Skip to main content

AI-SRE-Agent (Nika)

Ni (नि) — to investigate. Ka (क) — the one who does. "The one who investigates."

Autonomous AI SRE agent that monitors multi-account AWS infrastructure, performs real-time Root Cause Analysis when alerts fire, and posts findings directly to your incident channels. Learns from every investigation and engineer feedback.

Built for Vegapay — powering credit card and payment processing across 7 banking clients, 4 AWS accounts.


Architecture

┌────────────────────────────────────────────────────────────────────────┐
│                    ALERT SOURCES (4 AWS Accounts)                        │
│  CloudWatch │ Prometheus │ PagerDuty │ Opsgenie │ Datadog               │
└──────────────────────────────┬──────────────────────────────────────────┘
                               │ SNS → cross-account SQS
                               ▼
┌──────────────────────────────────────────────────────────────────────────┐
│              Vegapay-AI Account (g5.xlarge EC2 Spot)                       │
│                                                                           │
│  ┌──────────┐  ┌──────────────┐  ┌──────────────┐  ┌───────────────┐   │
│  │  vLLM    │  │  HolmesGPT   │  │ Memory       │  │  PostgreSQL   │   │
│  │  Server  │  │  + Slack Bot  │  │ Worker       │  │  + pgvector   │   │
│  │ Qwen3.6  │  │  + Plugins   │  │              │  │               │   │
│  │ 27B-AWQ  │  │              │  │              │  │               │   │
│  └──────────┘  └──────────────┘  └──────────────┘  └───────────────┘   │
│  ┌────────────────────┐  ┌────────────────────────────────────────────┐ │
│  │ Embedder (CPU)     │  │ RCA Dashboard (FastAPI)                     │ │
│  │ bge-base-en-v1.5   │  │ Browse/search/filter past investigations   │ │
│  └────────────────────┘  └────────────────────────────────────────────┘ │
└────────────────────────────────┬────────────────────────────────────────┘
                                 │ sts:AssumeRole (OIDC)
              ┌──────────────────┼──────────────────┐
              ▼                  ▼                  ▼
    ┌─────────────────┐ ┌──────────────┐ ┌──────────────────┐
    │ Vegapay Prod     │ │ SSFB         │ │ Yes Bank / BOB   │
    │ (4 clients:      │ │ (dedicated)  │ │ (dedicated)      │
    │ Capri/Ebix/      │ └──────────────┘ └──────────────────┘
    │ Scapia/Pahal)    │
    └─────────────────┘

Install

pip install nika

With Datadog support:

pip install nika[datadog]

Configuration

All config via environment variables (12-factor). Prefix: NIKA_.

Core

Variable Description Default
NIKA_DB_URL PostgreSQL connection (local or RDS/Cloud SQL) postgresql://postgres:postgres@localhost:5432/ai_sre_memory
NIKA_DB_SSL_MODE SSL mode (disable, prefer, require) prefer
NIKA_DB_POOL_MAX Max DB connection pool size 10
NIKA_REDIS_URL Redis URL (local or ElastiCache/Memorystore) redis://localhost:6379/0
NIKA_REDIS_SSL Enable TLS for managed Redis false
NIKA_VLLM_BASE_URL vLLM server URL http://localhost:8000/v1
NIKA_VLLM_MODEL Model name Qwen/Qwen3.6-27B-AWQ
NIKA_EMBEDDER_URL Embedding service URL http://localhost:8081

Infrastructure-agnostic: Every dependency is a connection string. Use self-hosted containers, managed services (RDS, ElastiCache, Cloud SQL), or any mix. See docs/deployment.md for configuration examples.

