Phase 7: AI-assisted query authoring (autocomplete, explain, fix, optimize, NL translation)

Adds a self-hosted (Ollama, qwen2.5-coder) model provider abstraction
with a pluggable opt-in cloud adapter, schema grounding, and a shared
cost/safety guard every AI-suggested query is assessed against --
compiling to and executing through the same unchanged Phase 2 IR/
compiler and Phase 4 tenant scoping as a hand-written query, no
parallel execution path.

Track A (built into the query bar): inline ghost-text autocomplete,
"Explain this query", "Fix this query" with a diff view, and a
rule-based "Optimize" suggestion. Track B: natural-language-to-query
translation, always a separate review step from execution, with
`sentryctl query --nl` requiring explicit confirmation to run.
Every accepted/dismissed translate-fix-optimize interaction is logged
into the same append-only audit_log table Phase 4 built.

Two real product bugs were found and fixed via live browser
verification (a Svelte effect re-running on every keystroke that
silently cancelled the ghost-text debounce; a ghost-text widget
positioned at document offset 0 instead of the cursor), and a real
costguard logic bug (unbounded-aggregation vs. raw-row) was caught by
its own test suite. New integration tests wire a real Ollama client
through the real HTTP handler against a mock server matching Ollama's
wire contract (hack/mock-ollama), keeping model-quality verification
out of CI as a disclosed, periodic human-run check instead.

See /docs/phase-7-ai-design.md and /docs/phase-7-runbook.md.
This commit is contained in:
2026-08-16 18:06:27 -07:00
parent 661568085e
commit 7d316f92db
37 changed files with 5230 additions and 20 deletions
@@ -48,6 +48,23 @@ type Config struct {
// Deployments with no Kubernetes cluster at all (docker-compose)
// never set this.
TenantCRDNamespace string
// AI gates Phase 7's AI-assisted query features, same shape and same
// env var names as api/internal/config.AIConfig -- duplicated rather
// than imported (that package is under api/internal/, which Go's
// internal/ visibility rule blocks a separate module like this one
// from importing at all, the same constraint that already moved
// querylang/executor and dashboards out of internal/ in earlier
// phases) -- matches this file's own existing pattern of
// independently defining every field even where it overlaps with
// api/internal/config's (Postgres, SearchGRPCAddr, and so on), not a
// new inconsistency introduced here.
AI AIConfig
}
type AIConfig struct {
OllamaBaseURL string
OllamaModel string
OllamaFastModel string
}
type ClickHouseAdminConfig struct {
@@ -84,6 +101,11 @@ func Load() (Config, error) {
Username: getenv("POSTGRES_USERNAME", "sentry"),
Password: getenv("POSTGRES_PASSWORD", ""),
},
AI: AIConfig{
OllamaBaseURL: getenv("OLLAMA_BASE_URL", ""),
OllamaModel: getenv("OLLAMA_MODEL", "qwen2.5-coder:7b"),
OllamaFastModel: getenv("OLLAMA_FAST_MODEL", "qwen2.5-coder:1.5b"),
},
AuditWriter: AuditWriterConfig{
Username: getenv("AUDIT_WRITER_USERNAME", "audit_writer"),
Password: getenv("AUDIT_WRITER_PASSWORD", ""),