How to Use Interactive Alert Input for OpenSRE Investigations

Run opensre investigate --interactive to paste alert JSON payloads directly into your terminal, bypassing file-based or inline string input requirements.

OpenSRE provides an interactive mode that streamlines incident response by letting you paste raw alert JSON directly into the terminal. This eliminates the need to save alerts to temporary files or manually escape complex JSON strings for command-line arguments. According to the Tracer-Cloud/opensre source code, the interactive workflow reads from standard input, validates the payload, and passes it directly to the investigation pipeline orchestrated by LangGraph.

How Interactive Alert Input Works

The interactive mode follows a five-stage pipeline through the OpenSRE CLI architecture:

1. CLI Command Parsing

The investigate command defined in app/cli/commands/general.py receives the --interactive flag and forwards it to the core runner. Lines 36-38 handle the flag parsing and argv construction for the investigation.

2. Payload Dispatch

In app/cli/payload.py, the load_payload function (lines 71-80) acts as a central dispatcher. When interactive=True, it delegates to load_interactive() instead of file-based or JSON string loaders.

3. Interactive Prompt

The load_interactive() function (lines 62-68) writes the instruction "Paste the alert JSON payload, then press Ctrl-D when finished." to stderr. This ensures the prompt does not corrupt the JSON output stream on stdout. It then reads all data from stdin until EOF (Ctrl-D).

4. Investigation Execution

The parsed dictionary passes to run_investigation_cli in app/cli/investigate.py (lines 51-63). This function normalizes alert metadata, resolves pipeline configurations, and invokes the LangGraph-based investigation runner.

5. Result Output

After pipeline completion, the CLI prints a JSON result containing the Slack-compatible report, root cause analysis, and noise classification to stdout.

Using Interactive Mode from the CLI

Start an interactive investigation session by running:

opensre investigate --interactive

The terminal will display the prompt on stderr and wait for your input:


Paste the alert JSON payload, then press Ctrl-D when finished.
{
  "alert_name": "High CPU",
  "pipeline_name": "prod-services",
  "severity": "critical",
  "raw_alert": { "cpu": 98, "instance": "i-0123abc" }
}
^D

After pressing Ctrl-D (EOF), OpenSRE validates the JSON and executes the investigation. The final JSON report appears on stdout:

{"report":"…slack message…","problem_md":"…","root_cause":"…","is_noise":false}

Because the prompt writes to stderr, you can safely pipe the JSON output to other tools or files using --output.

Programmatic Usage with Python

You can embed the same interactive behavior in custom scripts by importing the payload loader directly from app/cli/payload.py:

from app.cli.payload import load_interactive
from app.cli.investigate import run_investigation_cli

# Blocks execution, prints prompt to stderr, and reads from stdin

payload = load_interactive()

# Execute investigation with parsed payload

result = run_investigation_cli(raw_alert=payload)

print(result["report"])

The load_interactive() function raises SystemExit on empty input, mirroring the CLI behavior exactly. This ensures consistent error handling whether you use the command line or a Python wrapper.

Testing Interactive Input

The OpenSRE test suite demonstrates how to simulate interactive input by patching sys.stdin with a StringIO buffer. This approach is implemented in tests/test_main.py:

import io
import sys
from app.cli.payload import load_payload

# Simulate user pasting JSON

sample = '{"alert_name":"High CPU","severity":"warning"}\n'
sys.stdin = io.StringIO(sample)

# Load as interactive payload

payload = load_payload(input_path=None, input_json=None, interactive=True)

assert payload["alert_name"] == "High CPU"

This technique allows you to test interactive workflows in CI/CD pipelines without requiring an actual TTY.

Summary

  • Entry Point: The --interactive flag in app/cli/commands/general.py triggers the interactive workflow.
  • Core Logic: load_interactive() in app/cli/payload.py handles stdin reading and JSON validation.
  • Output Isolation: Prompts write to stderr to keep stdout clean for machine-readable JSON results.
  • Integration: Use run_investigation_cli from app/cli/investigate.py for programmatic access.
  • Validation: Interactive mode bypasses TTY checks and reads until EOF, making it suitable for both manual and automated usage.

Frequently Asked Questions

What happens if I provide malformed JSON in interactive mode?

The load_interactive() function in app/cli/payload.py attempts to parse the stdin content with json.loads(). If the JSON is invalid, it raises a json.JSONDecodeError and exits with a non-zero status code, displaying the parsing error to stderr without corrupting the output stream.

Can I pipe JSON into an interactive investigation?

No. The interactive mode specifically bypasses the TTY check that load_stdin() would normally enforce. If you need to pipe JSON, omit the --interactive flag and use standard input redirection (cat alert.json | opensre investigate), which triggers load_stdin() rather than load_interactive(). The interactive flag is designed for scenarios where you want visual confirmation and manual pasting.

Where is the interactive prompt text defined?

The prompt string "Paste the alert JSON payload, then press Ctrl-D when finished." is hardcoded in app/cli/payload.py within the load_interactive() function (lines 62-68). The function uses sys.stderr.write() to ensure the instruction appears immediately and does not buffer with the JSON output.

How does OpenSRE handle empty input in interactive mode?

If you press Ctrl-D without entering any content, load_interactive() detects the empty string and raises SystemExit with an appropriate error message. This behavior mirrors standard UNIX tooling and ensures the investigation pipeline does not execute with null payloads.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →