A Go-based alert engine for monitoring application logs in OpenShift environments with real-time alerting via Slack.
Goal: Validate the concept with minimal viable alerting
- Simple Log Ingestion - OpenShift Logging Vector + Kafka pipeline
- Basic Alert Engine - Simple rule-based alerting (no NLP engine)
- Single notification channel - Slack integration only
- Minimal UI - Command Line or simple web form for alert creation
- Working log pipeline from OpenShift pods to Kafka
- Basic threshold-based alerts (count, keyword matching)
- Slack notification working
- Single hard-coded alert rule validation
- Can detect "ERROR" logs exceeding count threshold
- Can send Slack notification within 30 seconds
- No data loss in log pipeline
For the long-term vision and NLP-based alert pattern analysis that will guide future development phases, refer to:
π§ NLP Alert Patterns Analysis - Comprehensive analysis of natural language processing patterns for intelligent log monitoring and advanced alert detection capabilities.
The Alert Engine is a cloud-native solution designed to monitor application logs from OpenShift/Kubernetes environments, evaluate them against configurable alert rules, and send notifications to Slack channels. This implementation represents Phase 0 of a comprehensive log monitoring system.
- Real-time Log Processing: Consumes log messages from Kafka streams
- Flexible Alert Rules: Configurable rules based on log level, namespace, service, keywords, and thresholds
- Slack Integration: Rich notification messages with severity-based formatting
- High Performance: Redis-backed state management with horizontal scaling support
- Cloud-Native: Designed for OpenShift/Kubernetes with proper RBAC and security
- RESTful API: Full API for managing alert rules and monitoring system status
βββββββββββββββββββ ββββββββββββββββ βββββββββββββββββββ βββββββββββββββ
β OpenShift β β AMQ β β Alert β β Slack β
β Pods/Logs βββββΆβ Streams βββββΆβ Engine βββββΆβ Webhook β
β β β (Kafka) β β (Go Service) β β β
βββββββββββββββββββ ββββββββββββββββ βββββββββββββββββββ βββββββββββββββ
β β β
β β β
βΌ βΌ βΌ
βββββββββββββββββββ ββββββββββββββββ βββββββββββββββββββ
β OpenShift β β Redis β β REST API β
β Logging β β (State) β β (Management) β
β (Vector) β β β β β
βββββββββββββββββββ ββββββββββββββββ βββββββββββββββββββ
- Language: Go 1.21+
- Framework: Gin (HTTP router)
- Message Streaming: Apache Kafka (Red Hat AMQ Streams)
- State Storage: Redis
- Container Platform: OpenShift 4.12+
- Notifications: Slack Webhooks
- Monitoring: Prometheus metrics
alert-engine/
βββ bin/ # Binary executables
βββ cmd/ # Application entry points
βββ configs/ # Configuration files
β βββ config.yaml # Main application configuration
β βββ README.md # Configuration documentation
βββ deployments/ # Deployment manifests
β βββ alert-engine/ # Alert Engine OpenShift deployment
β β βββ BUILD_SUMMARY.md # Build summary documentation
β β βββ build.sh # Build script
β β βββ configmap.yaml # ConfigMap manifest
β β βββ deployment.yaml # Deployment manifest
β β βββ Dockerfile # Container image definition
β β βββ kustomization.yaml # Kustomize configuration
β β βββ namespace.yaml # Namespace manifest
β β βββ networkpolicy.yaml # Network policy manifest
β β βββ README.md # Deployment documentation
β β βββ secret.yaml # Secret manifest
β β βββ service.yaml # Service manifest
β β βββ serviceaccount.yaml # Service account manifest
β β βββ update-image.sh # Image update script
β βββ phase0/ # Phase 0 deployment manifests
β βββ payment-error-job.yaml # Payment error test job
βββ inputs/ # Project documentation and analysis
β βββ coverage_analysis.md # Test coverage analysis
β βββ Log Monitoring PRD.pdf # Product requirements document
β βββ nlp_alert_patterns.md # NLP pattern analysis
βββ internal/ # Internal application packages
β βββ alerting/ # Alert evaluation engine
β β βββ engine.go # Main alert evaluation engine
β β βββ engine_test.go # Engine unit tests
β β βββ evaluator.go # Rule evaluation logic
β β βββ evaluator_test.go # Evaluator unit tests
β β βββ rules.go # Rule management and validation
β β βββ rules_test.go # Rules unit tests
β β βββ mock_test.go # Mock setup for tests
β β βββ fixtures/ # Test data fixtures
β β β βββ test_logs.json
β β β βββ test_rules.json
β β βββ mocks/ # Generated mocks
β β β βββ mock_notifier.go
β β β βββ mock_state_store.go
β β βββ README.md # Alerting package documentation
β βββ api/ # HTTP API layer
β β βββ handlers.go # HTTP API handlers
β β βββ handlers_test.go # Handler unit tests
β β βββ routes.go # API route definitions
β β βββ integration_test.go # API integration tests
β β βββ fixtures/ # Test data fixtures
β β β βββ test_requests.json
β β β βββ test_responses.json
β β βββ mocks/ # Generated mocks
β β β βββ mock_alert_engine.go
β β β βββ mock_state_store.go
β β βββ README.md # API package documentation
β βββ kafka/ # Kafka integration
β β βββ consumer.go # Kafka consumer implementation
β β βββ consumer_test.go # Consumer unit tests
β β βββ processor.go # Log message processing
β β βββ processor_test.go # Processor unit tests
β β βββ integration_test.go # Kafka integration tests
β β βββ fixtures/ # Test data fixtures
β β β βββ test_configs.json
β β β βββ test_messages.json
β β βββ mocks/ # Generated mocks
β β β βββ mock_alert_engine.go
β β β βββ mock_kafka_reader.go
β β β βββ mock_state_store.go
