Aller au contenu

Automatisation SRE

L’automatisation SRE est la console pour l’orchestrateur SRE — le service que la page de concept de l’orchestrateur SRE décrit, qui transforme une alerte ou un événement de la plateforme en incident avec une proposition de remédiation attachée. Le haut de l’écran indique si l’orchestrateur est activé, son mode d’automatisation actuel et les totaux sur la durée de vie (incidents soulevés, combien résolus au cours des dernières 24 heures, temps moyen de résolution) ; en dessous, Incidents récents répertorie chaque incident, filtrable par statut et sévérité, avec l’alerte, la source et le plan de remédiation de chacun, les actions Approuver et Rejeter que le guide des tâches parcourt étape par étape, et une action Rejeter pour les incidents qui ne nécessitent aucune révision de remédiation. Un panneau de paramètres distinct contient tout ce que l’orchestrateur fera et ne fera pas de lui-même : les garde-fous de sécurité (niveaux de risque et sévérités autorisés pour l’auto-remédiation, services et alertes sur liste noire, modèles de commandes dangereuses, limites de commandes par incident et temps de retrait), les paramètres d’analyse qui délimitent ce que le modèle examinant un incident est autorisé à faire (son invite système, sa liste d’outils, les délais de tour et de session, la quantité de contexte qu’il collecte), et où les notifications Slack et email pour un incident sont routées.

Section de la barre latérale Opérations → Automatisation SRE.

L'écran Automatisation SRE du tableau de bord Odysseus.
  • infrastructure:sREAutomation.0-unlimited-bounded-only-by — “0 = illimité (limité uniquement par le délai d’expiration de la session)”
  • infrastructure:sREAutomation.actions — “Actions”
  • infrastructure:sREAutomation.advanced-safety-settings — “Paramètres de sécurité avancés”
  • infrastructure:sREAutomation.alert — “Alerte”
  • infrastructure:sREAutomation.alert-fired — “Alerte déclenchée”
  • infrastructure:sREAutomation.alert-severities-that-can-be — “Sévérités d’alerte pouvant être auto-remédiées sans approbation”
  • infrastructure:sREAutomation.all-severities — “Toutes les sévérités”
  • infrastructure:sREAutomation.all-statuses — “Tous les statuts”
  • infrastructure:sREAutomation.allowed-risk-levels-for-auto — “Niveaux de risque autorisés pour l’exécution automatique”
  • infrastructure:sREAutomation.allowed-severities-for-auto-remediation — “Sévérités autorisées pour l’auto-remédiation”
  • infrastructure:sREAutomation.allowed-tools — “Outils autorisés”
  • infrastructure:sREAutomation.approve — “Approuver”
  • infrastructure:sREAutomation.approve-execute — “Approuver et exécuter”
  • infrastructure:sREAutomation.approving — “Approbation en cours…”
  • infrastructure:sREAutomation.automation-mode — “Mode d’automatisation”
  • infrastructure:sREAutomation.avg-resolution-time — “Temps de résolution moyen”
  • infrastructure:sREAutomation.awaiting-approval — “En attente d’approbation”
  • infrastructure:sREAutomation.bash-read-grep-glob-webfetch — “Bash, Read, Grep, Glob, WebFetch, Task, Skill”
  • infrastructure:sREAutomation.blacklisted-alerts-comma-separated — “Alertes sur liste noire (séparées par des virgules)”
  • infrastructure:sREAutomation.blacklisted-services — “Services sur liste noire”
  • infrastructure:sREAutomation.cancel — “Annuler”
  • infrastructure:sREAutomation.channel — “@channel”
  • infrastructure:sREAutomation.claude-analysis-settings — “Paramètres d’analyse de Claude”
  • infrastructure:sREAutomation.close — “Fermer”
  • infrastructure:sREAutomation.comma-separated-severities-to-notify — “Sévérités séparées par des virgules pour lesquelles notifier”
  • infrastructure:sREAutomation.command-risk-levels-that-can — “Niveaux de risque de commande pouvant être exécutés sans approbation”
  • infrastructure:sREAutomation.command-timeout-seconds — “Délai d’expiration de la commande (secondes)”
  • infrastructure:sREAutomation.commands — “Commandes”
  • infrastructure:sREAutomation.commands-executed — “Commandes exécutées”
  • infrastructure:sREAutomation.container — “Conteneur”
  • infrastructure:sREAutomation.context-gathering — “Collecte de contexte”
  • infrastructure:sREAutomation.cooldown-seconds — “Délai de récupération (secondes)”
  • infrastructure:sREAutomation.created — “Créé”
  • infrastructure:sREAutomation.critical — “Critique”
  • infrastructure:sREAutomation.critical-alerts — “#critical-alerts”
  • infrastructure:sREAutomation.critical-channel — “Canal critique”
  • infrastructure:sREAutomation.critical-warning — “critique, warning”
  • infrastructure:sREAutomation.custom-prompt-active-click-reset — “Prompt personnalisé actif. Cliquez sur « Rétablir les valeurs par défaut » pour restaurer l’original.”
