# KubeMind **Kubernetes-Native AI Governance Gateway & Autonomous Control Plane** *Release v0.3.3 Β· Production Ready Β· Air-Gapped & Cloud-Native* --- ## 🌟 Core Value Proposition KubeMind intercepts, evaluates, transforms, and routes LLM requests through sub-millisecond governance pipelines: 1. **Adaptive Intent Routing**: Softmax temperature-scaled semantic classification routing prompts to optimal local or cloud models. 2. **Zero-Egress Reversible Privacy**: Inline Named Entity Recognition (Local Regex + ONNX Token Classification) that masks PII/secrets (`[KM_PERSON_1]`, `[KM_EMAIL_1]`) before dispatch and restores them in real-time over SSE streams. 3. **Fail-Closed Memory Grounding**: Mind hybrid vector knowledge retrieval (`pgvector` HNSW) that strictly returns `HTTP 503` if retrieval fails rather than allowing hallucinations. 4. **Cryptographic SHA-256 Audit Ledger**: Every routing decision, span, and policy action is appended to an immutable, tamper-evident cryptographic hash-chain. 5. **Decoupled Identity & Billing**: Native RS256 JWT validation against **OpenDesk** JWKS and self-serve metered Razorpay checkout via **PayDeck**. --- ## πŸ›οΈ High-Level System Architecture ``` β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ KUBEMIND ENTERPRISE PLATFORM β”‚ β”‚ Release v0.3.3 (master) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ β”‚ β”‚ β–Ό β–Ό β–Ό β–Ό β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Gateway & Policy β”‚ β”‚ Cloud Security β”‚ β”‚ Autonomous Agents β”‚ β”‚ Ops & Monitoring β”‚ β”‚ Client Ecosystem β”‚ β”‚ ──────────────── β”‚ β”‚ ───────────────── β”‚ β”‚ ───────────────── β”‚ β”‚ ───────────────── β”‚ β”‚ ───────────────── β”‚ β”‚ β€’ Local NER DLP β”‚ β”‚ β€’ 4-Tier RBAC β”‚ β”‚ β€’ Multi-Agent β”‚ β”‚ β€’ kmind top TUI β”‚ β”‚ β€’ @kubemind/sdk β”‚ β”‚ β€’ ONNX NER Model β”‚ β”‚ β€’ OpenDesk JWKS β”‚ β”‚ Swarm Pipeline β”‚ β”‚ β€’ kmind chat REPL β”‚ β”‚ (TypeScript) β”‚ β”‚ β€’ SSE Streaming β”‚ β”‚ β€’ HashiCorp Vault β”‚ β”‚ β€’ Native MCP β”‚ β”‚ β€’ PrometheusRules β”‚ β”‚ β€’ kubemind-sdk β”‚ β”‚ β€’ HNSW pgvector β”‚ β”‚ β€’ AWS Secrets β”‚ β”‚ Server (Claude) β”‚ β”‚ β€’ Grafana HUD β”‚ β”‚ (Python) β”‚ β”‚ β€’ Wasm Hooks β”‚ β”‚ β€’ SHA-256 Ledger β”‚ β”‚ β€’ Sandboxed Tools β”‚ β”‚ β€’ Next.js UI DAG β”‚ β”‚ β€’ Linux/Mac CLIs β”‚ β”‚ β€’ Adaptive T-Softβ”‚ β”‚ β€’ PayDeck Billing β”‚ β”‚ β€’ Tool Invocation β”‚ β”‚ β€’ Billing /billingβ”‚ β”‚ β€’ kmind fetch- β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ models CLI β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` --- ## ⚑ Request Execution & Zero-Egress Pipeline Flow ``` User Prompt (REST / SSE / SDK) β”‚ β”œβ”€β–Ί 1. RBAC & Tenant Verification β”‚ β€’ Evaluates X-API-Key or OpenDesk RS256 Bearer JWT against public JWKS β”‚ β€’ Cryptographically binds request to Workspace (admin, developer, auditor, viewer) β”‚ β”œβ”€β–Ί 2. Security & Inline Policy Engine (Runs BEFORE Classifier) β”‚ β€’ Secret Key Block: Rejects RSA keys, AWS/GCP API tokens with HTTP 403 β”‚ β€’ Privacy NER Engine: Local Regex + ONNX Bert NER masks names, emails, addresses into [KM_*] β”‚ β€’ Prompt Injection Filter: Heuristic adversarial score tagging β”‚ β”œβ”€β–Ί 3. Semantic & Exact Caching Check β”‚ β€’ Sub-millisecond exact hash & cosine nearest-neighbor lookup in Redis / pgvector β”‚ β€’ Bypassable with X-KubeMind-Cache: bypass β”‚ β”œβ”€β–Ί 4. Adaptive Intent Classification & Profile Matching β”‚ β€’ Soft-margin intent categorization (code, rag, general, log, security) β”‚ β€’ Selects provider pool and fallback cascade chain β”‚ β”œβ”€β–Ί 5. Mind Knowledge Graph Retrieval β”‚ β€’ Retrieves relevant semantic embeddings and relational context from Mind (:9081) β”‚ β€’ Fail-Closed: Outage in production returns 503 instead of risking hallucination β”‚ β”œβ”€β–Ί 6. LLM Provider Dispatch & Dynamic KMS Credential Resolution β”‚ β€’ Dispatches pseudonymized prompt to local Ollama/vLLM or Cloud Provider (KeyMint/Vault) β”‚ β”œβ”€β–Ί 7. Reversible Token Restoration & Streaming Engine β”‚ β€’ Non-Streaming: Swaps [KM_*] tokens back to original values in JSON response β”‚ β€’ Streaming (SSE): Sliding window StreamingDeAnonymizer restores entities in live token chunks β”‚ └─► 8. Cryptographic Audit Ledger & Telemetry β€’ Appends SHA-256 hash-chained receipt