Slack (Primary)

Variable Description
NIKA_SLACK_BOT_TOKEN Bot token (xoxb-...)
NIKA_SLACK_APP_TOKEN App token (xapp-...) for Socket Mode
NIKA_SLACK_DEFAULT_CHANNEL Default channel for RCAs

Microsoft Teams

Variable Description
NIKA_TEAMS_WEBHOOK_URL Incoming Webhook URL
NIKA_TEAMS_ENABLED Enable Teams notifications (true/false)

PagerDuty

Variable Description
NIKA_PAGERDUTY_ROUTING_KEY Events API v2 routing key
NIKA_PAGERDUTY_API_KEY REST API key (for notes/updates)
NIKA_PAGERDUTY_ENABLED Enable PagerDuty (true/false)

Opsgenie

Variable Description
NIKA_OPSGENIE_API_KEY Opsgenie API key
NIKA_OPSGENIE_TEAM Default responder team
NIKA_OPSGENIE_ENABLED Enable Opsgenie (true/false)

Datadog Collector

Variable Description
NIKA_DATADOG_API_KEY Datadog API key
NIKA_DATADOG_APP_KEY Datadog Application key
NIKA_DATADOG_SITE Datadog site (default: datadoghq.com)
NIKA_DATADOG_ENABLED Enable Datadog polling (true/false)

Bedrock Fallback (P1 only)

Variable Description Default
NIKA_BEDROCK_MODEL Claude model ID anthropic.claude-sonnet-4-20250514-v1:0
NIKA_BEDROCK_REGION AWS region for Bedrock us-east-1
NIKA_BEDROCK_TRIGGER_SEVERITY Min severity to trigger Bedrock P1

Accounts (YAML)

# config/accounts.yaml
accounts:
  - id: "111111111111"
    name: "vegapay-prod"
    type: "shared-cluster"
    role_arn: "arn:aws:iam::111111111111:role/ai-sre-readonly-role"
    region: "ap-south-1"
    clients:
      - name: "capri"
        label_selector: "vegapay.io/client=capri"
        service_prefix: "capri-"
        slack_channel: "#oncall-support"
        l1_team: "@payments-capri"
        l2_poc: "@capri-client-devops"
      # ... more clients

  - id: "222222222222"
    name: "ssfb-prod"
    type: "dedicated"
    role_arn: "arn:aws:iam::222222222222:role/ai-sre-readonly-role"
    region: "ap-south-1"
    slack_channel: "#oncall-support"
    l1_team: "@payments-ssfb"
    l2_poc: "@ssfb-client-devops"

Plugin System

Notification Targets

All targets implement NotificationTarget — post RCA reports and follow-up messages.

Plugin Transport Features
Slack (built-in) Bolt WebSocket Thread replies, reactions, feedback loop
Teams Incoming Webhook Adaptive Cards, severity coloring
PagerDuty Events API v2 Trigger/ack/resolve, severity mapping
Opsgenie Alerts API v2 Create/note/close, team routing

Alert Collectors

All collectors implement AlertCollector — poll for alerts and fetch metrics.

Plugin Source Capabilities
CloudWatch (built-in) SNS → SQS Cross-account, alarm metadata
Prometheus (built-in) AlertManager webhook Label-based routing
Datadog API v1/v2 Monitor polling, metric query, event correlation

Writing a Plugin

from nika.plugins import NotificationTarget
from nika.core.models import RCAReport

class MyTarget(NotificationTarget):
    name = "my-target"

    async def send_rca(self, report: RCAReport) -> str | None:
        # Post the RCA, return thread/incident ID
        ...

    async def send_followup(self, thread_id: str, message: str) -> None:
        # Post follow-up to existing thread
        ...

    async def healthcheck(self) -> bool:
        # Return True if connection is working
        ...

