Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
aa65b85
docs(kb): §13 benchmark outcome + production baseline measurements
DerrickF Aug 14, 2026
91cf1da
docs(kb): clarify attachment/KB composition; de-duplicate fail-open d…
DerrickF Aug 17, 2026
5f2c98b
feat(kb): managed knowledge base migration — spec, schema and worker …
DerrickF Aug 21, 2026
ffa7a40
feat(kb): KB_Record data layer with conditional state transitions
DerrickF Aug 24, 2026
24689de
refactor(kb): backend abstraction seam behind the retrieval entry point
DerrickF Aug 24, 2026
f2e86af
feat(kb): clamp retrieval queries and fail closed on unconfirmable st…
DerrickF Aug 24, 2026
d433d6f
feat(kb): per-owner byte cap with atomic reserve / commit / release
DerrickF Aug 24, 2026
620fa49
feat(kb): managed knowledge base provisioning, retrieval and direct i…
DerrickF Aug 24, 2026
e6936b0
feat(kb): ingestion consumer with exclusive engine routing
DerrickF Aug 25, 2026
8079f7e
feat(kb): tombstone deletion sagas and the report-only reconciler
DerrickF Aug 25, 2026
58f0c6b
docs(kb): handoff document and accurate task-list state
DerrickF Aug 25, 2026
a43d80b
feat(kb): app-side authorization, IAM-enforced sharing, publication s…
DerrickF Aug 25, 2026
a361fdd
feat(kb): opt-in dual-read pilot that legacy always wins
DerrickF Aug 25, 2026
5347654
docs(kb): handoff reflects groups 11-12 and two new defects
DerrickF Aug 25, 2026
ee09197
feat(kb): migration dispatcher and the shadow/verify/promote/retain w…
DerrickF Aug 25, 2026
d5e56f3
docs(kb): handoff reflects group 13 and four more defects
DerrickF Aug 25, 2026
a8965be
docs(kb): restore defect-list ordering in the handoff
DerrickF Aug 25, 2026
e59f771
feat(kb): register the managed backend, fleet metrics, and tagged tea…
DerrickF Aug 26, 2026
4acaa8f
docs(kb): handoff reflects group 14 backend half and three more defects
DerrickF Aug 26, 2026
4523983
fix(kb): one source of truth for the managed KB tag contract
DerrickF Aug 26, 2026
70cf78b
docs(kb): handoff records the tag contract fix
DerrickF Aug 26, 2026
8fc7395
feat(kb): owner-facing upgrade surface and the enrolment path it needed
DerrickF Aug 27, 2026
b5b6b99
Merge origin/develop into feature/kb-migration
DerrickF Aug 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .github/docs/deploy/step-03-github-config.md
Original file line number Diff line number Diff line change
Expand Up @@ -110,6 +110,26 @@ The per-origin cert vars below are **optional overrides** — set one only if yo
| `CDK_MCP_SANDBOX_EXTRA_FRAME_ANCESTORS` | — | Comma-separated extra origins (beyond `https://{CDK_DOMAIN_NAME}`) allowed to embed the MCP Apps sandbox proxy via CSP `frame-ancestors`. Set to `http://localhost:4200` to point a local SPA at this deployment. **Leave unset in production.** |
| `CDK_FINE_TUNING_CORS_ORIGINS` | — | Comma-separated extra CORS origins for the SageMaker fine-tuning data bucket, beyond `https://{CDK_DOMAIN_NAME}`. Optional — fine-tuning itself is always provisioned. |

### Managed Knowledge Bases

Every variable below is **optional**. Leave them all unset for the shipped state: the managed knowledge-base backend is deployed but **dormant** — no knowledge base is created managed, no migration runs, and the daily reconciler reports what it *would* delete without deleting anything.

The three flags are independent opt-ins that each default to **off**. An unset GitHub Variable arrives at the deploy as an empty string, which is read as off — so forgetting one never silently arms it.

| Variable Name | Default | Description |
|---------------|---------|-------------|
| `CDK_MANAGED_KB_NEW_DEFAULT` | `false` | Set to `true` so newly created knowledge bases are provisioned on the managed backend instead of the legacy one. Existing knowledge bases are untouched. |
| `CDK_MANAGED_KB_MIGRATION_ENABLED` | `false` | Set to `true` to let the background migration worker run at all. While unset, the worker performs no work and its schedule stays disabled. |
| `CDK_MANAGED_KB_RECONCILER_ARMED` | `false` | Set to `true` to let the daily reconciler **delete** orphaned knowledge bases. While unset the reconciler still runs and still logs every deletion it intends to make — review those logs before arming it. |
| `CDK_MANAGED_KB_PER_OWNER_BYTES` | `104857600` (100 MB) | Per-owner stored-bytes cap for the standard role tier, **in bytes**. Deliberately below the 1 GB user-files precedent: at 30,000 users a 1 GB cap permits 30 TB. |
| `CDK_MANAGED_KB_PER_OWNER_ELEVATED_BYTES` | `1073741824` (1 GB) | Per-owner cap for the elevated, admin-granted tier, **in bytes**. |
| `CDK_MANAGED_KB_PER_KB_CEILING_BYTES` | `524288000` (500 MB) | Ceiling for any single knowledge base, **in bytes**, bounding one runaway corpus inside an owner's allowance. |
| `CDK_MANAGED_KB_RETENTION_WINDOW_DAYS` | `30` | How long legacy vector data is kept after a knowledge base is promoted to the managed backend, **in days**, so a rollback stays possible. Do not set below `30`. |
| `CDK_MANAGED_KB_STORAGE_ALARM_GB` | `500` | CloudWatch alarm threshold for **fleet-wide** managed knowledge base storage, **in GB**. The per-owner caps above bound one user; this is the only thing that bounds the whole account. |
| `CDK_MANAGED_KB_DAILY_COST_ALARM_USD` | `100` | CloudWatch alarm threshold for the rolled-up daily Knowledge-Base cost, **in USD**. Set alongside the storage alarm — per-owner caps alone permit roughly two orders of magnitude more spend than expected usage. |