to Sentinel (:9083) β€’ Emits OpenTelemetry spans & Prometheus counters (kubemind_spans_ingested_total) ``` --- ## 🧩 Microservices Topology ``` β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ kmind CLI Β· Next.js Dashboard :9000 (/billing) Β· landing (marketing) β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ router :9080 Intent + Policy Gateway, SSE Streaming, KMS, MCP β”‚ β”‚ mind :9081 Knowledge Graph, pgvector Hybrid Search, Grounding β”‚ β”‚ agents :9082 Multi-Agent Swarm Orchestrator, Planning, Tool Runtime β”‚ β”‚ sentinel :9083 SHA-256 Audit Ledger, OpenTelemetry Spans, WebSocket β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ Postgres 16 (pgvector HNSW) Β· Redis 7 Β· Ollama / On-Prem Inference β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ OpenDesk :8090 Shared RS256 JWT Identity & JWKS Verification β”‚ β”‚ PayDeck :8787 Shared Razorpay Metered Billing Engine β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` | Service | Port | Key Features & Responsibilities | |---------|------|---------------------------------| | **`router`** | `9080` | Unified AI gateway: rate limiting, Wasm hooks, local NER/DLP + ONNX NER, adaptive softmax routing, HNSW semantic cache, SSE stream de-anonymization, KMS credential management, and MCP server. | | **`mind`** | `9081` | Enterprise organizational memory: pgvector hybrid vector + keyword retrieval with fail-closed grounding guarantees (`/v1/query`, `/v1/memory/query`, `/v1/graph`). | | **`agents`** | `9082` | Autonomous swarm execution: tool registry (`/v1/tools`), direct tool invocation (`/v1/tools/invoke`), and sync/async mission planner (`/v1/missions`). | | **`sentinel`** | `9083` | Cryptographic SHA-256 tamper-evident ledger, distributed trace ingestion, legal hold, audit exports (`/v1/export`), and Prometheus metrics (`/metrics`). | | **`dashboard`** | `9000` | Next.js 16 operator console with live CFO analytics, SHA-256 ledger integrity visualizer, Agent DAG workflow graph, and self-serve billing (`/billing`). | --- ## πŸš€ Quickstart ### 1. Launch the Stack ```bash cp .env.example .env make up make status ``` ### 2. Verify Health Across All Services ```bash curl -s http://localhost:9080/health # Router curl -s http://localhost:9081/health # Mind curl -s http://localhost:9082/health # Agents curl -s http://localhost:9083/health # Sentinel ``` ### 3. Run Intent Classification & Gateway Routes ```bash # Dry-run intent classification (no LLM dispatch) curl -s http://localhost:9080/v1/classify \ -H 'Content-Type: application/json' \ -d '{"prompt": "Write a Python script to compute fibonacci numbers"}' # Zero-Egress PII Masking & Reversible Restoration curl -s http://localhost:9080/v1/chat/completions \ -H 'Content-Type: application/json' \ -d '{ "model": "llama3.1", "messages": [{"role": "user", "content": "Doctor Alice Smith sent records to bob@corp.org"}] }' ``` ### 4. Fetch ONNX NER Models ```bash kmind fetch-models # Downloads ONNX NER weights to ~/.kubemind/models/ ``` --- ## πŸ§ͺ Comprehensive Automated Test Utility Run the complete 20-step end-to-end integration test suite: ```bash ./scripts/e2e_curl_test.sh ``` Logs are written to `logs/latest.log` with full request and response traces. --- ## πŸ“¦ Client SDKs - **Python SDK (`kubemind-sdk`)**: [`sdk/python/`](sdk/python) Β· `pip install kubemind-sdk` - **TypeScript / Node.js SDK (`@kubemind/sdk`)**: [`sdk/typescript/`](sdk/typescript) Β· `npm install @kubemind/sdk` - **Interactive Walkthroughs**: [`examples/`](examples) (Python & TypeScript demos) --- ## πŸ“– Documentation Index | Document | Description | |----------|-------------| | [docs/terminal-agents-guide.md](docs/terminal-agents-guide.md) | Terminal Agents (Aider, Claude Code, Python) & Existing LLMs Integration | | [docs/architecture.md](docs/architecture.md) | Canonical Reference Architecture & System Topology | | [docs/api.md](docs/api.md) | Complete Public API & `kmind` CLI Inventory | | [docs/integration.md](docs/integration.md) | OpenDesk Identity & PayDeck Billing Integration Guide | | [docs/credential-modes.md](docs/credential-modes.md) | KeyMint Zero-Trust vs Direct Credential Modes | | [charts/kubemind/README.md](charts/kubemind/README.md) | Production Kubernetes Helm Chart Configuration | --- ## πŸ“„ License MIT Β© 2026 KubeMind Authors.