Skip to main content
Version: 2.0

RCA Engine

Service: rca-engine · Port: 8103 · Database schema: rca

rca-engine answers "why did this happen?" for an incident. It gathers every relevant signal in parallel — anomalies, log patterns, slow and failing traces, recent changes and the incident's own timeline — puts them in order, and asks Claude for a structured root-cause analysis with contributing factors, evidence and a confidence score.

RCA reports appear on the incident, feed post-incident reviews, and are available to agents through the get_rca_analysis tool.

How an analysis runs​

POST /api/v1/rca  { "incident_id": "inc-f4a1" }

1. Gather signals in parallel, for the incident's cluster, namespace and time window:
├── anomaly-detector anomalies
├── log-gateway log patterns and their changes
├── tracing-gateway slow and failing traces
├── cicd-gateway deploys and pipeline runs (change events)
└── incident-manager the incident and its timeline

2. Build one chronological timeline from every signal.

3. Ask Claude for a structured analysis:
{
"root_cause": "…",
"contributing_factors": [
{ "factor": "…", "confidence": 0.9, "evidence": "…" }
],
"confidence": 0.85
}

4. Store the report and attach it to the incident.

Changes are the most common root cause, so rca-engine pays special attention to change events — deploys, configuration changes, scaling and node events — close to when the problem began.

Domain model​

RCAReport
├── id, incident_id, tenant_id
├── root_cause
├── contributing_factors: []{ factor, evidence, confidence }
├── confidence
├── timeline
└── generated_at

ChangeEvent
├── id, cluster_id
├── type: deployment | config | scale | node
├── resource, namespace, description, author
└── occurred_at

Change events are recorded automatically from cicd.events, nodes.events and app changes in kubeopera-api; you can also log changes made outside KubeOpera through the API.

REST API​

MethodPathDescription
POST/api/v1/rcaAnalyze an incident ({ "incident_id": "…" }).
GET/api/v1/rca/{id}A report.
GET/api/v1/incidents/{incident_id}/rcaThe latest report for an incident.
GET · POST/api/v1/changesList (?cluster_id=&limit=) or record change events.
GET/healthzHealth check.

Configuration​

VariableDefaultDescription
DATABASE_URL—PostgreSQL connection.
RABBITMQ_URL—Records change events from the platform.
ANOMALY_DETECTOR_BASE_URLhttp://anomaly-detector:8088Signal source.
LOG_GATEWAY_BASE_URLhttp://log-gateway:8099Signal source.
TRACING_GATEWAY_BASE_URLhttp://tracing-gateway:8102Signal source.
INCIDENT_MANAGER_BASE_URLhttp://incident-manager:8090Incident timelines.
AUTH_SERVICE_BASE_URL / AI_CREDENTIAL_INTERNAL_API_KEY—AI credential resolution.
PORT8103HTTP port.