The SRE agent you can embed anywhere

Relionaut brings 2026-generation SRE agent capabilities โ€” autonomous incident investigation, tool governance, bring-your-own LLM, MCP tools, persistent memory โ€” in a portable kernel you drop into your own production systems. No platform lock-in.

Get started View on GitHub
License: Apache-2.0 CI v0.1.0 BYO LLM

Why Relionaut

Cloud SRE agents ship impressive capabilities bound to their platform. Open-source investigators bind you to their stack. Relionaut splits the difference: a self-contained agent kernel with the capabilities, and every integration point behind a port you own.

๐Ÿงฉ

Embeddable kernel

A single core/ directory โ€” zero npm dependencies, zero upward imports, enforced by a purity gate. Vendor it, implement ports, assemble with createAgent().

๐Ÿ›ก๏ธ

Governance in the loop

Every tool declares risk; a pure govern() choke point blocks write-risk tools in read-only mode โ€” structurally, not by prompt. Unknown MCP tools default to write (fail-closed).

๐Ÿง 

Memory that compounds

Investigations distill into lessons; the next incident starts with the relevant history injected into context.

๐Ÿ”Œ

BYO everything

Any Anthropic- or OpenAI-compatible endpoint, Ollama for air-gapped. Your telemetry via one interface. Your toolchain via MCP.

๐Ÿ“œ

Auditable by construction

Every run ends in a persisted terminal outcome โ€” answered, step_budget_exhausted, or llm_error. Nothing is dropped from the audit trail.

๐Ÿ“ฆ

All-in-one demo

Prefer batteries included? docker compose up starts the full self-hosted loop: collect โ†’ alert โ†’ investigate โ†’ auto-recover, with a web console.

The kernel and its five ports

The ReAct investigation loop, governance, memory, and audit live in the kernel. Everything environment-specific sits behind five interfaces โ€” that's the whole integration surface.

core/ โ€” the kernel

Investigation loop ยท tool governance ยท system prompt assembly ยท trajectory replay ยท memory injection

  • LlmProviderstreaming chat + tool calls; provider protocols never leak past this port
  • TelemetrySourcelogs & metrics queries; sources describe themselves into the prompt
  • ToolSourcestandard tools, whitelisted shell, or any MCP server
  • RunStorebatched, block-paired trajectory persistence with terminal outcomes
  • MemoryStorelesson record & retrieval

platform/ โ€” the first host

The self-hosted all-in-one is just one consumer of the kernel.

  • anthropic providerGLM / Claude-style endpoints
  • PG telemetrybuilt-in collector: docker logs & stats, host metrics
  • docker toolsread-only whitelisted host forensics
  • PG run storeagent_messages with structured blocks
  • alert enginerule evaluation โ†’ incidents โ†’ auto-investigate โ†’ auto-recover

Two ways to run it

Self-host in one command

Full stack: PostgreSQL, Redis, collector, alert engine, investigation agent, web console.

git clone https://github.com/Joshwong1908/relionaut.git
cd relionaut
echo 'GLM_API_KEY=your-key' >> .env
docker compose up -d --build
# open http://localhost:8082 โ€” telemetry flows in 30s

Embed in your Node 24 service

Vendor the kernel directory, implement the ports you need, run an investigation.

import { createAgent, openaiProvider,
         staticTools, telemetryTools,
         inMemoryRunStore } from './agent-core/mod.ts';

const agent = createAgent({
  llm: openaiProvider({ baseUrl: 'http://llm.internal:11434/v1',
                        model: 'qwen3:32b' }),
  tools: [staticTools(...telemetryTools(myTelemetry))],
  store: inMemoryRunStore(),
  system: { /* role, environment, output format */ },
});
for await (const ev of agent.run({ runId, input })) { /* SSE events */ }

Where it sits today

Open-source SRE agents cluster on an autonomy spectrum. Relionaut ships as a read-only investigator by default โ€” the red line is structural โ€” with the interface reserved for approved remediation as trust grows.

L1 ยท ExplainerDeterministic analyzers, LLM explains findings.
L2 ยท Read-only investigator โ† Relionaut v0.1ReAct loop, dynamic tool choice, read-only by design.
L3 ยท Suggests fixesInterface reserved (advise mode; PR-style output).
L4 ยท Approved remediationInterface reserved (approve-write + Approval type).