Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,5 @@ dist
*.db-shm
*.db-wal
*.log
**/__pycache__
**/*.pyc
7 changes: 7 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -47,3 +47,10 @@ TRUSTED_PROXY_HOPS=1
WORKER_MONITOR_HOST=127.0.0.1
WORKER_MONITOR_PORT=4319
SHUTDOWN_TIMEOUT_MS=10000

# Remote Streamable HTTP MCP is disabled by default. When enabled behind a
# trusted TLS proxy, this must be the exact public origin clients use.
MCP_HTTP_ENABLED=false
# MCP_HTTP_PUBLIC_ORIGIN=https://agent-data.example.com
# Keep false for read-only integrations such as Azure SRE Agent investigations.
MCP_HTTP_WRITE_ENABLED=false
13 changes: 13 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,19 @@ jobs:
shell: pwsh
run: ./scripts/validate-deployments.ps1

microsoft-integrations:
name: Microsoft agent integrations
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-python@v6
with:
python-version: "3.12"
cache: pip
cache-dependency-path: examples/microsoft-agent-framework/validation-requirements.txt
- run: python -m pip install --disable-pip-version-check --quiet -r examples/microsoft-agent-framework/validation-requirements.txt
- run: python scripts/validate-microsoft-integrations.py

postgres:
name: PostgreSQL integration
runs-on: ubuntu-latest
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,11 +31,18 @@ jobs:
with:
node-version: 24
cache: npm
- uses: actions/setup-python@v6
with:
python-version: "3.12"
cache: pip
cache-dependency-path: examples/microsoft-agent-framework/validation-requirements.txt
- uses: docker/setup-qemu-action@v4
- uses: docker/setup-buildx-action@v4
- name: Use supported npm
run: npm install --global npm@12.0.2
- run: npm ci --no-audit --no-fund
- run: python -m pip install --disable-pip-version-check --quiet -r examples/microsoft-agent-framework/validation-requirements.txt
- run: python scripts/validate-microsoft-integrations.py
- name: Validate release tag
run: |
git fetch origin main:refs/remotes/origin/main
Expand Down
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ dist/
*.db-shm
*.db-wal
*.log
__pycache__/
*.pyc
.DS_Store
**/.terraform/
*.tfstate
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

## Unreleased

- Added authenticated, read-only-by-default Streamable HTTP MCP for remote
agent hosts, with exact public-origin validation and per-request identity
checks.
- Added validated Microsoft Agent Framework and Azure SRE Agent integration
examples.

## 1.1.0

- Added framework-neutral agent middleware with bounded context compilation,
Expand Down
8 changes: 7 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -269,6 +269,12 @@ use the remote HTTP adapter. Direct MCP remains available when the model host
already owns context assembly and turn lifecycle. See
[Agent Middleware](docs/AGENT_MIDDLEWARE.md).

Runnable integrations are included for
[Microsoft Agent Framework](examples/microsoft-agent-framework) and
[Azure SRE Agent](examples/azure-sre-agent). The former demonstrates local
stdio and production Streamable HTTP MCP. The latter configures ADK as a
durable incident-context connector and custom SRE specialist.

## When it fits

Use Agentic Data Kernel when several of these are true:
Expand Down Expand Up @@ -303,7 +309,7 @@ Package entry points and commands:
| PostgreSQL TypeScript | `agentic-data-kernel/production` |
| Embedded CLI | `agentic-data` or `agentic-data-kernel` |
| Production CLI | `agentic-data-prod` |
| MCP | `agentic-data-kernel mcp` or `agentic-data-prod mcp` |
| MCP | `agentic-data-kernel mcp`, `agentic-data-prod mcp`, or production `POST /mcp` |
| HTTP | `POST /v1/execute` |

Source checkout:
Expand Down
4 changes: 4 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,10 @@ issue.
- Do not grant `effects:reconcile` to ordinary API clients.
- Restrict `/metrics` and health endpoints at the network layer when operational
metadata is considered sensitive.
- Keep remote MCP disabled unless needed. When enabled, configure its exact
public HTTPS origin, preserve the public Host header at the proxy, and keep
write tools disabled unless a narrowly scoped identity and approval boundary
are in place.
- Back up the PostgreSQL database and encrypted artifact directory together.
- Sign backup manifests with `BACKUP_MANIFEST_KEY` stored outside the backup
location.
Expand Down
12 changes: 6 additions & 6 deletions benchmarks/sre/results/report.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@

Generated from `summary.json`.

Source revision: `4716f98095b9010911c2b952bc0f370d599315e9`
Source revision: `a0308b84ec3f85a1f74db1b767b7c866b7d4fc21`

Source hash: `f83a13452a3e6b6efa545a468d88394e43f25e64c21b5b312cfa550bf96079bd`
Source hash: `85a4b1683bd2281a016d54fb3fe72b9af3f139d22c6d8c480e294d183ded71d5`

## Correctness

Expand All @@ -24,11 +24,11 @@ Both variants must resolve every run with one delivery and one reconciliation.