Project Structure

AI-SRE-Agent/
├── src/nika/
│   ├── __init__.py
│   ├── core/
│   │   ├── config.py              # Pydantic settings, account loading
│   │   └── models.py              # Alert, Investigation, RCAReport
│   ├── plugins/
│   │   ├── __init__.py            # Base classes: NotificationTarget, AlertCollector
│   │   ├── targets/
│   │   │   ├── teams.py           # Microsoft Teams (Adaptive Cards)
│   │   │   ├── pagerduty.py       # PagerDuty Events API v2
│   │   │   └── opsgenie.py        # Opsgenie Alerts API v2
│   │   └── collectors/
│   │       └── datadog.py         # Datadog monitor polling + metrics
│   ├── investigation/             # HolmesGPT integration, query planner
│   └── memory/                    # Episodic, semantic, procedural memory
├── services/
│   ├── memory-worker/
│   │   ├── main.py                # Background: extraction, decay, archive
│   │   └── Dockerfile
│   └── rca-dashboard/
│       ├── app.py                 # FastAPI: browse/search investigations
│       └── Dockerfile
├── tests/
│   ├── unit/
│   │   ├── test_models.py
│   │   ├── test_targets.py
│   │   └── test_datadog.py
│   └── integration/
├── .github/workflows/
│   ├── ci.yml                     # Lint + test + docker build on push/PR
│   └── release.yml                # PyPI + GHCR publish on tag
├── config/
│   └── accounts.yaml              # Multi-account configuration
├── pyproject.toml
├── DESIGN.md                      # Full system design document
└── README.md

CI/CD

Continuous Integration (.github/workflows/ci.yml)

Triggers on push to main and PRs:

  1. Lint — ruff check src/ tests/
  2. Type check — mypy src/nika/
  3. Test — pytest tests/ -v --cov=nika (Python 3.11 + 3.12 matrix)
  4. Docker build — validates both Dockerfiles build cleanly

Release (.github/workflows/release.yml)

Triggers on tag push (v*):

  1. Test — full test suite gate
  2. PyPI — trusted publishing (OIDC, no API key)
  3. GHCR — builds and pushes container images:
    • ghcr.io/<owner>/nika-memory-worker:<version>
    • ghcr.io/<owner>/nika-rca-dashboard:<version>

Releasing

# Bump version in pyproject.toml, then:
git tag v0.1.0
git push --tags
# CI handles PyPI + GHCR automatically

Development

# Clone and install
git clone https://github.com/vegapay/ai-sre-agent.git
cd ai-sre-agent

# Using uv (recommended)
uv run --extra dev pytest tests/ -v

# Or manually
python3.11 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
pytest tests/ -v -m "not integration"

Running Lint + Type Checks

uv run --extra dev ruff check src/ tests/
uv run --extra dev mypy src/nika/ --ignore-missing-imports

Security Model

  • Read-only access — explicit IAM Deny on all write actions across all spoke accounts
  • Credential isolation — each account investigation gets its own temporary STS credentials (1hr TTL)
  • No credential sharing — multi-account aggregation only sees text findings, never holds multiple credential sets
  • Zero-trust — no Confluence/wiki access, no SSH to prod instances, no kubectl exec
  • Compliance archive — every investigation archived to S3 (KMS-encrypted, 2-year retention)

Cost

Component Monthly Notes
EC2 g5.xlarge (Spot) ~$230 A10G 24GB GPU
EBS (100GB gp3) ~$30 Model weights + DB
S3 archive ~$2 10K RCAs/month
Bedrock Claude (P1 only) ~$20 ~5-10 P1 incidents/month
Total ~$290/month

License

Apache-2.0

Release files for nika 0.2.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for nika 0.2.5
File Size Uploaded
nika-0.2.5.tar.gz 1.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for nika 0.2.5
File Interpreter ABI Platform
nika-0.2.5-py3-none-any.whl Python 3 none any Details

Total release size: 1.1 MB

Release files / nika-0.2.5.tar.gz

Download URL nika-0.2.5.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
5454d7253e391504825f48960d136021a78a3a4b2d1b48bc1f8c87b86449f625
BLAKE2b-256 checksum
How to use checksums
d5861050eec91a657f2e59f03245bc96b4a7420589c9f2b781723414bb463840
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.

Transparency log

Release files / nika-0.2.5-py3-none-any.whl

Download URL nika-0.2.5-py3-none-any.whl
Size 100.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c2aa99c9e5de12479a4776b741f884ad7fac5d640a5c1f82aecf5eceb62fac44
BLAKE2b-256 checksum
How to use checksums
2c9031e8f423dcc339050718cb8795026a373716731e5daa1d677b4c6e2e5bb4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.5 This release

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page