Hybrid AI Analysis
Combined deterministic rules with language-model analysis to support different levels of incident complexity.
Full-Stack Development · AI Integration
A full-stack application for analyzing CI/CD pipeline logs, identifying potential failures, and classifying incident severity. Combines rule-based analysis with language models to balance flexibility and operating costs.

The Project
CI/CD pipelines generate logs that can contain valuable information about software failures. However, interpreting those logs often requires identifying relevant error messages, distinguishing their severity, and determining which parts of the output are most useful for debugging.
I developed AI Incident CoPilot to explore how automated analysis can support this process. The application accepts pipeline logs, evaluates potential incidents, and presents structured analysis through a web dashboard.
Rather than relying exclusively on a language model, the system combines local rules with AI-assisted interpretation. This approach reflects my interest in building AI applications that are practical, maintainable, and conscious of operating costs.
Key Contributions
Combined deterministic rules with language-model analysis to support different levels of incident complexity.
Built functionality to analyze CI/CD logs, identify potential failures, and classify incident severity.
Connected a Python-based analysis backend to an interactive Next.js dashboard.
Behind the Build
AI Incident CoPilot is structured as a full-stack application with a Next.js frontend and a Python FastAPI backend. The frontend provides an interface for submitting logs and reviewing analysis results, while the backend handles incident interpretation.
The architecture separates user interaction from the analysis logic, allowing the backend to evaluate incoming log data independently of the presentation layer.
The application brings together log processing, incident classification, and AI-assisted interpretation within a single workflow.
A central design decision was using a hybrid approach rather than sending every incident directly to a language model.
Straightforward cases can be handled through local rules, while more complex cases can use AI-assisted analysis. This creates a practical distinction between tasks that benefit from deterministic logic and those that may require more flexible interpretation.
The approach is intended to reduce unnecessary model usage while preserving the ability to generate richer analysis when appropriate.
This project demonstrates an important engineering principle: integrating AI effectively involves deciding when not to use it.
The application accepts CI/CD pipeline logs and evaluates their contents for indicators of failures or operational problems.
The analysis workflow classifies incidents by severity and produces information intended to help users understand what may have gone wrong.
Severity classification provides structure to the results, helping distinguish lower-priority events from incidents that may require closer investigation.
The backend uses FastAPI to expose incident-analysis functionality through an HTTP interface.
The frontend is built with Next.js and TypeScript, providing an interactive dashboard where users can submit logs and review generated results.
The implementation required coordinating request handling, analysis selection, response formatting, and the presentation of incident information.
Separating these responsibilities makes it easier to refine the analysis logic without rebuilding the user interface.
The primary architectural tradeoff involved balancing the flexibility of language-model analysis against the predictability and lower operating cost of local rules.
Rule-based methods are useful when failure patterns are recognizable, but they may be less effective when logs contain unfamiliar or ambiguous problems.
Language models can provide more flexible interpretation, but their responses require careful evaluation and may introduce additional latency, cost, or uncertainty.
The hybrid design explores how these approaches can complement each other rather than treating either one as universally preferable.
The project demonstrates a full-stack incident-analysis workflow that connects log submission, severity classification, and AI-assisted interpretation.
It also provided experience designing a system in which different analysis strategies can be selected based on the characteristics of the input.
Potential future improvements include evaluation against a larger collection of real-world incident logs, more sophisticated failure-pattern detection, and quantitative comparisons of analysis cost and response quality.
The application is an engineering demonstration. Formal claims about diagnostic accuracy, cost savings, or production reliability would require additional evaluation.