Kumoss

Additional information

Kumoss's licensing, support channels, and how to report a security vulnerability.

This page gathers what does not fit under Guides or Reference: licensing of the default stack, how to reach the people behind a Kumoss deployment, where release notes and the changelog will be published, and where the FAQ lives.

Licensing of the default stack

Every component that runs by default in the checked-in Compose stack is open source, with one source-available exception that is disclosed rather than hidden (the bundled but inactive Terraform binary is a second, opt-in exception). Identity has no licensing footprint at all: Kumoss speaks standard OpenID Connect and trusts any spec-faithful issuer, so a fully open-source deployment can pair it with Keycloak (Apache-2.0, CNCF Incubating) while an enterprise can point it at Entra ID, Auth0, or Okta without changing a line of code.

Component Role Licence Notes

Kumoss (core, sidecars, SPA, contracts)

The platform

Apache-2.0

REUSE-compliant SPDX headers

OpenTofu 1.12.6

Default IaC engine in the iac sidecar

MPL-2.0 (Linux Foundation)

Digest-pinned. The same image also bundles HashiCorp Terraform 1.16.0 (BUSL-1.1, not OSI), downloaded and checksum-verified at build time and selectable via IAC_BINARY=terraform; running it makes your use subject to its licence terms

RustFS

Default, bundled S3-compatible object storage for artifacts (and for Terraform state where that is enabled)

Apache-2.0

Rust implementation of the S3 API; AWS S3 or Azure Blob Storage selectable via storage.provider, or any other S3-compatible endpoint via the RUSTFS provider

PostgreSQL 17

core-db and phoenix-db

PostgreSQL Licence

—

Redis 8

Fail-open cache

Tri-licensed: AGPLv3 (OSI) / RSALv2 / SSPLv1

AGPLv3 option restored in Redis 8.0

nginx

Reverse proxy and SPA host

BSD-2-Clause

—

FastAPI, LiteLLM, React, oidc-client-ts

Framework, model router, portal, OIDC client

MIT

—

OpenTelemetry / OpenInference

Tracing standard and semantic conventions

Apache-2.0

OpenTelemetry is CNCF Graduated (2026-05-21)

Arize Phoenix

Trace UI and runtime prompt registry

Elastic License 2.0 (source-available, not OSI-approved)

The only non-OSI component; disclosed in all public material

OpenID Connect

Authentication protocol

Open standard (OpenID Foundation)

No component shipped; any compliant IdP

Contact and support

Three channels, each with its own purpose:

  • Support request in the web application — questions about your own Kumoss deployment or about one of your sessions. It reaches the reviewers in your deployment, not the Kumoss project.

  • Issue tracker — bugs and feature requests in Kumoss itself. Check the existing issues first; Contributing covers what happens next.

  • Disclosure submission program — security vulnerabilities, reported privately and never through a public GitHub issue.

Support requests

Any signed-in user can send a support request from inside the web application. It goes to the people who hold the reviewer roles in your own Kumoss deployment — colleagues on your platform team, not the Kumoss project — through the channel your platform team connected (Slack in the reference setup), with a copy addressed to you.

From the browser, the chat-bubble Support icon in the header opens a form for up to 500 characters, plain text only — HTML and code formatting are rejected. The message carries your e-mail, the session id, the repository, branch, request, status, and a link to the session automatically, so you do not need to copy those in yourself. Contact Team (on a locked session) and Request Review (on the apply confirmation) send the same kind of message, pre-filled for that session, and flagged as a warning when the plan deletes or recreates resources. "Your question has been sent successfully" confirms delivery; "Your question could not be sent. Notifications are disabled." means your deployment has not connected a notification channel — use your organization’s usual support route and quote the session id.

The form calls POST /api/v1/notifications. The core forwards the request to the notifications sidecar with an audience made of the caller’s e-mail plus every user holding a panel role of editor or higher, and the bundled sidecar posts it to Slack. When services.notifications.enabled is false the route answers 503 Notifications are disabled.; when delivery fails it answers 502 Notification was not delivered.

Security

Report a security vulnerability through the disclosure submission program, in English — never through a public GitHub issue. The security team acknowledges a report within 48 hours, investigates its severity, and develops, tests, and publishes a fix and an advisory. See the security policy for the full process and the safe-harbor terms covering researchers who report in good faith.

Release notes

Kumoss has not published a tagged release yet. When it does, the curated highlights of each release — what is new and what it changes for the people using it — will be listed here and on the project’s GitHub Releases page.

Changelog

The unabridged, commit-level record of changes is the repository’s commit history; it is not duplicated here. Once releases exist, each GitHub Release carries the complete list of additions, changes, fixes, and deprecations since the previous one.

Sections

Answers to common questions about roles, requests, sessions, locks, and getting help.