Infrastructure Operations Ecosystem Five Projects One Integrated Ecosystem Infrastructure operations, AI agent orchestration, knowledge management, secrets management, and configuration generation.
  • Rust 83.2%
  • Nushell 7.4%
  • Nickel 5%
  • Just 2.2%
  • Shell 2%
  • Other 0.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
claude-bot 874d070df6
Some checks failed
Rust CI / Security Audit (push) Has been cancelled
Rust CI / Check + Test + Lint (push) Has been cancelled
Rust CI / Check + Test + Lint-1 (push) Has been cancelled
Rust CI / Ontology Audit (optional) (push) Has been cancelled
justfile: move agent-* forwarders below the existing default recipe
Same bug as stratumiops@75a3ef9: just's default recipe is whichever is
first in the file, not whichever is named `default`. The forwarders added
in ec72ca9 landed before code/justfile's own `@default`, so a bare `just`
here started requiring agent-commit's 2 args instead of showing the recipe
list. Moved below check-tools; behavior otherwise unchanged.
2026-07-30 04:24:00 +01:00
.cargo ci: out-of-tree target dir, CI profiles, and an ontology audit job 2026-07-27 13:31:16 +01:00
.config ontoref: the wrapper, the card, the NATS topology and the local scripts 2026-07-27 13:30:38 +01:00
.github/workflows ci: out-of-tree target dir, CI profiles, and an ontology audit job 2026-07-27 13:31:16 +01:00
.typedialog/ci chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.vale chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.woodpecker ci: out-of-tree target dir, CI profiles, and an ontology audit job 2026-07-27 13:31:16 +01:00
action-nodes feat: add stratum-orchestrator with graph, state, NATS, and Nickel action nodes 2026-02-22 21:33:26 +00:00
assets/logos assets: narrow the projection to what this repo actually renders 2026-07-27 12:30:03 +01:00
config feat: add stratum-orchestrator with graph, state, NATS, and Nickel action nodes 2026-02-22 21:33:26 +00:00
crates crates: dependency bump, qdrant store, nats topology, and rustfmt 2026-07-27 13:15:22 +01:00
docs markdownlint: fit the rules to how this project actually writes 2026-07-27 13:38:46 +01:00
howto markdownlint: fit the rules to how this project actually writes 2026-07-27 13:38:46 +01:00
justfiles just: commit the task system the ontology already claims exists 2026-07-27 12:30:23 +01:00
nats ontoref: the wrapper, the card, the NATS topology and the local scripts 2026-07-27 13:30:38 +01:00
nickel/stratum-base feat: add stratum-orchestrator with graph, state, NATS, and Nickel action nodes 2026-02-22 21:33:26 +00:00
schemas/capabilities feat: add stratum-orchestrator with graph, state, NATS, and Nickel action nodes 2026-02-22 21:33:26 +00:00
scripts ontoref: the wrapper, the card, the NATS topology and the local scripts 2026-07-27 13:30:38 +01:00
templates/ontology ontoref: the wrapper, the card, the NATS topology and the local scripts 2026-07-27 13:30:38 +01:00
workspaces feat: add stratum-orchestrator with graph, state, NATS, and Nickel action nodes 2026-02-22 21:33:26 +00:00
.clippy.toml chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.gitignore config: what this repo does not track, and one hook that guarded nothing 2026-07-27 12:29:50 +01:00
.markdownlint-cli2.jsonc markdownlint: fit the rules to how this project actually writes 2026-07-27 13:38:46 +01:00
.pre-commit-config.yaml chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.rustfmt.toml chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.shellcheckrc chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.taplo.toml chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.vale.ini chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
.yamllint-ci.yml chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
card.ncl ontoref: the wrapper, the card, the NATS topology and the local scripts 2026-07-27 13:30:38 +01:00
Cargo.lock deny: migrate to cargo-deny 0.18 schema, close the license/advisory gap it hid 2026-07-30 04:06:30 +01:00
Cargo.toml crates: dependency bump, qdrant store, nats topology, and rustfmt 2026-07-27 13:15:22 +01:00
CHANGELOG.md markdownlint: fit the rules to how this project actually writes 2026-07-27 13:38:46 +01:00
CODE_OF_CONDUCT.md chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
CONTRIBUTING.md chore: Init repo, add docs 2026-01-22 22:15:19 +00:00
deny.toml deny: extend license allow-list and ignore RUSTSEC-2023-0071 2026-07-30 04:07:31 +01:00
docker-compose.dev.yml feat: add stratum-orchestrator with graph, state, NATS, and Nickel action nodes 2026-02-22 21:33:26 +00:00
justfile justfile: move agent-* forwarders below the existing default recipe 2026-07-30 04:24:00 +01:00
ontoref ontoref: the wrapper, the card, the NATS topology and the local scripts 2026-07-27 13:30:38 +01:00
README.md markdownlint: fit the rules to how this project actually writes 2026-07-27 13:38:46 +01:00
SECURITY.md chore: Init repo, add docs 2026-01-22 22:15:19 +00:00

StratumIOps Logo

StratumIOps

Infrastructure operations, AI agent orchestration, knowledge management, secrets management, and configuration generation.

