Skip to content

feat: real container restart remediation via argus-executor - #7

Merged
sdOps merged 2 commits into
mainfrom
feat/remediation
Sep 21, 2026
Merged

sdOps merged 2 commits into
mainfrom
feat/remediation

Conversation

@sdOps

@sdOps sdOps commented Sep 21, 2026

Copy link
Copy Markdown
Owner
  • Add dedicated argus-executor service that owns /var/run/docker.sock and exposes a typed POST /execute endpoint.
  • execute_runbook_step no longer accepts a command string from the model; it looks up runbook steps by service + step_id and routes restart through the executor.
  • Enforce a per-incident remediation attempt cap (default 3, env configurable via REMEDIATION_ATTEMPT_CAP).
  • Keep /recover endpoints for manual/demo reset but remove them from the agent remediation path.
  • Refuse execution in native modes where no executor is configured.
  • Document all seven demo scenarios in README.md, including the unprimed api-oom case.
  • Update ARCHITECTURE.md §7/§10 to describe real container restart and the unprimed scenario.
  • Add remediation-cap test and update approval-gate test for the new tool signature.

Verified:

  • bun run --cwd argus-server typecheck
  • bun run --cwd argus-ui typecheck
  • bun run --cwd argus-ui build
  • bun test --cwd argus-server (30 pass, 0 fail)
  • docker compose build
  • docker compose up -d --build, mise run infra:demo -- db, approval, end-to-end resolved

This is a large change because it adds the executor service, refactors the remediation tool, and updates docs across both README.md and ARCHITECTURE.md.

Closes #6

- Add dedicated argus-executor service that owns /var/run/docker.sock

- execute_runbook_step no longer accepts a command string; it looks up typed runbook steps and routes restart through the executor

- Enforce per-incident remediation attempt cap (default 3, env configurable)

- Keep /recover endpoints for manual/demo reset but remove from agent path

- Refuse execution in native modes where no executor is configured

- Document all seven demo scenarios including the unprimed api-oom case

- Add remediation-cap test and update approval-gate test for new tool signature
@sdOps sdOps added enhancement New feature or request large-change Bypass PR size check for changes over 500 lines labels Sep 21, 2026
…ting

After execute_runbook_step reports back (incident.status = mitigated), the UI

should display 'verifying' while it waits for the detection path to clear

the remaining firing alerts, instead of staying in 'executing'.

Update the workflow state machine test to match.
@sdOps
sdOps merged commit 2b25f2e into main Sep 21, 2026
4 checks passed
@sdOps
sdOps deleted the feat/remediation branch September 21, 2026 01:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request large-change Bypass PR size check for changes over 500 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: real container restart remediation via argus-executor

1 participant