Skip to content

Commit

Permalink
feat: add the ability to run workflow on alert state change
Browse files Browse the repository at this point in the history
  • Loading branch information
shahargl committed Feb 7, 2024
1 parent 1f3b6c6 commit d8588de
Show file tree
Hide file tree
Showing 5 changed files with 119 additions and 31 deletions.
13 changes: 13 additions & 0 deletions examples/workflows/change.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
alert:
id: on-field-change
description: demonstrates how to trigger a workflow when a field changes
triggers:
- type: alert
only_on_change:
- status
actions:
- name: echo-test
provider:
type: console
with:
alert_message: "Hello workd"
50 changes: 41 additions & 9 deletions keep/api/core/db.py
Original file line number Diff line number Diff line change
Expand Up @@ -415,6 +415,7 @@ def get_all_workflows(tenant_id: str) -> List[Workflow]:
).all()
return workflows


def get_all_workflows_yamls(tenant_id: str) -> List[str]:
with Session(engine) as session:
workflows = session.exec(
Expand Down Expand Up @@ -782,6 +783,24 @@ def get_alerts_by_fingerprint(tenant_id: str, fingerprint: str, limit=1) -> List
return alerts


def get_previous_alert_by_fingerprint(tenant_id: str, fingerprint: str) -> Alert:
# get the previous alert for a given fingerprint
with Session(engine) as session:
alert = (

Check warning on line 789 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L788-L789

Added lines #L788 - L789 were not covered by tests
session.query(Alert)
.filter(Alert.tenant_id == tenant_id)
.filter(Alert.fingerprint == fingerprint)
.order_by(Alert.timestamp.desc())
.limit(2)
.all()
)
if len(alert) > 1:
return alert[1]

Check warning on line 798 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L797-L798

Added lines #L797 - L798 were not covered by tests
else:
# no previous alert
return None

Check warning on line 801 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L801

Added line #L801 was not covered by tests


def get_api_key(api_key: str) -> TenantApiKey:
with Session(engine) as session:
api_key_hashed = hashlib.sha256(api_key.encode()).hexdigest()
Expand Down Expand Up @@ -991,19 +1010,31 @@ def delete_rule(tenant_id, rule_id):
return False


def assign_alert_to_group(tenant_id, alert_id, rule_id, group_fingerprint) -> Group:
def assign_alert_to_group(
tenant_id, alert_id, rule_id, timeframe, group_fingerprint
) -> Group:
# checks if group with the group critiria exists, if not it creates it
# and then assign the alert to the group
with Session(engine, expire_on_commit=False) as session:
with Session(engine) as session:

Check warning on line 1018 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1018

Added line #L1018 was not covered by tests
group = session.exec(
select(Group)
.options(selectinload(Group.alerts))
.options(joinedload(Group.alerts))
.where(Group.tenant_id == tenant_id)
.where(Group.rule_id == rule_id)
.where(Group.group_fingerprint == group_fingerprint)
).first()

if not group:
# if the last alert in the group is older than the timeframe, create a new group
if group:

Check warning on line 1028 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1028

Added line #L1028 was not covered by tests
# group has at least one alert (o/w it wouldn't created in the first place)
is_group_expired = max(

Check warning on line 1030 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1030

Added line #L1030 was not covered by tests
alert.timestamp for alert in group.alerts
) < datetime.utcnow() - timedelta(seconds=timeframe)
else:
is_group_expired = True

Check warning on line 1034 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1034

Added line #L1034 was not covered by tests

# if there is no group with the group_fingerprint, create it
if not group or is_group_expired:

Check warning on line 1037 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1037

Added line #L1037 was not covered by tests
# Create and add a new group if it doesn't exist
group = Group(
tenant_id=tenant_id,
Expand All @@ -1015,7 +1046,7 @@ def assign_alert_to_group(tenant_id, alert_id, rule_id, group_fingerprint) -> Gr
# Re-query the group with selectinload to set up future automatic loading of alerts
group = session.exec(
select(Group)
.options(selectinload(Group.alerts))
.options(joinedload(Group.alerts))
.where(Group.id == group.id)
).first()

Expand All @@ -1027,10 +1058,11 @@ def assign_alert_to_group(tenant_id, alert_id, rule_id, group_fingerprint) -> Gr
)
session.add(alert_group)
session.commit()
# To reflect the newly added alert we expire its state to force a refresh on access
session.expire(group, ["alerts"])
session.refresh(group)
return group
# Requery the group to get the updated alerts
group = session.exec(

Check warning on line 1062 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1062

Added line #L1062 was not covered by tests
select(Group).options(joinedload(Group.alerts)).where(Group.id == group.id)
).first()
return group

Check warning on line 1065 in keep/api/core/db.py

View check run for this annotation

Codecov / codecov/patch

keep/api/core/db.py#L1065

Added line #L1065 was not covered by tests


def get_groups(tenant_id):
Expand Down
4 changes: 3 additions & 1 deletion keep/providers/prometheus_provider/prometheus_provider.py
Original file line number Diff line number Diff line change
Expand Up @@ -229,7 +229,9 @@ def simulate_alert(**kwargs) -> dict:
alert_payload[parameter] = random.choice(parameter_options)
annotations = {"summary": alert_payload["summary"]}
alert_payload["labels"]["alertname"] = alert_type
alert_payload["status"] = AlertStatus.FIRING.value
alert_payload["status"] = random.choice(
[AlertStatus.FIRING.value, AlertStatus.RESOLVED.value]
)
alert_payload["annotations"] = annotations
alert_payload["startsAt"] = datetime.datetime.now(
tz=datetime.timezone.utc
Expand Down
10 changes: 9 additions & 1 deletion keep/rulesengine/rulesengine.py
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ def run_rules(self, events: list[AlertDto]):
tenant_id=self.tenant_id,
alert_id=event.event_id,
rule_id=str(rule.id),
timeframe=rule.timeframe,
group_fingerprint=group_fingerprint,
)
groups.append(updated_group)
Expand Down Expand Up @@ -177,7 +178,14 @@ def _check_if_rule_apply(self, rule, event: AlertDto):
ast = env.compile(sub_rule)
prgm = env.program(ast)
activation = celpy.json_to_cel(json.loads(json.dumps(payload, default=str)))
r = prgm.evaluate(activation)
try:
r = prgm.evaluate(activation)
except celpy.evaluation.CELEvalError as e:

