Feature inventory¶
This is the source of truth for what the current checkout implements, what is enabled by default, and what remains operator-owned. “Shipped” means code, configuration, tests, and an operator path exist in this repository; it does not mean a customer-specific integration is configured.
Milestones 2–3 add durable workflows, framework agents, MCP tools, and workflow policy.
| Capability | Status | Default | Verification / boundary |
|---|---|---|---|
| Durable workflows | Shipped | Compose on; Helm/GitOps chart | Temporal with dedicated Postgres; worker-SIGKILL recovery smoke |
| Governed tool execution | Shipped | Deny unless configured in team policy | Fixed URLs, DLP, budget reservations, idempotency keys, run/step receipts |
| Framework agent steps | Shipped | Optional SDK framework dependencies | OpenAI, Anthropic, OpenAI Agents SDK, and LangGraph; local-fake Compose proof |
| Team MCP tools | Shipped | Explicit server/tool registration | Streamable HTTP 2025-03-26, argument/output DLP, costs, and receipts |
| Workflow policy | Shipped | Configured under each team | Provider/model/tool/egress allowlists and immutable run budget caps |
| Container agent steps | Shipped | Existing Kubernetes workspace required | Hardened workspace checks, scoped expiring credentials, one attempt, and completion receipts |
| Workflow token/cost budgets | Shipped | 10,000 tokens / $5 per run in SDK | Immutable team-scoped Redis counters; unknown attempts retain reservations |
| Human approvals | Shipped | Signal + query in example | Durable wait with expiry; verified approver identity and production Temporal authorization remain operator-owned |
| OpenAI chat completions | Shipped | On | Gateway tests, OpenAPI contract, local smoke |
| Legacy completions | Shipped | On, non-streaming | Gateway tests; streaming rejected explicitly |
| Embeddings | Shipped | On | Gateway tests; same auth, budget, audit, and model policy |
| Moderations | Shipped | On | Governance taxonomy, not OpenAI harm categories |
| Anthropic Messages | Shipped | On, streaming and non-streaming | Native translation through the governed chat path; streaming obeys the shared allowStreaming toggle |
| OpenAI Responses | Shipped | On, synchronous | Function tools with multi-turn tool calls and image inputs; optional state is off by default; background, streaming, and built-in tools remain out of scope |
| Responses server-side state | Shipped | Off | Tenant-scoped memory/Redis store with TTL and delete |
| Synchronous batch fan-out | Shipped | On | Per-item admission/budget/guardrail tests |
| Files + asynchronous Batch API | Shipped | Off | Bounded streaming upload, durable Redis queue with owner-token claims, object-store blobs, streamed and checkpointed processing, replay bound to the running batch and its submitter |
| Python client SDK and CLI | Shipped (typed) | Install ./sdk/python; command agentworkflows |
Isolated build/test matrix, checksums, and release artifacts; PyPI Trusted Publishing is optional |
| API-key authentication | Shipped | Local on; chart base off | Hashed keys or scoped/expiring key records |
| JWT/JWKS authentication | Shipped | Customer template on | Issuer/audience/time/algorithm validation and tenant binding |
| Model allowlist and routing | Shipped | On | Per-model primary/fallback/canary/shadow routes |
| Runtime failover | Shipped | Configured by policy | Readiness accepts a healthy declared fallback chain |
| Prompt and tool-payload admission | Shipped | On | Recursive secret/blocked-term scan and size ceilings |
| Output guardrail | Shipped | Off in base values | Scans visible content and generated tool/function arguments |
| Runtime parameter policy | Shipped | On | OpenAI parameters and reviewed runtime extensions are forwarded; control-defeating extensions (best_of > 1, beam search, chat_template, logits_processors, priority, ...) are refused; others are dropped and named in X-Dropped-Params; admission.extraForwardedParams overrides |
| Dedicated gateway metrics port | Shipped | Chart 9090; Compose uses the API port | metrics.port; the API port then answers /metrics with 404, and only networkPolicy.metricsIngressNamespaces reach the listener |