Five integrated Rust projects. One ecosystem. Zero compromises.


The 4 Problems It Solves

01 · Scattered Knowledge

Decisions in Slack, guidelines in wikis, patterns in docs—all disconnected. Kogral unifies knowledge with git-native markdown and MCP for AI agents.

02 · Uncontrolled LLM Costs

No visibility or limits on AI spending per team. Vapora provides real-time budgets, automatic fallback to cheaper providers, and expertise-based agent routing.

03 · Fragile YAML Configuration

Runtime errors from untyped configuration. Provisioning uses Nickel with pre-runtime validation, TypeDialog generates forms with contract validation.

04 · Static Cryptography

No preparation for quantum threats. SecretumVault implements production post-quantum crypto (ML-KEM-768, ML-DSA-65) with pluggable backends today.


Ecosystem Projects

Project Description Metrics
Vapora AI agent orchestration with learning and cost control 13 crates, 218 tests, 50K LOC
Kogral Knowledge graph with MCP for Claude Code 3 crates, 56 tests, 15K LOC
TypeDialog Multi-backend forms (CLI, TUI, Web, AI, Agent, Prov-gen) 8 crates, 3,818 tests, 90K LOC
Provisioning Declarative IaC with Nickel + AI-assisted generation 15+ crates, 218 tests, 40K LOC
SecretumVault Secrets management with post-quantum cryptography 1 crate, 50+ tests, 11K LOC

Vapora · AI Agent Orchestration

AI agent orchestration with learning and cost control. Agents improve from experience, automatic budget fallback, NATS JetStream coordination.

  • AI agent orchestration with learning
  • Agents improve from experience
  • Automatic budget fallback
  • NATS JetStream coordination
  • 13 crates, 218 tests, 50K LOC

Kogral · Knowledge Graph

Knowledge graph with MCP for Claude Code. 6 node types (Notes, ADRs, Guidelines, Patterns, Journals, Executions). Git-native markdown with semantic search.

  • Knowledge graph with MCP for Claude Code
  • 6 node types: Notes, ADRs, Guidelines, Patterns, Journals, Executions
  • Git-native markdown storage
  • Semantic search with embeddings
  • 3 crates, 56 tests, 15K LOC

TypeDialog · Multi-Backend Forms

Multi-backend forms (CLI, TUI, Web, AI, Agent, Prov-gen). One TOML definition, 6 interfaces. Nickel contract validation.

  • 6 backends: CLI, TUI, Web, AI, Agent, Prov-gen
  • One TOML definition for all interfaces
  • Nickel contract validation
  • Conditional fields & repeating groups
  • 8 crates, 3,818 tests, 90K LOC

Provisioning · Declarative IaC

Declarative IaC with Nickel + AI-assisted generation. Multi-cloud (AWS, UpCloud, Local), RAG with 1,200+ docs, MCP server, orchestrator with rollback.

  • Declarative IaC with Nickel + AI-assisted generation
  • Multi-cloud: AWS, UpCloud, Local (LXD)
  • RAG with 1,200+ domain docs
  • MCP server for natural language queries
  • Orchestrator with automatic rollback
  • 15+ crates, 218 tests, 40K LOC

SecretumVault · Secrets Management

Secrets management with post-quantum crypto. ML-KEM-768, ML-DSA-65 (NIST FIPS 203/204). 4 crypto backends, 4 storage backends, 4 secrets engines.

  • Post-quantum crypto: ML-KEM-768, ML-DSA-65 (NIST FIPS 203/204)
  • 4 crypto backends: OpenSSL, OQS, AWS-LC, RustCrypto
  • 4 storage backends: Filesystem, etcd, SurrealDB, PostgreSQL
  • 4 secrets engines: KV, Transit, PKI, Database
  • Shamir Secret Sharing for unsealing
  • 1 crate, 50+ tests, 11K LOC

Technology Stack

  • Languages: Rust Edition 2021, Nickel, Nushell, Bash, Markdown
  • Databases: SurrealDB (multi-tenant), etcd (HA), PostgreSQL (enterprise)
  • Messaging: NATS JetStream (durable, ordered)
  • Frameworks: Axum (REST), Leptos (WASM), Ratatui (TUI)
  • Crypto: OpenSSL, OQS (Post-Quantum), AWS-LC, RustCrypto
  • Observability: Prometheus, OpenTelemetry, Grafana

