{"id":51779466,"url":"https://github.com/seaworld008/aiops-system","last_synced_at":"2026-07-20T10:32:12.650Z","repository":{"id":370696831,"uuid":"1296231795","full_name":"seaworld008/aiops-system","owner":"seaworld008","description":"Evidence-first AIOps investigation and policy-governed safe automation platform","archived":false,"fork":false,"pushed_at":"2026-07-17T14:07:22.000Z","size":4391,"stargazers_count":1,"open_issues_count":2,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-17T14:20:54.838Z","etag":null,"topics":["aiops","devops","gitops","golang","incident-response","kubernetes","llmops","observability","platform-engineering","sre"],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/seaworld008.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":"GOVERNANCE.md","roadmap":"docs/roadmap.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-10T07:42:33.000Z","updated_at":"2026-07-17T14:01:01.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/seaworld008/aiops-system","commit_stats":null,"previous_names":["seaworld008/aiops-system"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/seaworld008/aiops-system","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/seaworld008%2Faiops-system","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/seaworld008%2Faiops-system/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/seaworld008%2Faiops-system/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/seaworld008%2Faiops-system/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/seaworld008","download_url":"https://codeload.github.com/seaworld008/aiops-system/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/seaworld008%2Faiops-system/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35684012,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"ssl_error","status_checked_at":"2026-07-20T02:08:09.736Z","response_time":111,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aiops","devops","gitops","golang","incident-response","kubernetes","llmops","observability","platform-engineering","sre"],"created_at":"2026-07-20T10:32:12.019Z","updated_at":"2026-07-20T10:32:12.641Z","avatar_url":"https://github.com/seaworld008.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# AIOps System\n\n[![CI](https://github.com/seaworld008/aiops-system/actions/workflows/ci.yml/badge.svg)](https://github.com/seaworld008/aiops-system/actions/workflows/ci.yml)\n[![License](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE)\n[![Go](https://img.shields.io/badge/Go-1.26.5-00ADD8?logo=go)](go.mod)\n\nEvidence-first operations intelligence with policy-governed automation.\n\n**English** · [简体中文](README.zh-CN.md)\n\n\u003e [!IMPORTANT]\n\u003e AIOps System is in active pre-alpha development. Read-only investigation foundations are usable for development and evaluation. Production write automation has no configurable enablement path and remains disabled until every safety and quality gate in the pilot plan has passed.\n\n## Why this project exists\n\nModern operations teams already have metrics, logs, Kubernetes, virtual machines, CI/CD, GitOps, and incident channels. What they often lack is a trustworthy layer that can correlate those facts, explain its evidence, and execute a very small set of changes without handing authority to an LLM.\n\nAIOps System is designed around four rules:\n\n- **Evidence before conclusions.** Every operational claim must cite bounded, traceable evidence.\n- **Models propose; deterministic systems decide.** CEL policy, identity, approvals, live state, and signed plans govern execution.\n- **Uncertain means stop and reconcile.** Side effects are fenced, verified, and never blindly retried.\n- **Least privilege is an architecture boundary.** Read and write runners have separate identities, queues, credentials, and network paths.\n\n## Current capabilities\n\n| Area | Status | What is available |\n| --- | --- | --- |\n| Signal ingestion | Implemented | Scoped and signed Alertmanager/Nightingale webhooks, idempotency, deduplication foundations |\n| Read-only evidence | Implemented | Bounded clients for Prometheus, VictoriaLogs, Kubernetes, AWX, Argo CD, GitLab, Jenkins, and GitHub Actions |\n| Investigation | Implemented foundation | Persistent facts, a strict mTLS READ Task Gateway, an atomic connector/target/egress/executor Bundle, a recovery-first Temporal v2 Workflow, fixed READ Runner Activity, immutable assembly Snapshot, role-isolated Temporal Starter/Control Worker, monitored fatal/stop subprocess containment, a sealed pre-assembly child lifecycle arbiter, and a kill-bounded fixed-root public-source loader plus sealed FD4 handoff exist; after exact semantic Snapshot comparison the child now emits a distinct one-shot `SECRET_READY`, receives bounded role-tagged secrets only through fixed FD5–FD7, and validates each P-256 private key against the captured client certificate before opaque binding. The production secret supplier and runtime factory remain fixed unavailable, so Dial, Worker Start and READY are still impossible; live Outbox/Runner assembly is absent and Admission remains closed pending M5C2-4c and external Go/No-Go gates |\n| Identity and policy | Implemented foundation | Keycloak OIDC, workspace/environment RBAC, signed ActionEnvelope, three-stage CEL decisions |\n| Execution safety | Implemented foundation | Exact runner scopes, durable credential revocation, TLS 1.3 mTLS Gateway, split READ/WRITE images, fixed killable executor, target locks, heartbeat, cancellation, and reconciliation |\n| Production automation | **Disabled** | Requires fixed real adapters, external sandbox/network gates, non-production drills, and formal Go/No-Go approval |\n| Web console / ChatOps | Planned | React console and Feishu workflows are not yet shipped |\n\n“Implemented foundation” means the contracts and testable core exist; it does **not** mean a connector or mutation path is ready for unattended production use.