Kumoss System Architecture

Kumoss System Architecture An architecture diagram generated by Archify. Browser · React 18 + TypeScript SPA · Architecture component Browser React 18 + TypeScript SPA OIDC provider · Entra ID, Keycloak, Auth0 · Architecture component · blank issuer = dev mode OIDC provider Entra ID, Keycloak, Auth0 blank issuer = dev mode LLM providers · routed by LiteLLM · Architecture component · Vertex AI by default LLM providers routed by LiteLLM Vertex AI by default Git hosting · GitHub, Azure DevOps, GitLab · Architecture component Git hosting GitHub, Azure DevOps, GitLab Nginx proxy · builds and serves the SPA · Kumoss stack, one Compose network · :80 and :9000 Nginx proxy builds and serves the SPA :80 and :9000 API layer · /api/v1 routers, SSE · Kumoss stack, one Compose network › core container :8000 · auth on every route API layer /api/v1 routers, SSE auth on every route Application + adapters · orchestration, LiteLLM, git · Kumoss stack, one Compose network › core container :8000 Application + adapters orchestration, LiteLLM, git Sidecar services · authz, mapping, iac, notifications · Kumoss stack, one Compose network · OpenAPI contracts Sidecar services authz, mapping, iac, notifications OpenAPI contracts object-storage · RustFS, S3 API · Kumoss stack, one Compose network · kumoss-artifacts object-storage RustFS, S3 API kumoss-artifacts core-db · PostgreSQL 17 · Kumoss stack, one Compose network · sessions, users, roles core-db PostgreSQL 17 sessions, users, roles Phoenix :6006 · traces + prompt registry · Kumoss stack, one Compose network · proxied at /monitoring/ Phoenix :6006 traces + prompt registry proxied at /monitoring/ :80 SPA, REST, SSE auth code + PKCE /api + SSE :9000 presigned GET discovery + JWKS ports to adapters HTTPS completions push + PR REST REST + bearer put + presign SQL via asyncpg OTLP + prompts Kumoss stack, one Compose network core container :8000 Legend Frontend Backend Database Reverse proxy Security External

Edge

  • • Nginx alone publishes ports
  • • Bearer token on every /v1 route but one
  • • Blank oidc.issuer_url: auth off

Core

  • • API → application → domain → adapters
  • • One OpenAPI contract per sidecar
  • • core and iac share /workspaces

State

  • • Roles and sessions: core-db, not authz
  • • Redis 8 caches core-db reads
  • • Artifacts: RustFS, S3 or Azure
  • • Dashed edges: unused as shipped