Check warning on line 183 in keep/rulesengine/rulesengine.py

View check run for this annotation

Codecov / codecov/patch

keep/rulesengine/rulesengine.py#L181-L183

Added lines #L181 - L183 were not covered by tests
# this is ok, it means that the subrule is not relevant for this event
if "no such member" in str(e):
return False

Check warning on line 186 in keep/rulesengine/rulesengine.py

View check run for this annotation

Codecov / codecov/patch

keep/rulesengine/rulesengine.py#L185-L186

Added lines #L185 - L186 were not covered by tests
# unknown
raise

Check warning on line 188 in keep/rulesengine/rulesengine.py

View check run for this annotation

Codecov / codecov/patch

keep/rulesengine/rulesengine.py#L188

Added line #L188 was not covered by tests
if r:
return True
# no subrules matched
Expand Down
73 changes: 53 additions & 20 deletions keep/workflowmanager/workflowmanager.py
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,11 @@
import uuid

from keep.api.core.config import AuthenticationType
from keep.api.core.db import get_enrichment, save_workflow_results
from keep.api.core.db import (
get_enrichment,
get_previous_alert_by_fingerprint,
save_workflow_results,
)
from keep.api.models.alert import AlertDto
from keep.providers.providers_factory import ProviderConfigurationException
from keep.workflowmanager.workflow import Workflow
Expand Down Expand Up @@ -84,6 +88,7 @@ def insert_events(self, tenant_id, events: typing.List[AlertDto]):
if not trigger.get("type") == "alert":
continue
should_run = True
# apply filters
for filter in trigger.get("filters", []):
# TODO: more sophisticated filtering/attributes/nested, etc
filter_key = filter.get("key")
Expand Down Expand Up @@ -128,26 +133,54 @@ def insert_events(self, tenant_id, events: typing.List[AlertDto]):
should_run = False
break

# if we got here, it means the event should trigger the workflow
if should_run:
self.logger.info("Found a workflow to run")
event.trigger = "alert"
# prepare the alert with the enrichment
self.logger.info("Enriching alert")
alert_enrichment = get_enrichment(tenant_id, event.fingerprint)
if alert_enrichment:
for k, v in alert_enrichment.enrichments.items():
setattr(event, k, v)
self.logger.info("Alert enriched")
self.scheduler.workflows_to_run.append(
{
"workflow": workflow,
"workflow_id": workflow_model.id,
"tenant_id": tenant_id,
"triggered_by": "alert",
"event": event,
}
if not should_run:
continue

Check warning on line 137 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L136-L137

Added lines #L136 - L137 were not covered by tests
# enrich the alert with more data
self.logger.info("Found a workflow to run")
event.trigger = "alert"

Check warning on line 140 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L139-L140

Added lines #L139 - L140 were not covered by tests
# prepare the alert with the enrichment
self.logger.info("Enriching alert")
alert_enrichment = get_enrichment(tenant_id, event.fingerprint)
if alert_enrichment:
for k, v in alert_enrichment.enrichments.items():
setattr(event, k, v)
self.logger.info("Alert enriched")

Check warning on line 147 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L142-L147

Added lines #L142 - L147 were not covered by tests
# apply only_on_change (https://github.com/keephq/keep/issues/801)
fields_that_needs_to_be_change = trigger.get("only_on_change", [])

Check warning on line 149 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L149

Added line #L149 was not covered by tests
# if there are fields that needs to be changed, get the previous alert
if fields_that_needs_to_be_change:
previous_alert = get_previous_alert_by_fingerprint(

Check warning on line 152 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L151-L152

Added lines #L151 - L152 were not covered by tests
tenant_id, event.fingerprint
)
# now compare:
# (no previous alert means that the workflow should run)
if previous_alert:
for field in fields_that_needs_to_be_change:

Check warning on line 158 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L157-L158

Added lines #L157 - L158 were not covered by tests
# the field hasn't change
if getattr(event, field) == previous_alert.event.get(field):
self.logger.info(

Check warning on line 161 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L160-L161

Added lines #L160 - L161 were not covered by tests
"Skipping the workflow because the field hasn't change",
extra={
"field": field,
"event": event,
"previous_alert": previous_alert,
},
)
should_run = False
break

Check warning on line 170 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L169-L170

Added lines #L169 - L170 were not covered by tests

if not should_run:
continue

Check warning on line 173 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L172-L173

Added lines #L172 - L173 were not covered by tests
# Lastly, if the workflow should run, add it to the scheduler
self.scheduler.workflows_to_run.append(

Check warning on line 175 in keep/workflowmanager/workflowmanager.py

View check run for this annotation

Codecov / codecov/patch

keep/workflowmanager/workflowmanager.py#L175

Added line #L175 was not covered by tests
{
"workflow": workflow,
"workflow_id": workflow_model.id,
"tenant_id": tenant_id,
"triggered_by": "alert",
"event": event,
}
)

def _get_event_value(self, event, filter_key):
# if the filter key is a nested key, get the value
Expand Down

0 comments on commit d8588de

Please sign in to comment.