  • infrastructure:sREAutomation.dangerous-patterns — “Motifs dangereux”
  • infrastructure:sREAutomation.days-to-keep-old-incidents — “Jours de conservation des incidents anciens”
  • infrastructure:sREAutomation.default-channel — “Canal par défaut”
  • infrastructure:sREAutomation.description — “Description”
  • infrastructure:sREAutomation.dismiss — “Rejeter”
  • infrastructure:sREAutomation.dismiss-all — “Tout rejeter”
  • infrastructure:sREAutomation.edit — “Modifier”
  • infrastructure:sREAutomation.email-routing — “Routage des e-mails”
  • infrastructure:sREAutomation.email-subject-prefix — “Préfixe de l’objet de l’e-mail”
  • infrastructure:sREAutomation.enable-or-disable-automated-incident — “Activer ou désactiver la réponse automatisée aux incidents”
  • infrastructure:sREAutomation.enable-sre-email — “Activer l’e-mail SRE”
  • infrastructure:sREAutomation.enable-sre-slack — “Activer le Slack SRE”
  • infrastructure:sREAutomation.enabled — “Activé”
  • infrastructure:sREAutomation.error — “Erreur :”
  • infrastructure:sREAutomation.escalated — “Escaladé”
  • infrastructure:sREAutomation.escalation-channel — “Canal d’escalade”
  • infrastructure:sREAutomation.event-triggers — “Déclencheurs d’événements”
  • infrastructure:sREAutomation.explain-why-this-incident-is — “Expliquez pourquoi cet incident est rejeté…”
  • infrastructure:sREAutomation.failed — “Échoué”
  • infrastructure:sREAutomation.general-settings — “Paramètres généraux”
  • infrastructure:sREAutomation.id — “ID :”
  • infrastructure:sREAutomation.in-progress — “En cours”
  • infrastructure:sREAutomation.incident-retention-days — “Conservation des incidents (jours)”
  • infrastructure:sREAutomation.include-commands — “Inclure les commandes”
  • infrastructure:sREAutomation.include-docker-stats — “Inclure les statistiques Docker”
  • infrastructure:sREAutomation.include-prometheus-metrics — “Inclure les métriques Prometheus”
  • infrastructure:sREAutomation.include-root-cause-analysis — “Inclure l’analyse des causes profondes”
  • infrastructure:sREAutomation.include-trace-analysis — “Inclure l’analyse des traces”
  • infrastructure:sREAutomation.info — “Info”
  • infrastructure:sREAutomation.last-24-hours — “Dernières 24 heures”
  • infrastructure:sREAutomation.live — “En direct”
  • infrastructure:sREAutomation.loading — “Chargement…”
  • infrastructure:sREAutomation.log-lines-to-gather — “Lignes de journal à collecter”
  • infrastructure:sREAutomation.max-commands-per-incident — “Commandes max par incident”
  • infrastructure:sREAutomation.max-time-for-each-remediation — “Temps max pour chaque commande de remédiation (ex. : docker restart)”
  • infrastructure:sREAutomation.max-tokens — “Tokens max”
  • infrastructure:sREAutomation.max-turns-hard-limit — “Tours max (limite stricte)”
  • infrastructure:sREAutomation.maximum-tokens-for-claude-response — “Tokens maximum pour la réponse de Claude”
  • infrastructure:sREAutomation.message-customization — “Personnalisation des messages”
  • infrastructure:sREAutomation.no — “Non”
  • infrastructure:sREAutomation.no-incidents-found — “Aucun incident trouvé”
  • infrastructure:sREAutomation.no-incidents-match-the-current — “Aucun incident ne correspond aux filtres actuels”