> Accepted values for the three flags are `true`, `false`, `1`, `0`, or empty (empty means off). Anything else fails fast at deploy time with a message naming the variable.

---

## 3c. Authentication
Expand Down
37 changes: 37 additions & 0 deletions .github/workflows/platform.yml
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,43 @@ jobs:
# cdk.context.json stay inert.
CDK_MCP_TOKEN_ENRICHMENT_ENABLED: ${{ vars.CDK_MCP_TOKEN_ENRICHMENT_ENABLED }}
CDK_MCP_TOKEN_ENRICHMENT_CLAIMS: ${{ vars.CDK_MCP_TOKEN_ENRICHMENT_CLAIMS }}
# Managed knowledge bases (.kiro/specs/managed-kb-migration). THREE
# INDEPENDENT OPT-IN flags, all defaulting to OFF — the inverse of the
# kill-switch flags above, and the difference matters here. An unset
# GitHub Actions variable renders as an EMPTY STRING, not as absent, so
# a `!== 'false'` reading of an unset variable would resolve to TRUE and
# arm the feature on every fork. config.ts reads these with
# parseBooleanEnv, which maps both unset and empty to undefined and falls
# through to `false` (Requirement 19.8). Leave all three unset to deploy
# the managed backend without starting a fleet migration.
#
# CDK_MANAGED_KB_NEW_DEFAULT new KBs are created managed
# CDK_MANAGED_KB_MIGRATION_ENABLED the background migrator runs at all
# CDK_MANAGED_KB_RECONCILER_ARMED the daily reconciler DELETES orphans
# rather than only reporting them
#
# reconcilerArmed is the inverted one: the Reconciler is deployed and
# running from day one but DISARMED, so its judgement can be reviewed
# against real data before it deletes anything (Requirements 14.7, 19.7).
CDK_MANAGED_KB_NEW_DEFAULT: ${{ vars.CDK_MANAGED_KB_NEW_DEFAULT }}
CDK_MANAGED_KB_MIGRATION_ENABLED: ${{ vars.CDK_MANAGED_KB_MIGRATION_ENABLED }}
CDK_MANAGED_KB_RECONCILER_ARMED: ${{ vars.CDK_MANAGED_KB_RECONCILER_ARMED }}
# Storage cost controls. Byte_Caps are in BYTES (Requirement 12.2),
# defaulting to 100 MB standard / 1 GB elevated / 500 MB per knowledge
# base; the retention window is in DAYS and must stay >= 30
# (Requirement 15.11). Leave unset to take those defaults — these exist
# so an environment can tune them without a code change.
CDK_MANAGED_KB_PER_OWNER_BYTES: ${{ vars.CDK_MANAGED_KB_PER_OWNER_BYTES }}
CDK_MANAGED_KB_PER_OWNER_ELEVATED_BYTES: ${{ vars.CDK_MANAGED_KB_PER_OWNER_ELEVATED_BYTES }}
CDK_MANAGED_KB_PER_KB_CEILING_BYTES: ${{ vars.CDK_MANAGED_KB_PER_KB_CEILING_BYTES }}
CDK_MANAGED_KB_RETENTION_WINDOW_DAYS: ${{ vars.CDK_MANAGED_KB_RETENTION_WINDOW_DAYS }}
# Fleet-level alarm thresholds (Requirement 12.13). The Byte_Caps above
# bound ONE owner; these two bound the whole account, which is the gap
# between ~$169/month expected and ~$15,000/month that per-owner caps
# alone permit. Storage is in GB (default 500), daily cost in USD
# (default 100). Leave unset to take those defaults.
CDK_MANAGED_KB_STORAGE_ALARM_GB: ${{ vars.CDK_MANAGED_KB_STORAGE_ALARM_GB }}
CDK_MANAGED_KB_DAILY_COST_ALARM_USD: ${{ vars.CDK_MANAGED_KB_DAILY_COST_ALARM_USD }}
# Secrets
AWS_ROLE_ARN: ${{ secrets.AWS_ROLE_ARN }}
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
Expand Down
1 change: 1 addition & 0 deletions .kiro/specs/managed-kb-migration/.config.kiro
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"specId": "612a1431-367c-427e-8fe0-08872d03a9b9", "workflowType": "design-first", "specType": "feature"}
Loading