β β βββ testcontainers/ # Test container setup
β β β βββ kafka_container.go
β β βββ README.md # Kafka package documentation
β βββ notifications/ # Notification integrations
β β βββ interfaces.go # Notification interfaces
β β βββ interfaces_test.go # Interface unit tests
β β βββ slack.go # Slack integration
β β βββ slack_test.go # Slack unit tests
β β βββ integration_test.go # Notification integration tests
β β βββ fixtures/ # Test data fixtures
β β β βββ test_alerts.json
β β βββ mocks/ # Generated mocks
β β β βββ mock_http_client.go
β β β βββ mock_http_server.go
β β βββ README.md # Notifications package documentation
β βββ storage/ # Data storage layer
β βββ redis.go # Redis storage implementation
β βββ redis_test.go # Redis unit tests
β βββ integration_test.go # Storage integration tests
β βββ redis_container.go # Redis test container setup
β βββ test_data.json # Test data for storage
β βββ README.md # Storage package documentation
βββ local_e2e/ # End-to-end testing setup
β βββ setup/ # E2E environment setup
β β βββ config_local_e2e.yaml
β β βββ docker-compose-local-e2e.yml
β β βββ mock_log_forwarder.py
β β βββ requirements.txt
β β βββ setup_local_e2e.sh
β β βββ start_alert_engine.sh
β β βββ teardown_local_e2e.sh
β β βββ test_slack.sh
β β βββ README.md
β βββ tests/ # E2E test cases
β βββ comprehensive_e2e_test_config.json
β βββ run_e2e_tests.sh
β βββ README.md
βββ pkg/ # Public packages
β βββ models/ # Data models
β βββ alert.go # Alert rule models
β βββ alert_test.go # Alert model tests
β βββ log.go # Log entry models
β βββ log_test.go # Log model tests
β βββ fixtures/ # Test data fixtures
β β βββ test_alerts.json
β β βββ test_logs.json
β βββ README.md # Models package documentation
βββ scripts/ # Build and test automation
β βββ cleanup_openshift_infrastructure.sh # OpenShift cleanup script
β βββ docker-compose.test.yml # Test environment setup
β βββ openshift_utils.sh # Shared OpenShift utilities
β βββ prompt.md # Development prompts and guidance
β βββ run_integration_tests.sh # Integration test runner
β βββ run_kafka_integration_tests.sh # Kafka-specific test runner
β βββ run_unit_tests.sh # Unit test runner
β βββ setup_openshift_infrastructure.sh # OpenShift setup script
β βββ test_strategy.md # Testing strategy documentation
β βββ validate_openshift_infrastructure.sh # OpenShift validation script
β βββ verify_resources_before_cleanup.sh # Pre-cleanup verification
β βββ README.md # Scripts documentation
βββ alert_engine_infra_setup.md # Infrastructure setup guide
βββ go.mod # Go module definition
βββ go.sum # Go module checksums
βββ main # Compiled binary
βββ Makefile # Build automation
βββ README.md # This file
- Go 1.21 or later
- Access to OpenShift/Kubernetes cluster
- Redis instance
- Kafka cluster (Red Hat AMQ Streams)
- Slack workspace with webhook permissions
- Openshift AI
IMPORTANT: Before proceeding with the Alert Engine setup, you must first install and configure the required infrastructure components on your OpenShift cluster.
π OpenShift Infrastructure Setup Guide
Key infrastructure components to install (15-20 minutes total):
- Red Hat AMQ Streams: Install operator and deploy 3-node Kafka cluster with
application-logstopic - Redis Enterprise: Install operator and create database with ReJSON/TimeSeries modules for state management
- OpenShift Logging: Install operator and configure ClusterLogForwarder to route application logs to Kafka
- RBAC & Security: Create service accounts, role bindings, and network policies for secure log collection
- Verification: Test connectivity between components and validate log forwarding pipeline
Complete the infrastructure setup before proceeding with the local development or deployment steps below.
For comprehensive local development setup with end-to-end testing capabilities, refer to:
- π Local E2E Setup Guide - Complete environment setup with Docker Compose, mock services, and infrastructure
- π§ͺ Local E2E Testing Guide - Running end-to-end tests with real Slack notifications
For detailed configuration instructions including environment variables, configuration files, and deployment settings, refer to:
π Configuration Guide - Complete configuration documentation with examples for local development, testing, and production deployment.
For comprehensive API documentation including endpoints, request/response formats, and usage examples, refer to:
π API Documentation - Complete REST API documentation with detailed endpoint specifications, authentication, and integration examples.
- The Alert Engine is complete for Phase0. Run the following commands to get started
make infra-setup
make infra-validate
make test-all
oc apply -f deployments/phase0/payment-error-job.yaml
make build-and-deploy
make logs
make health
- set an alert rule
curl -s -X POST "http://localhost:8080/api/v1/rules" \
-H "Content-Type: application/json" \
-d '{
"id": "perfect-payment-alert",
"name": "Perfect Payment Alert",
"description": "Exactly matches current payment logs",
"enabled": true,
"conditions": {
"log_level": "error",
"namespace": "phase0-logs",
"service": "payment-service",
"keywords": ["Payment", "failed"],
"threshold": 1,
"time_window": 60000000000,
"operator": "gte"
},
"actions": {
"slack_webhook": "https://hooks.slack.com/services/YOUR_WEBHOOK_URL",
"channel": "#alert-channel", # Your own channel
"severity": "high"
}
}'
Alert Engine v1.0.0 - Phase 0: Foundation & Proof of Concept