RCA Engine
Service: rca-engine · Port: 8103 · Database schema: rca
rca-engine answers "why did this happen?" for an incident. It gathers every relevant signal in parallel — anomalies, log patterns, slow and failing traces, recent changes and the incident's own timeline — puts them in order, and asks Claude for a structured root-cause analysis with contributing factors, evidence and a confidence score.
RCA reports appear on the incident, feed post-incident reviews, and are available to agents through the get_rca_analysis tool.
How an analysis runs
POST /api/v1/rca { "incident_id": "inc-f4a1" }
1. Gather signals in parallel, for the incident's cluster, namespace and time window:
├── anomaly-detector anomalies
├── log-gateway log patterns and their changes
├── tracing-gateway slow and failing traces
├── cicd-gateway deploys and pipeline runs (change events)
└── incident-manager the incident and its timeline
2. Build one chronological timeline from every signal.
3. Ask Claude for a structured analysis:
{
"root_cause": "…",
"contributing_factors": [
{ "factor": "…", "confidence": 0.9, "evidence": "…" }
],
"confidence": 0.85
}
4. Store the report and attach it to the incident.
Changes are the most common root cause, so rca-engine pays special attention to change events — deploys, configuration changes, scaling and node events — close to when the problem began.
Domain model
RCAReport
├── id, incident_id, tenant_id
├── root_cause
├── contributing_factors: []{ factor, evidence, confidence }
├── confidence
├── timeline
└── generated_at
ChangeEvent
├── id, cluster_id
├── type: deployment | config | scale | node
├── resource, namespace, description, author
└── occurred_at
Change events are recorded automatically from cicd.events, nodes.events and app changes in kubeopera-api; you can also log changes made outside KubeOpera through the API.
REST API
| Method | Path | Description |
|---|---|---|
POST | /api/v1/rca | Analyze an incident ({ "incident_id": "…" }). |
GET | /api/v1/rca/{id} | A report. |
GET | /api/v1/incidents/{incident_id}/rca | The latest report for an incident. |
GET · POST | /api/v1/changes | List (?cluster_id=&limit=) or record change events. |
GET | /healthz | Health check. |
Configuration
| Variable | Default | Description |
|---|---|---|
DATABASE_URL | — | PostgreSQL connection. |
RABBITMQ_URL | — | Records change events from the platform. |
ANOMALY_DETECTOR_BASE_URL | http://anomaly-detector:8088 | Signal source. |
LOG_GATEWAY_BASE_URL | http://log-gateway:8099 | Signal source. |
TRACING_GATEWAY_BASE_URL | http://tracing-gateway:8102 | Signal source. |
INCIDENT_MANAGER_BASE_URL | http://incident-manager:8090 | Incident timelines. |
AUTH_SERVICE_BASE_URL / AI_CREDENTIAL_INTERNAL_API_KEY | — | AI credential resolution. |
PORT | 8103 | HTTP port. |