The adapter delegates to the shipped SRE scenario, which contains
930 nonblank TypeScript source lines inside the
dependency. The full kernel dependency contains 16424
dependency. The full kernel dependency contains 16709
nonblank TypeScript source lines.

The benchmark runner and engine-specific audit verification contain
1443 nonblank TypeScript source lines.
1445 nonblank TypeScript source lines.
They are excluded from both application columns. Dependency and harness code
is not application-authored, but it remains code that must be understood,
operated, or upgraded.
Expand All @@ -44,8 +44,8 @@ operated, or upgraded.

| Variant | Median milliseconds |
| --- | ---: |
| Conventional PostgreSQL | 50.75 |
| Agentic Data Kernel | 898.69 |
| Conventional PostgreSQL | 51.26 |
| Agentic Data Kernel | 900.22 |

Runtime is not a headline metric. The variants perform different work and this
deterministic smoke benchmark is not a latency study.
Expand Down
24 changes: 12 additions & 12 deletions benchmarks/sre/results/summary.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@
"environment": {
"node": "v22.22.2",
"postgres": "18.6 (Debian 18.6-1.pgdg12+2)",
"commit": "4716f98095b9010911c2b952bc0f370d599315e9",
"sourceHash": "f83a13452a3e6b6efa545a468d88394e43f25e64c21b5b312cfa550bf96079bd"
"commit": "a0308b84ec3f85a1f74db1b767b7c866b7d4fc21",
"sourceHash": "85a4b1683bd2281a016d54fb3fe72b9af3f139d22c6d8c480e294d183ded71d5"
},
"runs": [
{
Expand All @@ -31,7 +31,7 @@
"provider reconciliation": true,
"verification and terminal state": true
},
"durationMs": 55.4837
"durationMs": 53.41859999999997
},
"operatedTables": 8,
"databaseBytes": 540672
Expand Down Expand Up @@ -59,7 +59,7 @@
"provider reconciliation": true,
"verification and terminal state": true
},
"durationMs": 927.7570999999999
"durationMs": 900.2152000000001
},
"operatedTables": 18,
"databaseBytes": 1572864
Expand Down Expand Up @@ -87,7 +87,7 @@
"provider reconciliation": true,
"verification and terminal state": true
},
"durationMs": 50.752899999999954
"durationMs": 47.721500000000106
},
"operatedTables": 8,
"databaseBytes": 540672
Expand Down Expand Up @@ -115,7 +115,7 @@
"provider reconciliation": true,
"verification and terminal state": true
},
"durationMs": 898.6871000000001
"durationMs": 829.989
},
"operatedTables": 18,
"databaseBytes": 1572864
Expand Down Expand Up @@ -143,7 +143,7 @@
"provider reconciliation": true,
"verification and terminal state": true
},
"durationMs": 50.02570000000014
"durationMs": 51.25579999999991
},
"operatedTables": 8,
"databaseBytes": 540672
Expand Down Expand Up @@ -171,7 +171,7 @@
"provider reconciliation": true,
"verification and terminal state": true
},
"durationMs": 840.5906000000004
"durationMs": 945.9665
},
"operatedTables": 18,
"databaseBytes": 1572864
Expand Down Expand Up @@ -266,19 +266,19 @@
"authoredTables": 0,
"operatedTables": 18,
"scenarioSourceLines": 930,
"dependencySourceLines": 16424
"dependencySourceLines": 16709
}
},
"benchmarkHarness": {
"nonblankLines": 1443
"nonblankLines": 1445
},
"databaseBytes": {
"conventionalPostgresMedian": 540672,
"agenticDataKernelMedian": 1572864
},
"runtimeMillisecondsInformational": {
"conventionalPostgresMedian": 50.752899999999954,
"agenticDataKernelMedian": 898.6871000000001
"conventionalPostgresMedian": 51.25579999999991,
"agenticDataKernelMedian": 900.2152000000001
},
"explanationQuestions": 9,
"claims": {
Expand Down
2 changes: 2 additions & 0 deletions benchmarks/sre/run.ts
Original file line number Diff line number Diff line change
Expand Up @@ -572,6 +572,8 @@ function testConfig(
shutdownTimeoutMs: 10_000,
workerMonitorHost: "127.0.0.1",
workerMonitorPort: 4319,
mcpHttpEnabled: false,
mcpHttpWriteEnabled: false,
};
}

Expand Down
4 changes: 4 additions & 0 deletions deploy/CONTRACT.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,9 @@ durability semantics.
## Networking

