AI-SRE-Agent (Nika)
Ni (नि) — to investigate. Ka (क) — the one who does. "The one who investigates."
Autonomous AI SRE agent that monitors multi-account AWS infrastructure, performs real-time Root Cause Analysis when alerts fire, and posts findings directly to your incident channels. Learns from every investigation and engineer feedback.
Built for Vegapay — powering credit card and payment processing across 7 banking clients, 4 AWS accounts.
Architecture
┌────────────────────────────────────────────────────────────────────────┐
│ ALERT SOURCES (4 AWS Accounts) │
│ CloudWatch │ Prometheus │ PagerDuty │ Opsgenie │ Datadog │
└──────────────────────────────┬──────────────────────────────────────────┘
│ SNS → cross-account SQS
▼
┌──────────────────────────────────────────────────────────────────────────┐
│ Vegapay-AI Account (g5.xlarge EC2 Spot) │
│ │
│ ┌──────────┐ ┌──────────────┐ ┌──────────────┐ ┌───────────────┐ │
│ │ vLLM │ │ HolmesGPT │ │ Memory │ │ PostgreSQL │ │
│ │ Server │ │ + Slack Bot │ │ Worker │ │ + pgvector │ │
│ │ Qwen3.6 │ │ + Plugins │ │ │ │ │ │
│ │ 27B-AWQ │ │ │ │ │ │ │ │
│ └──────────┘ └──────────────┘ └──────────────┘ └───────────────┘ │
│ ┌────────────────────┐ ┌────────────────────────────────────────────┐ │
│ │ Embedder (CPU) │ │ RCA Dashboard (FastAPI) │ │
│ │ bge-base-en-v1.5 │ │ Browse/search/filter past investigations │ │
│ └────────────────────┘ └────────────────────────────────────────────┘ │
└────────────────────────────────┬────────────────────────────────────────┘
│ sts:AssumeRole (OIDC)
┌──────────────────┼──────────────────┐
▼ ▼ ▼
┌─────────────────┐ ┌──────────────┐ ┌──────────────────┐
│ Vegapay Prod │ │ SSFB │ │ Yes Bank / BOB │
│ (4 clients: │ │ (dedicated) │ │ (dedicated) │
│ Capri/Ebix/ │ └──────────────┘ └──────────────────┘
│ Scapia/Pahal) │
└─────────────────┘
Install
pip install nika
With Datadog support:
pip install nika[datadog]
Configuration
All config via environment variables (12-factor). Prefix: NIKA_.
Core
| Variable | Description | Default |
|---|---|---|
NIKA_DB_URL |
PostgreSQL connection (local or RDS/Cloud SQL) | postgresql://postgres:postgres@localhost:5432/ai_sre_memory |
NIKA_DB_SSL_MODE |
SSL mode (disable, prefer, require) |
prefer |
NIKA_DB_POOL_MAX |
Max DB connection pool size | 10 |
NIKA_REDIS_URL |
Redis URL (local or ElastiCache/Memorystore) | redis://localhost:6379/0 |
NIKA_REDIS_SSL |
Enable TLS for managed Redis | false |
NIKA_VLLM_BASE_URL |
vLLM server URL | http://localhost:8000/v1 |
NIKA_VLLM_MODEL |
Model name | Qwen/Qwen3.6-27B-AWQ |
NIKA_EMBEDDER_URL |
Embedding service URL | http://localhost:8081 |
Infrastructure-agnostic: Every dependency is a connection string. Use self-hosted containers, managed services (RDS, ElastiCache, Cloud SQL), or any mix. See docs/deployment.md for configuration examples.
