Back to Skills

oncall-irm

Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates, escalation chains (wait → notify schedule → notify team → webhook → auto-resolve), schedules (web + iCal + Terraform `grafana_oncall_schedule`), Slack chatops with Acknowledge/Resolve/Silence, and the P1-P4 incident lifecycle. Use when wiring Alertmanager to OnCall, deciding which team gets paged, bui

203stars17forksUpdated 7/27/2026

Security Assessment

Safe(93/100)
Security Score93/100

About oncall-irm

This skill helps engineers configure alert routing, on-call rotations, and incident response in Grafana IRM and OnCall. It solves the operational problem of getting the right alerts to the right people by covering integrations (Alertmanager, Grafana Alerting, generic webhook, PagerDuty), Jinja2 routing and grouping templates, escalation chains, schedules, Slack ChatOps, and the P1-P4 incident lifecycle. It also flags that OnCall OSS is in maintenance mode (archived March 2026) and that Grafana Cloud users should use IRM, noting the concepts are identical.

The skill is organized around common workflows with verification steps built in: wiring Alertmanager to IRM and previewing the routing template before going live, building an escalation chain (notify on-call, wait, notify team, trigger outgoing webhook, auto-resolve) and testing it with a demo alert, and creating a schedule from an iCal feed then confirming who is on-call via the API. Reference files document Jinja2 routing templates (which return True/False, first match wins), grouping ID templates, advanced template helpers, escalation-chain step types, and iCal/Terraform schedule creation. Best practices include keeping chains shallow with a definitive final step, setting send_resolved so alerts auto-resolve, and assigning integrations and schedules to teams for RBAC.

It is aimed at SRE, platform, and DevOps engineers setting up incident management. The API interactions shown use an Authorization token supplied by the user against the user's own Grafana Cloud stack; the curl calls are standard, mostly read-oriented or resource-creation operations, with credentials handled as normal API tokens rather than being harvested or exfiltrated.

FAQ

What are the prerequisites?

A Grafana Cloud stack with IRM/OnCall enabled, an API token used in the Authorization header, and a Slack workspace with admin access to install the OnCall app for ChatOps.

Should I use OnCall or IRM?

OnCall OSS is in maintenance mode and was archived in March 2026, so Grafana Cloud users should use IRM. The core concepts (escalation chains, schedules, integrations) are identical between the two.

How does alert routing work?

Each integration provides a webhook URL; incoming alerts are matched by Jinja2 routing templates that return True or False with first match wins, then handed to an escalation chain. Related alerts are consolidated using a Grouping ID template. You can preview routing with a sample payload before going live.

How do I set up an on-call schedule?

Create a schedule via the API (or Terraform grafana_oncall_schedule) using an iCal URL and optional Slack channel/user group, then verify it was created and check who is on-call now via the schedules and next_shifts API endpoints.

What are the recommended best practices?

Keep escalation chains to four levels or fewer with a definitive final step (webhook to PagerDuty or auto-resolve), always set send_resolved:true in Alertmanager, use max_alerts:100, combine Slack and mobile push for reliability, and assign integrations/schedules to teams for RBAC.

All Files

3 files
SKILL.md5.4 KB
View
references/templates-schedules.md3.2 KB
View
references/integrations.md2.1 KB
View

Install oncall-irm

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

grafana/skills