- Expose only the API.
- Remote MCP shares the API listener at `/mcp`; expose it only when
`MCP_HTTP_ENABLED=true` and `MCP_HTTP_PUBLIC_ORIGIN` exactly matches the
trusted public HTTPS origin.
- Terminate TLS at the managed ingress or load balancer.
- Set `TRUSTED_PROXY_HOPS` to the exact number of trusted forwarding hops and
prevent direct access to the Node.js listener.
Expand All @@ -116,6 +119,7 @@ durability semantics.
endpoint, and effect destinations. Standard Kubernetes NetworkPolicy cannot
filter HTTPS by hostname.
- Configure `EFFECT_ALLOWED_HOSTS` explicitly.
- Keep `MCP_HTTP_WRITE_ENABLED=false` for read-only agent integrations.

## Health and rollout

Expand Down
5 changes: 5 additions & 0 deletions deploy/aws/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,3 +94,8 @@ Do not update the image while leaving `services_enabled = true`.

Secrets are referenced by ARN and are not created by this module. Do not pass
secret values through `.tfvars`.

Remote MCP shares the ALB-backed API at `/mcp`. Enable it with
`mcp_http_enabled`, configure the exact HTTPS `mcp_http_public_origin`, and
leave `mcp_http_write_enabled` false unless a narrowly scoped write identity
and review boundary are in place.
5 changes: 4 additions & 1 deletion deploy/aws/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,10 @@ locals {
{ name = "TRUSTED_PROXY_HOPS", value = "1" },
{ name = "WORKER_MONITOR_HOST", value = "0.0.0.0" },
{ name = "WORKER_MONITOR_PORT", value = "4319" },
{ name = "SHUTDOWN_TIMEOUT_MS", value = "10000" }
{ name = "SHUTDOWN_TIMEOUT_MS", value = "10000" },
{ name = "MCP_HTTP_ENABLED", value = tostring(var.mcp_http_enabled) },
{ name = "MCP_HTTP_PUBLIC_ORIGIN", value = var.mcp_http_public_origin },
{ name = "MCP_HTTP_WRITE_ENABLED", value = tostring(var.mcp_http_write_enabled) }
]
runtime_secrets = [
{ name = "DATABASE_URL", valueFrom = var.secret_arns.database_url },
Expand Down
3 changes: 3 additions & 0 deletions deploy/aws/terraform.tfvars.example
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@
# embedding_base_url = "https://api.openai.com/v1"
# artifact_current_key_id = "v1"
# effect_allowed_hosts = "payments.example.com,deployments.example.com"
# mcp_http_enabled = true
# mcp_http_public_origin = "https://agent-data.example.com"
# mcp_http_write_enabled = false
# services_enabled = false
#
# secret_arns = {
Expand Down
39 changes: 39 additions & 0 deletions deploy/aws/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,45 @@ variable "effect_allowed_hosts" {
default = ""
}

variable "mcp_http_enabled" {
description = "Expose authenticated Streamable HTTP MCP at /mcp."
type = bool
default = false
}

variable "mcp_http_public_origin" {
description = "Exact public HTTPS origin used for remote MCP Host and Origin validation."
type = string
default = ""

validation {
condition = (
var.mcp_http_public_origin == "" ||
can(regex(
"^https://([A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?)(\\.([A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?))*(:([1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?/?$",
var.mcp_http_public_origin
))
)
error_message = "mcp_http_public_origin must be an HTTPS DNS origin with an optional port from 1 through 65535."
}

validation {
condition = !var.mcp_http_enabled || var.mcp_http_public_origin != ""
error_message = "mcp_http_public_origin is required when mcp_http_enabled is true."
}
}

variable "mcp_http_write_enabled" {
description = "Expose execute_operation through remote MCP. Keep false for read-only agents."
type = bool
default = false

validation {
condition = !var.mcp_http_write_enabled || var.mcp_http_enabled
error_message = "mcp_http_write_enabled requires mcp_http_enabled."
}
}

variable "services_enabled" {
description = "Set true only after bootstrap and migration tasks succeed."
type = bool
Expand Down
6 changes: 6 additions & 0 deletions deploy/azure/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,3 +106,9 @@ already present in the container's system trust store.
Container Apps terminates TLS for its managed public hostname. Use an internal
environment plus Application Gateway or Front Door when organizational policy
requires private ingress, WAF, or centralized custom-domain TLS.

To expose remote MCP for Microsoft Agent Framework or Azure SRE Agent, set
`mcpHttpEnabled = true` and set `mcpHttpPublicHostname` to the exact public DNS
hostname. The template constructs the HTTPS origin and rejects schemes, ports,
paths, queries, and credentials. Keep `mcpHttpWriteEnabled = false` for
investigation-only connectors.
Loading