Ecosystem Metrics

Metric Value
Total Rust crates 40+
Total tests 4,360+
Total LOC ~206K
Clippy warnings 0
Unsafe code blocks 0
Public API doc coverage 100%
Crypto backends 4 (OpenSSL, OQS, AWS-LC, RustCrypto)
Storage backends 4 (Filesystem, etcd, SurrealDB, PostgreSQL)
TypeDialog backends 6 (CLI, TUI, Web, AI, Agent, Prov-gen)
MCP Tools 14+
Multi-Cloud Support AWS, UpCloud, Local (LXD)
Post-Quantum Ready Yes (ML-KEM-768, ML-DSA-65)

What is StratumIOps

StratumIOps is not a single project. It's the orchestration layer that coordinates:

  • Documentation: Unified docs for all ecosystem projects (bilingual en/es)
  • Branding Assets: Logos, color schemes, web landing pages
  • Integration Patterns: How projects work together
  • Shared Standards: Language guidelines (Rust, Nickel, Nushell, Bash)

Stratum Crates

Shared infrastructure libraries for the ecosystem:

Crate Description
stratum-orchestrator Graph-driven workflow orchestrator with Saga compensation, Cedar authorization, Vault integration
stratum-graph ActionGraph core: nodes, capabilities, retry policies, backoff strategies
stratum-state Pipeline state tracker with in-memory and SurrealDB backends
stratum-llm Unified LLM providers with CLI credential detection, circuit breaker, and caching
stratum-embeddings Unified embedding providers with caching, batch processing, and VectorStore trait
stratum-daemon Optional persistent daemon: NCL export cache, file watcher, actor registry, notification barrier
stratum-db Thin SurrealDB client with schemaless CRUD, graph edges, and feature-gated backends
platform-nats NATS JetStream client with NKey auth, topology-driven stream/consumer management
ncl-import-resolver CLI tool for resolving OCI-hosted Nickel library imports to local cache

The .ontology/, adrs/, and reflection/ protocol tooling is formalized in the ontoref project.

Documentation Structure

docs/
├── en/                 # English documentation
│   ├── ia/             # AI/Development track
│   ├── ops/            # Ops/DevOps track
│   └── architecture/   # Architecture decisions (ADRs)
└── es/                 # Spanish documentation
    ├── ia/             # AI/Development track
    ├── ops/            # Ops/DevOps track
    └── architecture/   # Architecture decisions (ADRs)

Branding Assets

Complete branding system with 18+ assets:

  • 8 Logo variants: Horizontal, vertical, animated, static, dark mode
  • 4 Icon variants: Animated, static, dark mode
  • 4 Monochrome variants: Black/white for print and accessibility
  • 2 Social variants: Optimized for social platforms (1080×1080)
  • 2 Favicon variants: Browser tabs (16×16, 32×32)

See assets/branding/README.md for detailed guidelines.


Integration Patterns

Example: Kogral → Vapora

// Vapora agent queries Kogral for guidelines before generating code
async fn get_project_context(task: &Task) -> Result<ProjectContext> {
    let kogral = KogralMcpClient::connect().await?;

    let guidelines = kogral.call("get_guidelines", json!({
        "topic": &task.task_type,
        "include_shared": true,
    })).await?;

    Ok(ProjectContext { guidelines })
}

Example: TypeDialog → Provisioning

// TypeDialog prov-gen backend generates Nickel for Provisioning
async fn generate_infrastructure(form_response: &FormResponse) -> Result<WorkflowId> {
    let generator = ProvGenBackend::new();
    let iac = generator.generate(&form_response.into()).await?;

    let provisioning = ProvisioningClient::connect().await?;
    let workflow_id = provisioning.submit_workflow(iac).await?;

    Ok(workflow_id)
}

Project Local Path Git Repo
vapora /Users/Akasha/Development/vapora https://repo.jesusperez.pro/jesus/vapora
kogra /Users/Akasha/Development/kogral https://repo.jesusperez.pro/jesus/kogra
typedialog /Users/Akasha/Development/typedialog https://repo.jesusperez.pro/jesus/typedialog
provisioning /Users/Akasha/project-provisioning/provisioning https://repo.jesusperez.pro/jesus/provisioning
secretumvault /Users/Akasha/Development/secretumvault https://repo.jesusperez.pro/jesus/secretumvault

Contributing

See CONTRIBUTING.md for development guidelines, code standards, and pull request process.

Security

See SECURITY.md for security policy, vulnerability reporting, and security best practices.

Code of Conduct

See CODE_OF_CONDUCT.md for community guidelines and expected behavior.

License

Proprietary / To be defined


StratumIOps v0.1.0

Integrated ecosystem with Rust excellence

Infrastructure Operations | AI Orchestration | Knowledge Management | Secrets & Configuration

100% Rust. Zero compromises.