AI investigations
Root cause for a broken cluster, in about a minute.
An investigation is only as good as the cluster context the agent reads. Ask your own agent, click Investigate in Radar, or let Radar Cloud run it on every alert. The same cluster model sits underneath all three.
1.6–3.6×faster30–85%cheaperthan the AI SRE tools we tested, on live faultsThree ways to run one
- 4.6sissues namespace=astronomy-shop
- 4.9sget_changes namespace=astronomy-shop
- 11.8sget_resource deployment/frontend
- 12.3sget_workload_logs frontend
- 20.4sdiagnose deployment/product-catalog
- 34.8sfrontend lost CART_ADDR (was cart:8080) at 22:15:29, so checkout can't reach the cart service. Cart itself is healthy.
Open source
Your agent, over MCP
Ask Claude Code, Codex, Cursor, Copilot or any MCP agent from your terminal or IDE. Radar's MCP server answers with the cluster already correlated.
The MCP serverOpen source
Your agent CLI, run from Radar
Click Investigate on anything broken. Radar runs Claude Code, Codex, Cursor or OpenCode read-only on your machine and lays out the findings, the evidence and a fix you approve.
What you see- 1
Alert fires
A rule matches an issue on any connected cluster.
- 2
Radar Cloud investigates
Its agent runs read-only against the same cluster model.
- 3
Root cause in Slack
With the evidence, and a link to the full investigation.
Radar Cloud
Radar Cloud's own agent
Runs automatically when an alert fires, or on demand, and sends the root cause to Slack with the evidence behind it. Nothing to install on anyone's laptop.
Radar CloudWhy Radar is faster than dedicated AI SRE tools
The agent starts from a cluster model that is already joined, time-indexed and checked for failures.
Failures are already detected
Radar's Issues engine ranks failures before anyone asks. In our benchmark it was the agent's first call on all 50 faults.
Changes are on a timeline
Every spec change and event sits on a timeline, so "what changed before this broke" is one call.
Resources come back joined
Owners, topology and error-filtered logs come back correlated and secret-redacted in one response, so the agent starts with the connections already made.
Measured in the AI SRE benchmark, the Kubernetes MCP server benchmark and the MCP vs kubectl benchmark.
What the investigation workspace shows
From Radar's UI or Radar Cloud, an investigation shows its findings, the evidence behind each one and a proposed fix.
Starts from the issue
Investigate sits on the issue itself. There's no prompt to write and no context to paste.
Evidence for each claim
Evidence cards carry the log lines, events and resources the agent relied on. One click opens the real object.
Stated confidence
Established, Likely, or Still open, with the questions it couldn't settle listed plainly.
Fixes need approval
Approve a fix and it runs as a separate session. Radar then checks whether it actually worked.
Safety limits
- In Radar's UI and Radar Cloud, investigations are read-only: write tools aren't loaded. Over MCP, your agent's write access is your choice, within your RBAC.
- An approved fix runs alone, in its own session.
- Argo CD, Flux and Helm-managed changes ask first.
- Open source runs on your machine and your model account.
Why the limits live in the tool layer: Read-Only Is Not a Safety Boundary.
AI investigation questions
What is an AI investigation in Radar?
Do I need to buy an AI SRE tool?
How does Radar compare with HolmesGPT, kubectl-ai and AWS DevOps Agent?
Which agents work with Radar?
Where does my cluster data go?
Can an investigation change my cluster?
More of what Radar does in the same binary.
Connect your agent to Radar
Radar is open source, one binary. Run it on your laptop or in your cluster.
$curl -fsSL https://get.radarhq.io | sh && kubectl radarApache 2.0 · No account for local use · Run Radar OSS forever