An automated issue-fixing system that watches Jira tickets labeled autofix
and dispatches AI agents to fix bugs, review code, and manage the full
lifecycle from ticket to merged PR.
Runtime: OpenCode (agent runtime) + OpenShell (sandbox isolation). Model: Claude Sonnet 4.6 (default). Also supports open models via Ollama/LiteMaaS. Status: E2E verified locally, in OpenShell sandbox, and on OpenShift 4.21 cluster.
flowchart LR
A["๐ซ Jira<br>autofix"] --> B["๐ Watcher"]
subgraph INV["INVESTIGATE (Phases 0-4)"]
C["๐ Clone +<br>Root Cause"] --> D["๐ Plan +<br>3-Agent Audit"]
end
B --> C
D --> E
E["๐ง GATE 1<br>Human Plan<br>Review"]:::gate
subgraph IMPL["IMPLEMENT (Phases 5-11)"]
F["โ๏ธ Code Fix +<br>Tests +<br>Blocklist"] --> G["๐ค Create PR +<br>Jira Telemetry"]
end
E -->|approved| F
subgraph REV["REVIEW"]
H["๐ 3-Lens<br>Correctness<br>Security<br>Quality"]
H -->|findings| I["๐ง Review Fix"]
I -->|"< 3 cycles"| H
H -->|clean| J["โ
Done"]
end
G --> H
J --> K["๐ง GATE 2<br>Human PR<br>Review"]:::gate
K -->|approved| L["๐ Merged"]:::merged
I -->|"3 cycles"| M["โ ๏ธ Escalate"]:::fail
M -.->|"bot-retry<br>(max 2x)"| B
classDef gate fill:#fff3e0,stroke:#f57c00,stroke-width:2px
classDef fail fill:#ffebee,stroke:#c62828,stroke-width:2px
classDef merged fill:#e8f5e9,stroke:#2e7d32,stroke-width:2px
style INV fill:#e3f2fd,stroke:#1565c0
style IMPL fill:#e8f5e9,stroke:#2e7d32
style REV fill:#f3e5f5,stroke:#7b1fa2
- A user creates a Jira ticket with the
autofixlabel and includes the repository URL - The Watcher polls Jira, picks up the ticket, dispatches the Investigation Agent
- The Investigation Agent clones the repo, investigates, writes a fix plan, runs 3 audit sub-agents
- A human reviews and approves the plan
- The Implementation Agent implements the fix, runs tests, creates a PR
- The Review Agent reviews the PR (correctness, security, quality)
- The Review-Fix Agent addresses findings (max 3 cycles)
- A human approves and merges the PR
| Guide | Description |
|---|---|
| Local Quick Start | Run agents on your Mac with opencode run โ no sandbox |
| OpenShell Sandbox | Run agents in OpenShell sandbox locally โ Landlock isolation via Podman |
| OpenShift Deployment | Full cluster deployment โ watcher + OpenShell + Helm |
[Describe the bug โ what's broken, steps to reproduce, expected behavior]
## Agent Configuration
**Repository**: https://github.com/org/repo (REQUIRED)
**Branch**: main (optional)
**Commit**: abc1234def (optional)
**Skills**: (optional)
- https://raw.githubusercontent.com/org/repo/main/.claude/skills/conventions.md
**Knowledge Repo**: https://github.com/org/team-docs (optional)| Label | Meaning |
|---|---|
autofix |
Permanent marker โ ticket should be handled by automation |
bot-in-progress |
Fix agent is working on it |
bot-plan-ready |
Plan approved by auditors, awaiting human review |
bot-plan-approved |
Human adds this to authorize implementation |
bot-ready-for-review |
PR created, awaiting agent review |
bot-review-fix |
Review found issues, review-fix agent is addressing them |
bot-review-complete |
Agent review passed, awaiting human approval |
bot-merged |
PR merged, ticket ready for manual close |
bot-fix-failed |
Agent could not fix โ needs human attention |
bot-missing-info |
Ticket missing required info โ bot re-checks each cycle |
bot-retry |
Retry โ user adds to bot-fix-failed ticket to trigger re-processing (max 2) |
bot-cancelled |
Human override โ stops active sessions, returns ticket to failed state |
no-autofix |
Opt-out โ ticket excluded from automation |
| Variable | Default | Description |
|---|---|---|
PLAN_IN_PR |
true |
true: plan committed to branch + PR as audit trail. false: plan posted in Jira comment only, not in PR. |
FORK_MODE |
false |
false: push directly to ticket's repo. true: auto-fork to token owner, cross-repo PR. Details |
DEPLOY_MODE |
auto | Auto-detected: local, local+openshell, or openshift+openshell. Override if needed. |
JIRA_POLL_INTERVAL |
20 |
Minutes between watcher polling cycles |
MAX_FIX_RETRIES |
2 |
Max retry attempts when human adds bot-retry |
REVIEW_FIX_MAX_CYCLES |
3 |
Max review-fix iterations before escalation |
AUDIT_ENABLED |
true |
Enable 3-agent audit loop for fix plans |
DRY_RUN |
false |
Watcher polls Jira but makes no mutations |
SANDBOX_ENABLED |
false |
Dispatch agents in OpenShell sandboxes |
Full config reference: docs/Architecture.md โ config.env section.
