RCA Engine
This generates AI-powered root cause analysis reports. It parallelises signal collection from anomaly-detector, log-gateway, and incident-manager, builds a chronological timeline, and calls Claude Haiku to produce a structured RCA with root cause, contributing factors, and confidence score.
RCA Pipeline
POST /api/v1/rca { "incident_id": "inc-f4a1" }
1. Parallel fetch (goroutines):
├── anomaly-detector GET /api/v1/anomalies?limit=20
├── log-gateway GET /api/v1/logs/patterns?limit=20
└── incident-manager GET /api/v1/incidents/{incident_id}
2. Build chronological timeline string from all signals
3. Call Claude Haiku (claude-haiku-4-5-20251001)
→ system: "You are an SRE expert performing root cause analysis"
→ user: timeline + structured JSON response requirement
4. Parse JSON response:
{
"root_cause": "...",
"contributing_factors": [
{ "factor": "...", "confidence": 0.9, "evidence": "..." }
],
"confidence": 0.85
}
5. Persist RCAReport to PostgreSQL
6. Return RCAReport
Domain Model
RCAReport
├── id, incident_id
├── root_cause
├── contributing_factors: []CausalFactor
│ ├── factor, evidence
│ └── confidence: float64
├── confidence: float64
├── timeline (full signal text)
└── generated_at
ChangeEvent (operator-logged cluster changes)
├── id, cluster_id
├── type: deployment | config | scale | node
├── resource, namespace
├── description, author
└── occurred_at
REST API
| Method | Path | Description |
|---|---|---|
POST | /api/v1/rca | Generate RCA for an incident ({ "incident_id": "..." }) |
GET | /api/v1/rca/{id} | Retrieve a generated report by ID |
GET | /api/v1/changes | List change events (?cluster_id=&limit=) |
GET | /healthz | Health check |
Environment Variables
| Variable | Default | Description |
|---|---|---|
ANTHROPIC_API_KEY | — | Required for RCA generation |
DATABASE_URL | — | Optional — persists reports; returns without saving if unset |
ANOMALY_DETECTOR_BASE_URL | http://localhost:8088 | Signal source |
LOG_GATEWAY_BASE_URL | http://localhost:8099 | Signal source |
TRACING_GATEWAY_BASE_URL | http://localhost:8102 | Signal source (reserved for future use) |
INCIDENT_MANAGER_BASE_URL | http://localhost:8090 | Incident timeline source |
PORT | 8103 | HTTP port |