| Remote image URLs | Shipped | Off (data: only) |
admission.imageUrlAllowedHosts admits named hosts; other schemes are always refused |
| Request/body limits | Shipped | 1 MiB JSON | Files use the independent bounded batch-file ceiling |
| Rate limits and budgets | Shipped | Customer Redis profile on | Atomic shared counters; fixed windows; reservations settled against measured usage; fail policy is explicit |
| Tamper-evident audit receipts | Shipped | On | Redacted fingerprints, chain verifier, head anchors, and chain-of-chains continuity across restarts |
| Agent-action receipts | Shipped | Off | POST /v1/receipts; closed action vocabulary, tenant-bound, records claims and enforces nothing (ADR 0014) |
| RAG retrieval receipts | Shipped | On | Own chain, same primitives and same verifier as the gateway |
| Audit chain head persistence | Shipped | Memory (no continuity) | file or redis backend needed for cross-restart linkage; storage is operator-provided |
| Team web console | Shipped | On in Compose/umbrella Helm; opt-in standalone | /console; existing auth, identity switching, filtered runs, approvals, step receipts/logs, admin configuration guidance, and costs |
| Docker Compose evaluation stack | Shipped | make compose-up |
Gateway/console, cloud fakes, Temporal, Redis, worker and RAG on 127.0.0.1; optional Ollama/Open WebUI; headless browser smoke in CI; no Kubernetes network policy or agent workspaces |
| Ollama runtime | Shipped | Local profile | Pinned image; local-only model-pull egress exception |
| vLLM generation runtime | Shipped | Customer profile | NVIDIA/AMD values, explicit task, queue-based autoscaling |
| vLLM embedding runtime | Shipped | Customer profile | Dedicated --task embed release consumed by RAG |
| Lexical and Qdrant RAG | Shipped | Lexical local; Qdrant customer | Hybrid retrieval, reranker interface, collection versioning |
| RAG tenant isolation | Shipped | App default on; local shared profile off | Query and document metadata both fail closed by owner |
| Agent sandbox workspace | Shipped | Local/customer profiles | Restricted pod, no ambient token, scoped token, PVC, quotas |
| Network-policy enforcement | Shipped | Calico local default | Reachable-target deny smoke; customer CNI remains operator-owned |
| GitOps delivery | Shipped | Argo CD | Immutable release revisions; every declared app is health-gated and customer sync fails closed |
| Evidence and release gates | Shipped | CI/nightly | Conformance and model-quality evidence are labeled separately |
| Egress exception expiry | Shipped | Report-only | Rendered onto the NetworkPolicy; Kyverno denies expired, CronJob retires them when enforcement is on |
| Signed releases | Shipped | Release workflow | Tag-built multi-arch images and digest-bound charts signed with Cosign; SBOM and scans run locally (make supply-chain-check, make image-scan) |
| Multi-node model serving | Example/integration | Off | LeaderWorkerSet/Ray installation and topology are operator-owned |
| End-user multi-user chat UI | Example only | Off | Open WebUI manifest/runbook; identity and storage are operator-owned |
| Training, fine-tuning, audio, images | Out of scope | n/a | Use purpose-built systems; see Scope and non-goals |
Milestone 1 (0.2.0): OpenAI, Anthropic, Azure OpenAI, Bedrock, and Vertex Gemini adapters share model policy, budgets, DLP, settlement, and provider/cost receipts. Cloud routes are opt-in; confidential/restricted tenants and requests remain local. Provider protocols and the extended Compose walkthrough are tested with local fakes. See model selection for configuration and limits.
For operational acceptance criteria, use the Production readiness matrix. For exact supported versions, use the Version matrix.
Team operations (since 0.2.0)¶
Projects and admin/builder/approver/viewer roles extend existing sandbox identities. The authenticated API/CLI starts, lists, inspects, cancels, retries, and approves runs; timelines include provider, model, tokens, estimated cost, duration, and receipt IDs. Team provider-key mappings, shared token/USD budgets, reports, and Grafana dashboards/alerts are included. Onboarding is declarative; Temporal and workers remain trusted operator surfaces. Follow the team walkthrough.