| Provider | Model ID | Notes |
|---|---|---|
| Vertex AI | google-vertex-anthropic/claude-sonnet-4-6 |
Recommended default โ handles all issue types |
| Vertex AI | google-vertex-anthropic/claude-opus-4-6 |
For complex or high-priority issues |
| Ollama | ollama/deepseek-r1:32b |
Fast local option โ works for simple, well-scoped bugs |
| Ollama Cloud | ollama/minimax-m2.5:cloud |
Cloud-hosted open model โ works for simple bugs |
| LiteMaaS | litemaas/Qwen3.6-35B-A3B |
Cluster-compatible โ can investigate but struggles with implementation |
| Ollama | ollama/gemma4:31b |
Local testing only โ slow inference, limited reliability |
Note: Open models (30-35B) can often identify root causes correctly but struggle with the multi-phase implementation pipeline. The bottleneck is instruction following and tool-call reliability, not reasoning capability.
For full setup instructions, see the Model Configuration Guide.
.opencode/
โโโ agents/ # Agent definitions (fix-investigate, fix-implement, review, review-fix, 3 audit)
โโโ skills/ # Skill files (issue-investigate, issue-implement, issue-review, review-fix)
โโโ plugins/ # Safety hooks (block-destructive.js)
โโโ settings.json # Pre-allowed permissions for unattended agents
orchestrator/
โโโ watcher.py # Jira polling, label state machine, 9 phases
โโโ dispatcher.py # Agent dispatch with OpenShell sandbox support
โโโ jira_client.py # REST API client for Jira (v3 ADF parsing)
โโโ config.py # Config from env vars + projects.json
โโโ models.py # Data models (Ticket, CycleStats)
policies/ # OpenShell sandbox policies (filesystem + network)
manifests/ # K8s manifests (namespace, RBAC, PVC, secrets, deployment)
docs/ # Deployment guides and architecture
eval/ # Model evaluation results
Containerfile # UBI9 image with OpenCode, OpenShell, toolchain
opencode.json # OpenCode config โ MCP servers, instructions
AGENTS.md # Project rules loaded into agent context
| Doc | Purpose |
|---|---|
| docs/quickstart-local.md | Local development โ opencode run on your Mac |
| docs/quickstart-openshell.md | OpenShell sandbox โ local Podman isolation |
| docs/deploy-openshift.md | OpenShift cluster deployment + OpenShell |
| docs/Architecture.md | System design, label state machine, audit loop |
| docs/models.md | Model setup โ Vertex AI, Ollama, LiteMaaS providers |
| eval/README.md | Model evaluation results and benchmarking |
| CONTRIBUTING.md | How to contribute โ code standards, workflow, review process |
Initial skill patterns inspired by the AAP SDLC Harness (bugfix-workflow, code-review, git-workflow, jira-integration, ai-attribution). Skills have since been rewritten for OpenCode with structured playbooks, audit sub-agents, and MCP-based Jira integration.