  • infrastructure:sREAutomation.no-incidents-yet — “Aucun incident pour le moment”
  • infrastructure:sREAutomation.no-risk-levels — “non”
  • infrastructure:sREAutomation.none-executed — “Aucune exécutée”
  • infrastructure:sREAutomation.observe-only-no-auto-execution — “Observation uniquement - pas d’exécution automatique”
  • infrastructure:sREAutomation.oncall — “#oncall”
  • infrastructure:sREAutomation.one-pattern-per-line-commands — “Un motif par ligne - les commandes correspondantes sont bloquées”
  • infrastructure:sREAutomation.open — “Ouvert”
  • infrastructure:sREAutomation.polling — “Interrogation périodique”
  • infrastructure:sREAutomation.postgresqldown-dataloss — “PostgreSQLDown, DataLoss”
  • infrastructure:sREAutomation.quick-dismiss — “Rejet rapide”
  • infrastructure:sREAutomation.reason-optional — “Raison (facultative)”
  • infrastructure:sREAutomation.received-by-sre — “Reçu par le SRE”
  • infrastructure:sREAutomation.recent-incidents — “Incidents récents”
  • infrastructure:sREAutomation.refresh — “Actualiser”
  • infrastructure:sREAutomation.reject — “Rejeter”
  • infrastructure:sREAutomation.reject-incident — “Rejeter l’incident”
  • infrastructure:sREAutomation.reject-incident-2 — “Rejeter l’incident :”
  • infrastructure:sREAutomation.reject-with-reason — “Rejeter avec raison”
  • infrastructure:sREAutomation.rejecting — “Rejet en cours…”
  • infrastructure:sREAutomation.remediation — “Remédiation”
  • infrastructure:sREAutomation.remediation-plan — “Plan de remédiation”
  • infrastructure:sREAutomation.reset-to-default — “Réinitialiser aux valeurs par défaut”
  • infrastructure:sREAutomation.resolution-type — “Type de résolution”
  • infrastructure:sREAutomation.resolved — “Résolu”
  • infrastructure:sREAutomation.risk-level — “Niveau de risque”
  • infrastructure:sREAutomation.rm-rf-dd-if-drop — “rm -rf /\ndd if=\nDROP DATABASE”
  • infrastructure:sREAutomation.root-cause-analysis — “Analyse des causes profondes”
  • infrastructure:sREAutomation.safety-guardrails — “Garde-fous de sécurité”
  • infrastructure:sREAutomation.save-configuration — “Enregistrer la configuration”
  • infrastructure:sREAutomation.saving — “Enregistrement en cours…”
  • infrastructure:sREAutomation.select-service-to-blacklist — “Sélectionner le service à mettre sur liste noire…”
  • infrastructure:sREAutomation.send-test-email — “Envoyer un e-mail de test”
  • infrastructure:sREAutomation.send-test-message — “Envoyer un message de test”
  • infrastructure:sREAutomation.sending — “Envoi en cours…”
  • infrastructure:sREAutomation.session-timeout-seconds — “Délai d’expiration de session (secondes)”
  • infrastructure:sREAutomation.settings-notifications — “Paramètres → Notifications”
  • infrastructure:sREAutomation.severity — “Sévérité”
  • infrastructure:sREAutomation.severity-filter — “Filtre de sévérité”
  • infrastructure:sREAutomation.slack-mention-on-critical — “Mention Slack sur Critique”
  • infrastructure:sREAutomation.slack-routing — “Routage Slack”
  • infrastructure:sREAutomation.smtp-and-slack-credentials-are — “Les identifiants SMTP et Slack sont configurés dans”