Slack (Primary)
| Variable | Description |
|---|---|
NIKA_SLACK_BOT_TOKEN |
Bot token (xoxb-...) |
NIKA_SLACK_APP_TOKEN |
App token (xapp-...) for Socket Mode |
NIKA_SLACK_DEFAULT_CHANNEL |
Default channel for RCAs |
Microsoft Teams
| Variable | Description |
|---|---|
NIKA_TEAMS_WEBHOOK_URL |
Incoming Webhook URL |
NIKA_TEAMS_ENABLED |
Enable Teams notifications (true/false) |
PagerDuty
| Variable | Description |
|---|---|
NIKA_PAGERDUTY_ROUTING_KEY |
Events API v2 routing key |
NIKA_PAGERDUTY_API_KEY |
REST API key (for notes/updates) |
NIKA_PAGERDUTY_ENABLED |
Enable PagerDuty (true/false) |
Opsgenie
| Variable | Description |
|---|---|
NIKA_OPSGENIE_API_KEY |
Opsgenie API key |
NIKA_OPSGENIE_TEAM |
Default responder team |
NIKA_OPSGENIE_ENABLED |
Enable Opsgenie (true/false) |
Datadog Collector
| Variable | Description |
|---|---|
NIKA_DATADOG_API_KEY |
Datadog API key |
NIKA_DATADOG_APP_KEY |
Datadog Application key |
NIKA_DATADOG_SITE |
Datadog site (default: datadoghq.com) |
NIKA_DATADOG_ENABLED |
Enable Datadog polling (true/false) |
Bedrock Fallback (P1 only)
| Variable | Description | Default |
|---|---|---|
NIKA_BEDROCK_MODEL |
Claude model ID | anthropic.claude-sonnet-4-20250514-v1:0 |
NIKA_BEDROCK_REGION |
AWS region for Bedrock | us-east-1 |
NIKA_BEDROCK_TRIGGER_SEVERITY |
Min severity to trigger Bedrock | P1 |
Accounts (YAML)
# config/accounts.yaml
accounts:
- id: "111111111111"
name: "vegapay-prod"
type: "shared-cluster"
role_arn: "arn:aws:iam::111111111111:role/ai-sre-readonly-role"
region: "ap-south-1"
clients:
- name: "capri"
label_selector: "vegapay.io/client=capri"
service_prefix: "capri-"
slack_channel: "#oncall-support"
l1_team: "@payments-capri"
l2_poc: "@capri-client-devops"
# ... more clients
- id: "222222222222"
name: "ssfb-prod"
type: "dedicated"
role_arn: "arn:aws:iam::222222222222:role/ai-sre-readonly-role"
region: "ap-south-1"
slack_channel: "#oncall-support"
l1_team: "@payments-ssfb"
l2_poc: "@ssfb-client-devops"
Plugin System
Notification Targets
All targets implement NotificationTarget — post RCA reports and follow-up messages.
| Plugin | Transport | Features |
|---|---|---|
| Slack (built-in) | Bolt WebSocket | Thread replies, reactions, feedback loop |
| Teams | Incoming Webhook | Adaptive Cards, severity coloring |
| PagerDuty | Events API v2 | Trigger/ack/resolve, severity mapping |
| Opsgenie | Alerts API v2 | Create/note/close, team routing |
Alert Collectors
All collectors implement AlertCollector — poll for alerts and fetch metrics.
| Plugin | Source | Capabilities |
|---|---|---|
| CloudWatch (built-in) | SNS → SQS | Cross-account, alarm metadata |
| Prometheus (built-in) | AlertManager webhook | Label-based routing |
| Datadog | API v1/v2 | Monitor polling, metric query, event correlation |
Writing a Plugin
from nika.plugins import NotificationTarget
from nika.core.models import RCAReport
class MyTarget(NotificationTarget):
name = "my-target"
async def send_rca(self, report: RCAReport) -> str | None:
# Post the RCA, return thread/incident ID
...
async def send_followup(self, thread_id: str, message: str) -> None:
# Post follow-up to existing thread
...
async def healthcheck(self) -> bool:
# Return True if connection is working
...
