Skip to main content
Version: 1.0

RCA Engine

This generates AI-powered root cause analysis reports. It parallelises signal collection from anomaly-detector, log-gateway, and incident-manager, builds a chronological timeline, and calls Claude Haiku to produce a structured RCA with root cause, contributing factors, and confidence score.

RCA Pipeline​

POST /api/v1/rca  { "incident_id": "inc-f4a1" }

1. Parallel fetch (goroutines):
├── anomaly-detector GET /api/v1/anomalies?limit=20
├── log-gateway GET /api/v1/logs/patterns?limit=20
└── incident-manager GET /api/v1/incidents/{incident_id}

2. Build chronological timeline string from all signals

3. Call Claude Haiku (claude-haiku-4-5-20251001)
→ system: "You are an SRE expert performing root cause analysis"
→ user: timeline + structured JSON response requirement

4. Parse JSON response:
{
"root_cause": "...",
"contributing_factors": [
{ "factor": "...", "confidence": 0.9, "evidence": "..." }
],
"confidence": 0.85
}

5. Persist RCAReport to PostgreSQL
6. Return RCAReport

Domain Model​

RCAReport
├── id, incident_id
├── root_cause
├── contributing_factors: []CausalFactor
│ ├── factor, evidence
│ └── confidence: float64
├── confidence: float64
├── timeline (full signal text)
└── generated_at

ChangeEvent (operator-logged cluster changes)
├── id, cluster_id
├── type: deployment | config | scale | node
├── resource, namespace
├── description, author
└── occurred_at

REST API​

MethodPathDescription
POST/api/v1/rcaGenerate RCA for an incident ({ "incident_id": "..." })
GET/api/v1/rca/{id}Retrieve a generated report by ID
GET/api/v1/changesList change events (?cluster_id=&limit=)
GET/healthzHealth check

Environment Variables​

VariableDefaultDescription
ANTHROPIC_API_KEY—Required for RCA generation
DATABASE_URL—Optional — persists reports; returns without saving if unset
ANOMALY_DETECTOR_BASE_URLhttp://localhost:8088Signal source
LOG_GATEWAY_BASE_URLhttp://localhost:8099Signal source
TRACING_GATEWAY_BASE_URLhttp://localhost:8102Signal source (reserved for future use)
INCIDENT_MANAGER_BASE_URLhttp://localhost:8090Incident timeline source
PORT8103HTTP port