack

Frontend Application (Vite / React)

  • Framework: React 19, TypeScript, Vite
  • Styling: Tailwind CSS v4, custom glassmorphism, responsive widescreen dashboard
  • Icons: Lucide React
  • Local Simulation: Client-side fallback engine using localStorage

Backend & AI Intelligence (Python)

  • LLM Engine: Groq Cloud SDK (openai/gpt-oss-120b, fallback to llama-3.3-70b-versatile)
  • Persistent Memory: Hindsight Client SDK (hindsight-client, interacting with api.hindsight.vectorize.io)
  • Dashboard Framework: Streamlit
  • Environment & Typing: Pydantic v2, Python-dotenv

πŸ“‚ Project Structure

β”œβ”€β”€ agent.py                  # Core triage engine, 4-channel recall & Groq synthesis
β”œβ”€β”€ app.py                    # Streamlit enterprise multi-tab dashboard
β”œβ”€β”€ sample_incidents.py       # Seeds production outages into incidentops-bank
β”œβ”€β”€ test_cloud_hindsight.py   # Cloud retain/recall verification test script
β”œβ”€β”€ test_groq.py              # Groq LPU sub-second inference test script
β”œβ”€β”€ requirements.txt          # Python dependencies
β”œβ”€β”€ package.json              # Node.js dependencies & scripts
β”œβ”€β”€ vite.config.ts            # Vite configuration with Tailwind CSS plugin
β”œβ”€β”€ index.html                # HTML entry point
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ App.tsx               # Main React dashboard layout
β”‚   β”œβ”€β”€ index.css             # Tailwind v4 styles & theme
β”‚   β”œβ”€β”€ main.tsx              # React mounting root
β”‚   β”œβ”€β”€ components/
β”‚   β”‚   β”œβ”€β”€ TopBar.tsx           # Global navigation and cluster health
β”‚   β”‚   β”œβ”€β”€ TriageConsole.tsx    # Live alert intake and diagnosis
β”‚   β”‚   β”œβ”€β”€ BeforeAfterDemo.tsx  # 3-Stage multi-scenario evolution demo
β”‚   β”‚   β”œβ”€β”€ PostMortemStudio.tsx # TEMPER post-mortem retention studio
β”‚   β”‚   β”œβ”€β”€ MemoryExplorer.tsx   # Causal graph and bank inspector
β”‚   β”‚   β”œβ”€β”€ ArchitectureDoc.tsx  # Interactive system architecture doc
β”‚   β”‚   β”œβ”€β”€ TerminalRunner.tsx   # Interactive browser-based SRE terminal
β”‚   β”‚   β”œβ”€β”€ PythonSuiteViewer.tsx# In-browser Python source inspector
β”‚   β”‚   └── SettingsModal.tsx    # Engine and API key configuration
β”‚   β”œβ”€β”€ services/
β”‚   β”‚   β”œβ”€β”€ hindsightEngine.ts   # Biomimetic 4-channel client engine
β”‚   β”‚   └── groqEngine.ts        # Groq client & static command safety guard
β”‚   β”œβ”€β”€ types/
β”‚   β”‚   └── incident.ts          # TypeScript interfaces
β”‚   └── data/
β”‚       └── seedData.ts          # Seed post-mortems and preset error logs

πŸš€ Execution & Setup Guide

1. Environment Configuration

Create a .env file in the project root:

GROQ_API_KEY="gsk_your_groq_api_key_here"
HINDSIGHT_API_KEY="your_hindsight_api_key_here"
HINDSIGHT_BASE_URL="https://api.hindsight.vectorize.io"
HINDSIGHT_BANK_ID="incidentops-bank"


### 2. Option A: Running the Python Streamlit App

1. Create and activate a Python virtual environment

python -m venv .venv

Windows:

.venv\Scripts{=tex}\activate{=tex} # Linux/macOS: source .venv/bin/activate

2. Install dependencies

pip install -r requirements.txt

3. Seed real enterprise outages into Hindsight Cloud

python sample_incidents.py

4. Verify cloud connectivity

python test_cloud_hindsight.py python test_groq.py

5. Launch the Streamlit dashboard

streamlit run app.py

The dashboard will open at `http://localhost:8501`.

3. Option B: Running the React / Vite Web App

# 1. Install Node.js packages
npm install --legacy-peer-deps

# 2. Launch Vite development server
npm run dev

The application will open at http://localhost:3000.

```

πŸ”¬ Enterprise Outage Test Scenarios

IncidentOps includes pre-configured production failure modes for immediate evaluation:


Scenario Service Symptoms Diagnosed Root Verified Remediation Runbook Cause


Redis Pool checkout-service HTTP 504 Gateway Timeouts, 10,000 active leases Zombie connection redis-cli -h redis-master -p 6379 client kill type normal``<br>{=html}kubectl patch configmap checkout-config ...``<br>{=html}kubectl rollout restart deployment/checkout-cluster-worker Exhaustion leak in Python
redis-py
failing to
release socket
leases on port
6379.

Kafka payment-stream Consumer lag >50,000 messages, worker crashloop Poison pill JSON kafka-consumer-groups.sh ... --shift-by 1 --execute``<br>{=html}kafka-console-producer.sh ... --topic payments.dlq``<br>{=html}kubectl set image deployment/payment-processor ... Deserialization missing mandatory currency_code
schema key
triggering
unhandled
deserialization
loop.

PostgreSQL data-platform-analytics FATAL: remaining connection slots are reserved (max 500) Nightly ETL cron psql -c "SELECT pg_terminate_backend(pid) FROM pg_stat_activity WHERE state = 'idle in transaction';"``<br>{=html}kubectl patch cronjob analytics-nightly-rollup ... Saturation spawned 200
Celery sub-tasks
bypassing
PgBouncer
directly to port
5432.

πŸ“Š Enterprise Benchmark Comparison


Metric Dimension Traditional SRE Naive Vector RAG IncidentOps (Amnesia) (Groq + Hindsight)


Mean Time to ~4.2 Hours ~45 Minutes < 8.4 Seconds Resolution (-99.9%) (MTTR)

Memory Manual runbook $0.08 / query $0.00 (Zero Retrieval Cost search (Embeddings) LLM Tokens)

Inference Human manual 12 - 35 Seconds 280 - 450 ms Latency triage (Groq LPU)

Channel None (Lost in Single vector 4-Channel Coverage Slack) similarity Biomimetic Graph

Runbook Safety Manual human None Static Regex Analysis review (Hallucinated Guardrail scripts)

πŸ›‘οΈ Static Command Safety Guard

To prevent automated destructive script execution during remediation, all output runbooks pass through a regex guardrail before reaching the terminal:

  • Destructive Patterns Flagged: rm -rf, drop database, kill -9 -1, kubectl delete namespace, truncate table, dd if=, shutdown -h.
  • Safe Patterns Allowed: redis-cli client kill type normal, kubectl rollout restart, kubectl patch configmap, pg_terminate_backend().

πŸ“„ License

This project is distributed under the MIT License.

About

Autonomous SRE incident triage and runbook memory agent pairing Groq LPU sub-second inference with Hindsight biomimetic 4-channel persistent memory.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages