Repository navigation
Create cncf-self-assesment.md - #637
Conversation
WalkthroughA new document, Changes
Possibly related PRs
Suggested reviewers
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (4)
docs/cncf-self-assesment.md (4)
70-70: Sentence fragment
No relevant.reads awkwardly and lacks a subject.-No relevant. +None.
18-22: Inconsistent list markers (*vs-)The document mixes
*and-for unordered lists. Pick one (markdown-lint default:-) for consistency and easier automated linting.Also applies to: 60-65, 113-120
60-60: Minor wording – drop “are able to”
- Human-in-the-loop: users are able to interact …
Shorter form improves readability:
-* Human-in-the-loop: users are able to interact with and guide HolmesGPT investigations +* Human-in-the-loop: users can interact with and guide HolmesGPT investigations
100-103: Bare URLs – convert to Markdown linksBare links violate MD034 and render inconsistently in some viewers. Wrap them with brackets:
-Please refer to https://robusta-dev.github.io/holmesgpt/installation/cli-installation/ +Please refer to <https://robusta-dev.github.io/holmesgpt/installation/cli-installation/>(and similarly for lines 103 & 123).
Also applies to: 123-123
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
docs/cncf-self-assesment.md(1 hunks)
🧰 Additional context used
🧠 Learnings (2)
📓 Common learnings
Learnt from: nherment
PR: robusta-dev/holmesgpt#610
File: .github/workflows/llm-evaluation.yaml:39-42
Timestamp: 2025-07-08T08:45:41.069Z
Learning: The robusta-dev/holmesgpt codebase has comprehensive existing validation for Azure environment variables (AZURE_API_BASE, AZURE_API_KEY, AZURE_API_VERSION) and MODEL in tests/llm/utils/classifiers.py, tests/llm/conftest.py, and holmes/core/llm.py. Don't suggest adding redundant validation logic.
docs/cncf-self-assesment.md (2)
Learnt from: nherment
PR: robusta-dev/holmesgpt#610
File: .github/workflows/llm-evaluation.yaml:39-42
Timestamp: 2025-07-08T08:45:41.069Z
Learning: The robusta-dev/holmesgpt codebase has comprehensive existing validation for Azure environment variables (AZURE_API_BASE, AZURE_API_KEY, AZURE_API_VERSION) and MODEL in tests/llm/utils/classifiers.py, tests/llm/conftest.py, and holmes/core/llm.py. Don't suggest adding redundant validation logic.
Learnt from: Sheeproid
PR: robusta-dev/holmesgpt#586
File: tests/llm/fixtures/test_ask_holmes/03_what_is_the_command_to_port_forward/test_case.yaml:4-4
Timestamp: 2025-07-02T10:27:17.231Z
Learning: In LLM-as-judge test cases for HolmesGPT, expected outputs should be descriptive rather than prescriptive when testing for flexible responses like port numbers. Using specific values in expected outputs can cause unnecessary test failures when the AI generates different but equally valid responses.
🪛 LanguageTool
docs/cncf-self-assesment.md
[style] ~60-~60: As a shorter alternative for ‘able to’, consider using “can”.
Context: ...following.** * Human-in-the-loop: users are able to interact with and guide HolmesGPT inves...
(BE_ABLE_TO)
[grammar] ~67-~67: Ensure spelling is correct
Context: ...applicable.** Lightweight, can run as a standaone local CLI or in-cluster as an HTTP serv...
(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)
[style] ~116-~116: This phrase is redundant. Consider writing “point” or “time”.
Context: ...rmissions with which Holmes runs at any point in time and Holmes will identify it and adapt *...
(MOMENT_IN_TIME)
🪛 markdownlint-cli2 (0.17.2)
docs/cncf-self-assesment.md
6-6: Bare URL used
(MD034, no-bare-urls)
18-18: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
19-19: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
20-20: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
21-21: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
60-60: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
61-61: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
62-62: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
63-63: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
64-64: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
100-100: Bare URL used
(MD034, no-bare-urls)
103-103: Bare URL used
(MD034, no-bare-urls)
113-113: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
114-114: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
115-115: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
116-116: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
117-117: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
118-118: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
119-119: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
120-120: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
123-123: Bare URL used
(MD034, no-bare-urls)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
- GitHub Check: llm_evals
- GitHub Check: Pre-commit checks
- GitHub Check: Pre-commit checks
🔇 Additional comments (1)
docs/cncf-self-assesment.md (1)
135-135: Broken link referenceThe PDF link is reported broken. Verify the target or replace with the up-to-date CNCF SSCP location to avoid 404s.
There was a problem hiding this comment.
Actionable comments posted: 0
🧹 Nitpick comments (6)
docs/cncf-self-assesment.md (6)
18-21: Use a single list marker style across the documentStars (
*) are mixed with dashes (-). Markdown-lint already flags this (MD004). Convert the four bullet points below to dashes to stay consistent with the rest of the file.-* Community feedback from users and contributors, gathered through GitHub issues, Slack, and regular discussions -* Strategic alignment with the project’s long-term mission: enabling AI-powered root cause analysis in cloud-native environments -* Technical priorities based on gaps surfaced during usage or contributor pain points -* Upstream integration plans with core CNCF projects like Prometheus, Kubernetes, and OpenTelemetry +- Community feedback from users and contributors, gathered through GitHub issues, Slack, and regular discussions +- Strategic alignment with the project’s long-term mission: enabling AI-powered root-cause analysis in cloud-native environments +- Technical priorities based on gaps surfaced during usage or contributor pain points +- Upstream integration plans with core CNCF projects like Prometheus, Kubernetes, and OpenTelemetry
60-64: Second occurrence of mixed list markersThe design-principles list also uses stars—switch to dashes for consistency.
-* Human-in-the-loop: users are able to interact with and guide HolmesGPT investigations -* Safety-first - The agent is restricted by default and only allowed to run safe commands. -* Interoperable – works seamlessly with existing observability stacks -* Kubernetes-native: Works with Prometheus, Loki, and other CNCF stack components. -* Extensible: Modular plugin system for adding new data sources, including external MCP servers +- Human-in-the-loop: users can interact with and guide HolmesGPT investigations +- Safety-first – the agent is restricted by default and allowed to run only safe commands +- Interoperable – works seamlessly with existing observability stacks +- Kubernetes-native – works with Prometheus, Loki, and other CNCF stack components +- Extensible – modular plugin system for adding new data sources, including external MCP servers
113-120: Third list-style inconsistencyApply the same dash marker to the security-tenets list.
-* Make security a design requirement - see above. -* Applying secure configuration has the best user experience - also covered above -* Selecting insecure configuration is a conscious decision - Users must make a conscious and concerted effort to add insecure toolsets (data sources) to HolmesGPT - it cannot be done accidentally. -* Transition from insecure to secure state is possible - users are free to reduce the permissions with which Holmes runs at any point in time and Holmes will identify it and adapt -* Secure defaults are inherited - by default Holmes inherits service roles and permissions from its environment -* Exception lists have first class support - users can add their own toolsets to give Holmes access to additional commands -* Secure defaults protect against pervasive vulnerability exploits - in the case of Holmes, this is equivalent to providing security even when used with malicious/hallucinating LLM which is done as described above -* Security limitations of a system are explainable - Holmes reports permission issues when encountered +- Make security a design requirement – see above +- Applying secure configuration has the best user experience – also covered above +- Selecting insecure configuration is a conscious decision – users must explicitly add insecure tool-sets; it cannot be done accidentally +- Transition from insecure to secure state is possible – users can reduce Holmes’s permissions at any time and Holmes will adapt +- Secure defaults are inherited – by default Holmes inherits service roles and permissions from its environment +- Exception lists have first-class support – users can add their own tool-sets to grant Holmes additional commands +- Secure defaults protect against pervasive vulnerability exploits – this ensures safety even when an LLM misbehaves +- Security limitations of a system are explainable – Holmes reports permission issues when encountered
69-70: Clarify wording of service-dependency section
No relevant.is grammatically incomplete and a bit vague. Recommend:-No relevant. +None.
128-129: Avoid redundant phrasing“Least minimal privileges” is tautological. Prefer “minimum privileges” or “least privilege”.
-Explain the least minimal privileges required by the project and reasons for additional privileges. +Explain the minimum privileges required by the project and reasons for any additional permissions.
100-103: Wrap bare URLs in Markdown linksBare URLs trigger MD034 and hurt readability.
-Please refer to https://robusta-dev.github.io/holmesgpt/installation/cli-installation/ +See the [CLI installation guide](https://robusta-dev.github.io/holmesgpt/installation/cli-installation/). @@ -Please refer to https://robusta-dev.github.io/holmesgpt/walkthrough/ +See the [quick walkthrough](https://robusta-dev.github.io/holmesgpt/walkthrough/).
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
docs/cncf-self-assesment.md(1 hunks)
🧰 Additional context used
🧠 Learnings (2)
📓 Common learnings
Learnt from: nherment
PR: robusta-dev/holmesgpt#610
File: .github/workflows/llm-evaluation.yaml:39-42
Timestamp: 2025-07-08T08:45:41.069Z
Learning: The robusta-dev/holmesgpt codebase has comprehensive existing validation for Azure environment variables (AZURE_API_BASE, AZURE_API_KEY, AZURE_API_VERSION) and MODEL in tests/llm/utils/classifiers.py, tests/llm/conftest.py, and holmes/core/llm.py. Don't suggest adding redundant validation logic.
docs/cncf-self-assesment.md (2)
Learnt from: nherment
PR: robusta-dev/holmesgpt#610
File: .github/workflows/llm-evaluation.yaml:39-42
Timestamp: 2025-07-08T08:45:41.069Z
Learning: The robusta-dev/holmesgpt codebase has comprehensive existing validation for Azure environment variables (AZURE_API_BASE, AZURE_API_KEY, AZURE_API_VERSION) and MODEL in tests/llm/utils/classifiers.py, tests/llm/conftest.py, and holmes/core/llm.py. Don't suggest adding redundant validation logic.
Learnt from: Sheeproid
PR: robusta-dev/holmesgpt#586
File: tests/llm/fixtures/test_ask_holmes/03_what_is_the_command_to_port_forward/test_case.yaml:4-4
Timestamp: 2025-07-02T10:27:17.231Z
Learning: In LLM-as-judge test cases for HolmesGPT, expected outputs should be descriptive rather than prescriptive when testing for flexible responses like port numbers. Using specific values in expected outputs can cause unnecessary test failures when the AI generates different but equally valid responses.
🪛 LanguageTool
docs/cncf-self-assesment.md
[style] ~60-~60: As a shorter alternative for ‘able to’, consider using “can”.
Context: ...following.** * Human-in-the-loop: users are able to interact with and guide HolmesGPT inves...
(BE_ABLE_TO)
[style] ~116-~116: This phrase is redundant. Consider writing “point” or “time”.
Context: ...rmissions with which Holmes runs at any point in time and Holmes will identify it and adapt *...
(MOMENT_IN_TIME)
🪛 markdownlint-cli2 (0.17.2)
docs/cncf-self-assesment.md
6-6: Bare URL used
(MD034, no-bare-urls)
18-18: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
19-19: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
20-20: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
21-21: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
60-60: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
61-61: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
62-62: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
63-63: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
64-64: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
100-100: Bare URL used
(MD034, no-bare-urls)
103-103: Bare URL used
(MD034, no-bare-urls)
113-113: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
114-114: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
115-115: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
116-116: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
117-117: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
118-118: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
119-119: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
120-120: Unordered list style
Expected: dash; Actual: asterisk
(MD004, ul-style)
123-123: Bare URL used
(MD034, no-bare-urls)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (7)
- GitHub Check: build (3.12)
- GitHub Check: build (3.10)
- GitHub Check: build (3.11)
- GitHub Check: build (3.12)
- GitHub Check: build (3.10)
- GitHub Check: build (3.11)
- GitHub Check: llm_evals
🔇 Additional comments (1)
docs/cncf-self-assesment.md (1)
134-135: Broken supply-chain best-practices linkThe comment notes the link is broken. Please verify and update to the canonical CNCF SSCP PDF URL (currently
https://github.com/cncf/tag-security/blob/main/assessments/CNCF_SSCP_v1.pdf) or remove the link altogether.
No description provided.