Kumoss Compose Deployment Topology

Kumoss Compose Deployment Topology An architecture diagram generated by Archify. authz · FastAPI :8083, no volume · Compose project kumoss, one bridge network authz FastAPI :8083, no volume mapping · FastAPI :8081 · Compose project kumoss, one bridge network mapping FastAPI :8081 notifications · FastAPI :8080 · Compose project kumoss, one bridge network notifications FastAPI :8080 phoenix · Phoenix :6006, phoenix-db · Compose project kumoss, one bridge network phoenix Phoenix :6006, phoenix-db iac · OpenTofu :8082, workspaces · Compose project kumoss, one bridge network iac OpenTofu :8082, workspaces core · FastAPI :8000, workspaces · Compose project kumoss, one bridge network core FastAPI :8000, workspaces object-storage · RustFS, object_storage_data · Compose project kumoss, one bridge network object-storage RustFS, object_storage_data proxy · Nginx + SPA, :80 and :9000 · Compose project kumoss, one bridge network proxy Nginx + SPA, :80 and :9000 core-db · PostgreSQL 17, core_db_data · Compose project kumoss, one bridge network core-db PostgreSQL 17, core_db_data redis · Redis 8 :6379 · Compose project kumoss, one bridge network redis Redis 8 :6379 User's browser · outside the bridge network · Architecture component User's browser outside the bridge network :80 and :9000 /api + SSE /monitoring/ project check mappings fire-and-forget engine jobs artifacts asyncpg cache Compose project kumoss, one bridge network Legend Frontend Backend Database Cloud

Published surface

  • • Only proxy publishes host ports: :80 for SPA, API, SSE and /monitoring/, :9000 for presigned URLs
  • • Every other container is internal-only via expose
  • • core calls the LLM and git APIs; notifications posts to the Slack webhook

The shared workspaces volume

  • • core and iac mount workspaces read-write, so the engine runs on the core git clones
  • • Both run as kumoss, uid/gid 10001 via KUMOSS_UID and KUMOSS_GID
  • • Each run clones into a unique directory and deletes it in a finally block

Persistence and start-up

  • • Named volumes: core_db_data, phoenix_db_data, object_storage_data, workspaces
  • • The authz JSON role store has no volume and is lost on recreation
  • • depends_on orders start-up without health checks; the prompt seeder retries phoenix