Infra8
Case studyOur productCloud and AI

DevOps Buddy: AI Help for Failed Builds, Without the Keys to Production

How we built DevOps Buddy, a read-only co-pilot for GitHub Actions and Cloudflare that explains failures and drafts fixes a person approves.

Product overview

DevOps Buddy

DevOps Buddy watches your GitHub Actions pipelines and your Cloudflare account, explains every failure in plain English, and never changes anything until you say yes.

Portfolio view of projects with health, incidents and CI success, above an AI brief
Every project and incident in one place
  • Root cause with evidenceEach failed run gets an AI root-cause analysis with a confidence level and the exact log lines behind it.
  • Fix with BuddyReview the diff, then approve. Buddy opens the pull request, follows up if checks fail, and never merges.
  • GitHub Actions and CloudflarePipeline health, run and job logs, plus Workers, Pages, D1, R2, KV, zones and DNS in one place.
  • Ask BuddyAsk questions in plain English. Answers come from the same read-only APIs, with every lookup listed.

Read-only by default. Changes only with your approval. There is a live demo that needs no sign-up.

Opens buddy.infra8.co in a new tab

Partner With Us
Product film recorded in the demo workspace with sample data. The voice-over is AI-generated.
Type
Our own product
Built by
Infra8, in-house
Runs on
Cloudflare, serverless
Area
CI/CD and cloud operations
Stack
The challenge

Why We Built It

Short answer

DevOps Buddy is our own product. It watches GitHub Actions pipelines and Cloudflare resources, explains each failure in plain English with the log lines behind it, and drafts a fix that only becomes a pull request after a person approves it. We built it to show that AI can speed up delivery without ever holding the keys to production.

Teams that ship with GitHub Actions and run on Cloudflare often find the answer to a failed build spread across several places: the red run in one tab, the failed deploy in another, the logs somewhere else. Monitoring tools say that something broke. Few help you understand why, fix it, and confirm the fix worked.

AI can read a long log far faster than a person, but most teams are right not to give an AI agent write access to their repositories or production accounts. We wanted that speed without that risk.

What we built

What DevOps Buddy Does

  • 01

    One view of everything

    Repositories, workflows and Cloudflare resources grouped into the projects and services a team actually runs, with what needs attention at the top.

  • 02

    Root cause with evidence

    Each failure gets a plain-English explanation, a confidence level and the exact log lines behind it.

  • 03

    Fix with Buddy

    Buddy drafts a fix as a readable diff. Only after a person approves does it open a pull request, on its own branch. It never merges.

  • 04

    Ask Buddy

    Questions in plain English, answered from the same read-only data, with every lookup listed.

  • 05

    Verify and automate

    Each fix is followed until the checks pass. Automations prepare the next step and, by default, wait for approval.

How it works

The System, Step by Step

A high-level view of how the pieces fit together.

From a failed run to a verified fix
  1. 01 · WatchGitHub and CloudflareRead-only access to workflow runs, logs and Cloudflare resources.
  2. 02 · GuardRead-only by designEvery monitoring and AI call passes a guard that only allows reading.
  3. 03 · ExplainAI root causeThe failure is explained, with the log lines that prove it.
  4. 04 · ApproveA person decidesThe proposed change is shown as a diff. Nothing changes without a yes.
  5. 05 · FixPull request, then verifyA pull request on Buddy's own branch, followed until the checks pass.
Engineering decisions

The Choices That Shaped It

  1. 01

    Read-only unless a person approves

    Reading and changing take separate paths. The change path allows a short list of actions, each needing a one-time approval, and it never merges, deletes or force-pushes.

  2. 02

    An audit trail for every change

    Every change made on a person's behalf is recorded: who approved it, what changed and when.

  3. 03

    Serverless from day one

    The whole product runs on Cloudflare's serverless platform with no servers to patch, and it was designed around the free plan's limits so it stays fast and cheap to run.

  4. 04

    Secrets stay sealed

    Connection tokens are encrypted at rest and are never shown or logged once they are saved.

  5. 05

    Tested where it matters

    Automated tests cover the server logic, including the safety rules, with GitHub, Cloudflare and AI responses simulated.

Inside the product

Screens From the Product

Real product screens, shown with sample data.

  • Portfolio view of projects with health, incidents and CI success, above an AI brief
    Every project and incident in one place
  • Incident inbox and root-cause analysis with log evidence
    Root cause, with the log lines that prove it
  • A proposed fix shown as a readable diff before a pull request is opened
    A diff you review before anything reaches your repo
  • Ask Buddy answering a question about a workspace in plain English
    Plain-English answers, every lookup listed
What it shows

What This Work Demonstrates

  • AI that speeds up diagnosis without holding the keys to production.
  • A fix loop that ends with proof: every change is followed until the checks pass.
  • Coverage of more than fifty Cloudflare products, added as data rather than new code.
  • No servers to manage: the product runs on Cloudflare's free plan today.

The demo, the film and the screenshots use a sample workspace, not customer data.

Related service

Cloud/DevOps management

Your cloud, CI/CD and security run for you. Starts with a free audit.

Explore Service
Keep reading

More Case Studies

Get started

Tell Us Where Your Product Is. You'll Hear Back in 24 Hours on Business Days.

  • Fixed scope
  • You own everything
  • NDA on request