  • infrastructure:sREAutomation.source — “Source”
  • infrastructure:sREAutomation.sre — “[SRE]”
  • infrastructure:sREAutomation.sre-alerts — “#sre-alerts”
  • infrastructure:sREAutomation.sre-automation — “Automatisation SRE”
  • infrastructure:sREAutomation.sre-automation-enabled — “Automatisation SRE activée”
  • infrastructure:sREAutomation.sre-notification-routing — “Routage des notifications SRE”
  • infrastructure:sREAutomation.sre-orchestrator-status — “État de l’orchestrateur SRE”
  • infrastructure:sREAutomation.sre-will-not-take-automated — “Le SRE n’effectuera pas d’actions automatisées sur ces services”
  • infrastructure:sREAutomation.status — “État”
  • infrastructure:sREAutomation.system-prompt — “Invite système”
  • infrastructure:sREAutomation.this-section-configures-sre-specific — “. Cette section configure les règles de routage spécifiques au SRE.”
  • infrastructure:sREAutomation.time-allowed-per-analysis-turn — “Temps autorisé par tour d’analyse (par défaut : 900s = 15 min)”
  • infrastructure:sREAutomation.tools-claude-can-use-comma — “Outils que Claude peut utiliser (séparés par des virgules)”
  • infrastructure:sREAutomation.total-incidents — “Incidents totaux”
  • infrastructure:sREAutomation.total-time-for-multi-turn — “Temps total pour l’analyse multi-tours (par défaut : 9000s = 2,5 heures)”
  • infrastructure:sREAutomation.trace-window-minutes — “Fenêtre de trace (minutes)”
  • infrastructure:sREAutomation.turn-timeout-seconds — “Délai d’expiration du tour (secondes)”
  • infrastructure:sREAutomation.unknown — “Inconnu”
  • infrastructure:sREAutomation.use-system-default-email — “Utiliser l’e-mail par défaut du système”
  • infrastructure:sREAutomation.using-default-sre-prompt-click — “Utilisation du prompt SRE par défaut. Cliquez sur ‘Voir et modifier le par défaut’ pour personnaliser.”
  • infrastructure:sREAutomation.using-default-sre-prompt-click-2 — “Utilisation de l’invite SRE par défaut. Cliquez sur « Voir et modifier la valeur par défaut » pour la consulter et la modifier.”
  • infrastructure:sREAutomation.view — “Voir”
  • infrastructure:sREAutomation.view-edit-default — “Voir et modifier la valeur par défaut”
  • infrastructure:sREAutomation.warning — “Avertissement”
  • infrastructure:sREAutomation.yes — “Oui”
  • infrastructure:sreHealthState.degraded — “En cours d’exécution, mais ne fonctionne pas entièrement — des incidents sont enregistrés, voir ci-dessous”
  • infrastructure:sreHealthState.online — “En ligne et opérationnel”
  • infrastructure:sreHealthState.unavailable — “Indisponible”

Pour savoir ce qu’est un incident, comment il est attribué à un locataire, et ce que l’orchestrateur fera et ne fera pas automatiquement, consultez la page de concept de l’orchestrateur SRE. L’approbation d’une remédiation en file d’attente est parcourue étape par étape dans le guide des tâches. Les permissions sre:approve et sre:configure requises par les actions de cet écran, et les rôles qui les détiennent, se trouvent dans la référence des rôles ; si une approbation ou un changement de configuration est refusé, la référence des rejets est où le champ, la valeur et la forme acceptée du refus sont documentés.