Skip to main content

chainlog-ai

chainlog-ai answers one question: why did my infrastructure fail?

It reads the logs an operator already has — execution clients, consensus clients, validators, and Kubernetes — and returns a cause that cites those lines. The case stays on the machine. A model is optional, and it only sees redacted excerpts.

chainlog-ai does not restart a client, edit a manifest, scrape a cluster, or sign with a validator key.

Work is tracked in milestones. This tree is the 0.2.0 shell: chainlog-ai --version is the command that exists today.

Command

Question Command
Read logs into a local case ingest
Which failure classes are present? classify
What happened, in order? timeline
Why did it fail? why
Has this happened before? patterns
What should I check next? ask
Write the report report

why can take a case id, or the same files as ingest. It classifies, builds the timeline, and states a cause.

chainlog-ai ingest \
  --execution /var/log/geth/geth.log \
  --consensus /var/log/lighthouse/beacon.log \
  --validator /var/log/lighthouse/validator.log \
  --builder /var/log/mev-boost.log \
  --kube /tmp/events.json

chainlog-ai why --case 20261008T061200Z
chainlog-ai ask --case 20261008T061200Z "what happened in the slot before the miss?"
chainlog-ai report --case 20261008T061200Z

Exit 0 means a cause is stated and every claim cites a timeline row. Exit 1 means the evidence is not enough. Exit 3 is a usage error or an unreadable input.

What a cause is allowed to say

A cause cites timeline rows: time, source, and the redacted line. The report separates three things:

  • Trigger — the earliest cited class that explains what followed.
  • Contributors — cited conditions that made it worse, such as disk pressure before a database error.
  • Symptoms — later misses, restarts, or probe failures that the trigger explains.

A symptom is never printed as the trigger. A class is applied only when a catalog rule matches, and every rule has a source. An unmatched line stays unclassified. When the lines do not support a cause, why says so and names what is missing.

A doppelganger detection or a slashable duty is printed first, even when an earlier warning exists in the window.

Sources

Source Clients and objects What it explains
Execution Geth, Nethermind, Erigon, Besu, Reth Sync, database, engine API, peers, disk, JWT
Consensus Lighthouse, Prysm, Teku, Nimbus, Lodestar Slots, fork choice, checkpoints, engine calls
Validator Validator clients, Web3Signer Missed duties, doppelganger, signer timeouts
Builder MEV-boost Relay and builder timeouts on a proposal
Kubernetes Container logs, cluster events OOM, eviction, probes, volume mounts, node pressure

Slot, epoch, and block are taken from the line that prints them. A slot filled in from a nearby consensus line is marked inferred. When two consensus lines disagree, the slot stays blank.

Around the failure

An alert can open the case. A ValidatorPulse or Prometheus alert sets the window: one hour before it fired, and fifteen minutes after. A metric snapshot for that window can support a contributor: disk, memory, restarts, peer count, head lag, attestation effectiveness.

chainlog-ai reads the snapshot the operator exports. ValidatorPulse remains the monitor that raises the alert. ChainDiff remains the tool that decides whether a client upgrade is safe. chainlog-ai records the version change and stops there.

A pattern exported for another host contains class ids, client, version, and the order of classes. It contains no log lines and no host names.

Where a case lives

Cases are written under ~/.chainlog-ai, or CHAINLOG_AI_HOME when that is set. The case stores redacted excerpts and citations. The raw files stay at the paths the operator passed.

Redaction removes private keys, mnemonics, keystore passwords, JWT secrets, and API tokens before the case is written and before any model sees text. Validator pubkeys and peer ids stay, because the timeline joins on them. A removed span is marked.

ask answers from the case. With no model configured, it answers from the cause and the sourced runbook. --remote is off unless that invocation sets it, and the command prints that a remote call is about to happen. If redaction did not run, the remote call is refused.

Report

report writes markdown and JSON: cause, trigger, contributors, symptoms, the last healthy slot, the first bad slot, citations, and the pattern note. --no-paths drops local file paths. --bundle writes the redacted citations, the signature, and a hash. --verify checks that hash later.

Install

pip install chainlog-ai

The package is published from a GitHub release. Python 3.11 or newer. The command is chainlog-ai.

chainlog-ai --version

Limits

chainlog-ai explains a failure from evidence the operator provides. It does not fetch logs from a cluster API, apply a fix, or decide that a release is safe to run.

Metadata

Release files for chainlog-ai 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for chainlog-ai 0.2.0
File Size Uploaded
chainlog_ai-0.2.0.tar.gz 5.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for chainlog-ai 0.2.0
File Interpreter ABI Platform
chainlog_ai-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 11.2 kB

Release files / chainlog_ai-0.2.0.tar.gz

Download URL chainlog_ai-0.2.0.tar.gz
Size 5.5 kB
Tags Source
SHA-256 checksum
How to use checksums
28b231773d25ebf851265abc36b626c059d78d8d3ff734a68a5c7eae4d236cee
BLAKE2b-256 checksum
How to use checksums
e822d6c4cf69eb696bb4e4366feb4bd856f3d027c763a36f70125eacac317e59
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / chainlog_ai-0.2.0-py3-none-any.whl

Download URL chainlog_ai-0.2.0-py3-none-any.whl
Size 5.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7a04146f6d967f58b922d76ff6028445c0bbb5668907933a5000fc9be98660e6
BLAKE2b-256 checksum
How to use checksums
c6ff054d478e8d367a97212234fb11b3fb450ad88926b5ea016ddd74d8789436
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page