Project Structure
AI-SRE-Agent/
├── src/nika/
│ ├── __init__.py
│ ├── core/
│ │ ├── config.py # Pydantic settings, account loading
│ │ └── models.py # Alert, Investigation, RCAReport
│ ├── plugins/
│ │ ├── __init__.py # Base classes: NotificationTarget, AlertCollector
│ │ ├── targets/
│ │ │ ├── teams.py # Microsoft Teams (Adaptive Cards)
│ │ │ ├── pagerduty.py # PagerDuty Events API v2
│ │ │ └── opsgenie.py # Opsgenie Alerts API v2
│ │ └── collectors/
│ │ └── datadog.py # Datadog monitor polling + metrics
│ ├── investigation/ # HolmesGPT integration, query planner
│ └── memory/ # Episodic, semantic, procedural memory
├── services/
│ ├── memory-worker/
│ │ ├── main.py # Background: extraction, decay, archive
│ │ └── Dockerfile
│ └── rca-dashboard/
│ ├── app.py # FastAPI: browse/search investigations
│ └── Dockerfile
├── tests/
│ ├── unit/
│ │ ├── test_models.py
│ │ ├── test_targets.py
│ │ └── test_datadog.py
│ └── integration/
├── .github/workflows/
│ ├── ci.yml # Lint + test + docker build on push/PR
│ └── release.yml # PyPI + GHCR publish on tag
├── config/
│ └── accounts.yaml # Multi-account configuration
├── pyproject.toml
├── DESIGN.md # Full system design document
└── README.md
CI/CD
Continuous Integration (.github/workflows/ci.yml)
Triggers on push to main and PRs:
- Lint —
ruff check src/ tests/ - Type check —
mypy src/nika/ - Test —
pytest tests/ -v --cov=nika(Python 3.11 + 3.12 matrix) - Docker build — validates both Dockerfiles build cleanly
Release (.github/workflows/release.yml)
Triggers on tag push (v*):
- Test — full test suite gate
- PyPI — trusted publishing (OIDC, no API key)
- GHCR — builds and pushes container images:
ghcr.io/<owner>/nika-memory-worker:<version>ghcr.io/<owner>/nika-rca-dashboard:<version>
Releasing
# Bump version in pyproject.toml, then:
git tag v0.1.0
git push --tags
# CI handles PyPI + GHCR automatically
Development
# Clone and install
git clone https://github.com/vegapay/ai-sre-agent.git
cd ai-sre-agent
# Using uv (recommended)
uv run --extra dev pytest tests/ -v
# Or manually
python3.11 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
pytest tests/ -v -m "not integration"
Running Lint + Type Checks
uv run --extra dev ruff check src/ tests/
uv run --extra dev mypy src/nika/ --ignore-missing-imports
Security Model
- Read-only access — explicit IAM Deny on all write actions across all spoke accounts
- Credential isolation — each account investigation gets its own temporary STS credentials (1hr TTL)
- No credential sharing — multi-account aggregation only sees text findings, never holds multiple credential sets
- Zero-trust — no Confluence/wiki access, no SSH to prod instances, no kubectl exec
- Compliance archive — every investigation archived to S3 (KMS-encrypted, 2-year retention)
Cost
| Component | Monthly | Notes |
|---|---|---|
| EC2 g5.xlarge (Spot) | ~$230 | A10G 24GB GPU |
| EBS (100GB gp3) | ~$30 | Model weights + DB |
| S3 archive | ~$2 | 10K RCAs/month |
| Bedrock Claude (P1 only) | ~$20 | ~5-10 P1 incidents/month |
| Total | ~$290/month |
License
Apache-2.0
Release files for nika 0.2.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nika-0.2.5.tar.gz | 1.0 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nika-0.2.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.1 MB
Release files / nika-0.2.5.tar.gz
| Download URL | nika-0.2.5.tar.gz |
|---|---|
| Size | 1.0 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5454d7253e391504825f48960d136021a78a3a4b2d1b48bc1f8c87b86449f625
|
|
BLAKE2b-256 checksum How to use checksums |
d5861050eec91a657f2e59f03245bc96b4a7420589c9f2b781723414bb463840
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.
Transparency logRelease files / nika-0.2.5-py3-none-any.whl
| Download URL | nika-0.2.5-py3-none-any.whl |
|---|---|
| Size | 100.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c2aa99c9e5de12479a4776b741f884ad7fac5d640a5c1f82aecf5eceb62fac44
|
|
BLAKE2b-256 checksum How to use checksums |
2c9031e8f423dcc339050718cb8795026a373716731e5daa1d677b4c6e2e5bb4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.
Transparency log