Skip to main content

DevOps Sentinel

Python 3.10+ License: MIT

Local-first SRE CLI for HTTP health checks, thresholded incidents, and postmortems.

This is a command-line tool you install with pip. The website is documentation plus a live 503 demo for that CLI — not a hosted control plane. Sentinel does not store your data.

Source: github.com/jagadeepmamidi/devops-sentinel · Package: devops-sentinel-next on PyPI · Site: devops-sentinel-seven.vercel.app

What it is today

Shipped Optional Not shipped
sentinel init / local SQLite Bring-your-own Supabase Hosted SaaS / account wall
HTTP health checks (health, monitor, up) Slack webhook on incident open CrewAI / live multi-agent runtime
Failure and recovery thresholds LLM postmortem when you set a key Autonomous remediation that mutates infra
Local detect+diagnose (diag= model= anomaly= on every check) MCP (pip install "...[mcp]") Model-opened incidents or auto-restart
Incident open/resolve + event timeline sentinel serve operator API (localhost) Transactional outbox / Kafka / FAISS
Labeled template postmortems

The website (web/) is a Vite SPA: docs, a live failing-endpoint demo, a BYO-Supabase auth helper, and an optional operator UI that talks to your sentinel serve process.

Quick start

pip install devops-sentinel-next
sentinel init
sentinel demo
sentinel health https://api.example.com/health
sentinel services add production-api https://api.example.com/health
sentinel services list
sentinel incidents list

sentinel init defaults to local mode:

  • Data: .sentinel/sentinel.db in the initialized project
  • Identity: local@localhost
  • Login: not required
  • API server: not required for CLI monitoring
  • AI and Slack: optional
sentinel whoami
sentinel config
sentinel doctor
sentinel demo
sentinel up --once
sentinel monitor https://api.example.com/health --failure-threshold 3
sentinel health https://api.example.com/health --expect 200 --json-path status --ssl-min-days 14
sentinel postmortem generate <incident-id> --output postmortem.md

Commit sentinel.yaml (written by sentinel init) and run sentinel up to register those services. Example: examples/sentinel.yaml.

Optional richer checks on health and monitor: --expect status codes, --body substring, --json-path / --json-equals, --ssl-min-days. When a monitor opens an incident it prints a card with incidents show, ack, and postmortem generate.

Run sentinel init --mode supabase only when using your Supabase project. Sentinel does not host customer data.

sentinel init --mode supabase --url https://YOUR-PROJECT.supabase.co
sentinel schema --print   # paste into your SQL editor
sentinel login            # authenticates against YOUR project
sentinel supabase doctor  # URL, anon key, REST, tables, RLS

Configuration

.env is loaded from the current project directory. Provider keys can also be stored in a user-level file:

sentinel config set openrouter_api_key
sentinel config set openai_api_key
sentinel config list
sentinel config remove openrouter_api_key

config set prompts with hidden input and stores values in ~/.sentinel/config.json with restrictive permissions. Process variables and project .env values take precedence. sentinel config always masks secrets. Local mode needs no login.

sentinel postmortem generate calls OpenRouter (or OpenAI) when a key is present. Default model is openai/gpt-4o-mini with SENTINEL_LLM_MAX_TOKENS=1024. If the model call fails, the CLI writes the local template and says so (yellow stderr plus a footer in the markdown). The HTTP generate endpoint returns source and fallback_reason so a template report is never presented as AI-authored.

sentinel monitor https://… auto-registers the URL so failure thresholds persist incidents. --notify posts SLACK_WEBHOOK_URL when an incident opens.

sentinel serve binds 127.0.0.1 by default. In local mode /api/services and /api/incidents do not require a bearer token — that is intentional for localhost. Binding 0.0.0.0 (Docker/Render, or --host 0.0.0.0) prints a warning; do not expose that API to the public internet without auth.

SENTINEL_MODE=local
SENTINEL_DATA_DIR=.sentinel
OPENROUTER_API_KEY=
SLACK_WEBHOOK_URL=

Optional compatibility mode:

SENTINEL_MODE=supabase
SUPABASE_URL=https://your-project.supabase.co
SUPABASE_ANON_KEY=your-key

Configuration precedence: process environment, project .env, user config, defaults. Secrets are redacted by sentinel config.

Service commands:

sentinel services add production-api https://api.example.com/health
sentinel services list
sentinel services check <service-id>

HTTP 2xx and 3xx responses count as reachable. Redirects still appear with their response code.