\n\n## Architecture\n\n```mermaid\nflowchart LR\n    UI[\"Web / Feishu / Alert Webhooks\"] --\u003e IN[\"Verified ingestion and service mapping\"]\n    IN --\u003e CP[\"Go modular control plane\"]\n    CP --\u003e PG[(PostgreSQL)]\n    CP --\u003e OBJ[(S3-compatible evidence store)]\n    CP --\u003e TW[\"Temporal workflows\"]\n    CP --\u003e CEL[\"CEL policy engine\"]\n    CP --\u003e AI[\"Private / cloud model adapters\"]\n\n    TW --\u003e GW[\"Outbound Runner Gateway\"]\n    GW --\u003e RR[\"Read-only runners\"]\n    GW --\u003e WR[\"Split write runners + fixed executor\"]\n    RR --\u003e OBS[\"Metrics / logs / K8s / AWX / CI / Argo\"]\n    WR --\u003e MUT[\"Typed K8s / GitOps / AWX actions\"]\n\n    KC[\"Keycloak\"] --\u003e CP\n    VAULT[\"Vault short-lived credentials\"] --\u003e RR\n    VAULT --\u003e WR\n```\n\nThe first release targets a single self-hosted organization with multiple workspaces. PostgreSQL is the domain source of truth; Temporal is used only for durable orchestration. Runner communication is outbound-only through a dedicated TLS 1.3 mTLS Gateway.\n\n## Safety model\n\nThe only accepted mutation input is a canonical, signed `ActionEnvelope`. It binds the exact target, parameters, observed resource version, preconditions, verification, compensation, risk, policy version, credential scope, idempotency key, and expiry.\n\nBefore a write starts, the system must verify:\n\n1. an exact service/environment mapping;\n2. a valid signature and immutable plan hash;\n3. current policy at plan, credential, and execution stages;\n4. non-self approval bound to the exact plan and live target state;\n5. a single-target, short-lived credential anchored before use and durably revoked after execution;\n6. all global, environment, connector, and action kill switches;\n7. target locking and the pilot-wide production concurrency limit;\n8. a fixed isolated executor that must be killed and reaped before release, followed by post-action verification or an `UNCERTAIN` state that retains the lock until reconciliation.\n\nSee the [security model and implementation blueprint](docs/architecture/implementation-blueprint-v3.md) for the complete contract.\n\n## Quick start\n\nRequirements:\n\n- Go 1.26.5\n- PostgreSQL 18.4 or newer 18.x for persistence and migration tests\n- Temporal, Keycloak, Vault, and S3-compatible storage for the intended production architecture\n\nRun the development control plane with its in-memory repository:\n\n```bash\nmake test\nmake vet\nmake build\nmake run\n```\n\nThen check:\n\n```text\nGET http://localhost:8080/healthz\nGET http://localhost:8080/readyz\nGET http://localhost:8080/api/v1/session\n```\n\nThe in-memory mode is for local development only. Production mode fails closed unless PostgreSQL, scoped webhook secrets, and Keycloak OIDC are configured. Copy [.env.example](.env.example) as a reference; never commit real credentials.\n\nTo run real PostgreSQL migration and repository tests:\n\n```bash\nmake postgres-local-check\nmake test-integration-local\n```\n\nThese targets use the workstation PostgreSQL 18.4 mTLS deployment without printing or committing its password. See [Local PostgreSQL 18.4 development](docs/operations/local-postgresql-development.md).\n\nWith Docker/BuildKit available, build the physically separate Runner images with:\n\n```bash\nmake runner-images\n```\n\nThe WRITE image defaults to `disabled`; M4 only performs a Linux isolation capability probe in `non-production` mode and still claims no jobs. See the [isolated Runner runtime gates](docs/operations/isolated-runner-runtime.md).\n\n## Documentation\n\n- [Documentation index](docs/README.md)\n- [Architecture overview](docs/architecture/overview.md)\n- [2026 V3 implementation blueprint](docs/architecture/implementation-blueprint-v3.md)\n- [SME internal pilot plan](docs/plans/2026-07-10-sme-internal-aiops-pilot.md)\n- [M4 isolated executor design](docs/plans/2026-07-11-isolated-executor-m4.md)\n- [Isolated Runner image and Linux runtime gates](docs/operations/isolated-runner-runtime.md)\n- [READ runtime Bundle and closed Admission](docs/operations/read-runtime-bundle.md)\n- [Roadmap and release gates](docs/roadmap.md)\n- [Historical designs](docs/archive/README.md)\n\n## Repository layout\n\n```text\ncmd/                       control-plane, worker, separate READ/WRITE runners, fixed executor\nbuild/package/             separate minimal READ and WRITE Runner image definitions\ninternal/                  domain, policy, connectors, investigation, execution\nmigrations/                ordered PostgreSQL schema migrations\ndocs/architecture/         current architecture and trust contracts\ndocs/plans/                executable delivery plans\ndocs/archive/              superseded designs kept for traceability\n.github/                   CI and community templates\n```\n\n## Contributing and security\n\nWe welcome design reviews, connector work, threat modeling, tests, documentation, and carefully scoped features. Start with [CONTRIBUTING.md](CONTRIBUTING.md) and open a proposal before large architectural changes.\n\nDo not report vulnerabilities in public issues. Follow [SECURITY.md](SECURITY.md) instead.\n\n## License\n\nLicensed under the [Apache License 2.0](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fseaworld008%2Faiops-system","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fseaworld008%2Faiops-system","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fseaworld008%2Faiops-system/lists"}