Jaime

Gaetan Gouzi Publisher

Platform:

Ubuntu
26.04 24.04 22.04
Channel Revision Published Runs on
latest/edge 24 09 Oct 2026
Ubuntu 26.04 Ubuntu 24.04 Ubuntu 22.04
latest/edge 23 09 Oct 2026
Ubuntu 26.04 Ubuntu 24.04 Ubuntu 22.04
latest/edge 22 09 Oct 2026
Ubuntu 26.04 Ubuntu 24.04 Ubuntu 22.04
juju deploy jaime --channel edge

Learn about configurations >

  • api-token | string

    API token for the configured AI provider. Accepts either a Juju secret URI (secret:<id>, recommended) or a plain token string (for development only). When a secret URI is provided, Jaime reads the token field from the secret content. The token is never logged. To use a secret: run juju add-secret jaime-token token=<value>, grant it to the application, then set this field to the returned secret URI.

  • audit-log-path | string

    Default: /var/log/jaime/events.jsonl

    Path to the structured JSONL audit log.

  • cooldown-minutes | int

    Default: 30

    Minimum time before generating another report for the same unresolved incident.

  • diagnostics | string

    JSON monitoring plan describing what to collect (log files, processes, env vars, network ports, systemd units, health commands). When empty, Jaime attempts to generate this plan via AI on relation-joined. See the diagnostic schema in src/jaime/diagnostics.py for the expected format.

  • failure-timeout-minutes | int

    Default: 5

    How long a watched status must persist before a report is generated.

  • juju-api-password | string

    Password for the juju-api-user. Accepts either a Juju secret URI (secret:<id>, recommended) or a plain string (development only). When a secret URI is provided, Jaime reads the password field from the secret content.

  • juju-api-user | string

    Name of a Juju user with 'read' permission on this model, used to fetch workload statuses for co-located units from the controller API. A unit's own agent identity does not have this permission. Only required when watch-applications is non-empty. Create with: juju add-user jaime-observer juju grant jaime-observer read <model-name>

  • log-window-minutes | int

    Default: 30

    How far back Jaime should collect recent logs (minutes).

  • max-context-lines | int

    Default: 500

    Per-item cap on collected lines. Some sections apply a tighter cap (for example socket statistics and firewall rules). This is not a report or prompt total.

  • mode | string

    Default: observe

    Operating mode. 'observe': collect context and generate reports only. 'suggest': like observe, plus calls the AI provider to append diagnosis and safe manual remediation suggestions to the report. Nothing is executed. 'act': NOT YET IMPLEMENTED. Setting mode to 'act' puts the charm in blocked state until command allowlisting is implemented.

  • model | string

    AI model to use with the selected provider (optional). Any model the provider supports is accepted. When empty, a provider default is used: 'gemini-2.5-flash' for gemini and '~deepseek/deepseek-v4-flash-latest' for openrouter. Ignored when provider is 'none'.

  • provider | string

    Default: none

    AI provider to use for optional report generation. Allowed values: 'none' (no provider; the charm always produces a non-AI report), 'gemini', or 'openrouter'.

  • report-dir | string

    Default: /var/log/jaime/reports

    Directory where Markdown report artifacts are written.

  • watch-applications | string

    Comma-separated application names whose units on this machine should be watched in addition to the principal. The principal is always watched. Empty (the default) watches only the principal and opens no controller connection, so no credentials are needed. Use "*" to watch every co-located unit. Reach is bounded to units on this machine, because the collectors read the local host; units on other machines are never reported on. A configured name with no unit on this machine is skipped silently.

  • watch-statuses | string

    Default: error,blocked

    Comma-separated unit workload statuses that should open an incident.