MCP is optional:

pip install "devops-sentinel-next[mcp]"
sentinel mcp

Cursor mcp.json (also in examples/mcp.json):

{
  "mcpServers": {
    "devops-sentinel": {
      "command": "sentinel",
      "args": ["mcp"]
    }
  }
}

Architecture

CLI (canonical)
  → health check → SQLite (or your Supabase)
  → open/resolve incidents using failure/recovery thresholds
  → template postmortem, or LLM if a key is set (fallback is labeled)

Website (this repo's web/)
  → docs + live 503 demo for the CLI
  → optional operator UI → your local `sentinel serve`

Storage is behind SentinelDB. SQLite uses the same project, service, health-check, incident, event, and postmortem method contracts as the Supabase adapter.

Monitoring and incident lifecycle

  1. Register a service.
  2. Run a single check or continuous monitor.
  3. Persist health-check evidence.
  4. Open incidents after failure-threshold evaluation.
  5. Record detection and recovery events.
  6. Resolve after recovery-threshold evaluation.
  7. Generate a labeled template postmortem, or an LLM draft when a key works.

Failure and recovery thresholds prevent one transient request from opening or resolving an incident. MTTD is left unset when there is not enough evidence to compute it.

Local detect and diagnose

Every health, monitor, and up check prints diag= model= anomaly=.

  • HTTP still decides open/resolve. The model never opens an incident and never remediates.
  • First 20 checks per service: model=warmup, diag=unknown unless the HTTP probe already failed (http_5xx, unreachable, …).
  • After 20 SQLite rows: Isolation Forest on that service’s history (model=iforest). If sklearn is missing, z-score model=baseline.
  • A healthy HTTP 200 with an outlier latency prints WATCH and diag=latency. Slack --notify still fires only when an incident opens.
  • Labels are a closed set: http_5xx http_4xx unreachable latency expect_mismatch tls unknown.
  • Models live next to the DB under .sentinel/models/.

Incident-response stages

The CLI pipeline is:

Health check
    ↓
Detect              Failure, latency, or SSL
    ↓
Open / notify       Incident row + optional Slack
    ↓
Plan                Template or optional LLM postmortem
    ↓
Human               Destructive remediation is not auto-executed

sentinel agents prints this map. It is not a CrewAI crew and does not run a separate agent process.

MCP hosts can query read-only operational context: health_check, health_check_batch, doctor, list_incidents, get_incident, get_incident_events, analyze_anomaly, generate_postmortem.

Do not expose remote MCP to the public internet without authentication.

GitHub Action for a one-shot health probe: .github/actions/sentinel-health. Copy examples/github-health.yml into a consuming repo.

Website

The marketing site is a client-rendered SPA. Static HTML includes the GitHub and PyPI links so a crawler that cannot execute JavaScript can still find the repo.

cd web
npm install
npm run dev

Operator routes talk to a FastAPI process you run (sentinel serve), not a hosted backend:

  • /operator/services
  • /operator/incidents
  • /operator/incidents/:incidentId

npm client

packages/client calls the HTTP API. It does not duplicate Python monitoring logic.

Development

Dependencies live in pyproject.toml only (pip install -e ".[dev]"). There is no requirements.txt.

python -m pip install -e ".[dev]"
pytest -q -o addopts="" --cov=sentinel.core --cov-report=term-missing
python -m ruff check sentinel tests
cd web
npm run lint
npm run build

Docker and Render bind 0.0.0.0 on purpose (containers must listen on all interfaces). The CLI default remains localhost.

License

MIT License.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

devops_sentinel_next-0.1.5.tar.gz (166.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

devops_sentinel_next-0.1.5-py3-none-any.whl (168.1 kB view details)

Uploaded Python 3

File details

Details for the file devops_sentinel_next-0.1.5.tar.gz.

File metadata

  • Download URL: devops_sentinel_next-0.1.5.tar.gz
  • Upload date:
  • Size: 166.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for devops_sentinel_next-0.1.5.tar.gz
Algorithm Hash digest
SHA256 b65afa0abb853e2cd33ee0fdb8b109768e9470cc2df2b521362e7fcc8d2df64f
MD5 d1b63a092bb39d425d0d174c5d542100
BLAKE2b-256 557ace153ea4fcfa4edad65c80d6abd4109605b97f5ff25df98306ae13e73c66

See more details on using hashes here.

File details

Details for the file devops_sentinel_next-0.1.5-py3-none-any.whl.

File metadata

File hashes

Hashes for devops_sentinel_next-0.1.5-py3-none-any.whl
Algorithm Hash digest
SHA256 372e0d42df3f0bf4db3e3a04f20ccbdb793f9373e71132ba9fe73d18b2cf4561
MD5 3e688fb4c5f081b6e143cf98deecb4e0
BLAKE2b-256 244e56686cde1f725abf5b50cb24cdfb59df4d4dff617d091b196569259c338d

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.5 This release

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page