Map of production-wired modules (invariants live in AGENTS.md)
Version: 0.10.x
Date: 2026-09-02
Binding industrial audit: docs/audits/AUDIT_DEEP_2026-09-01_EXEC.md (waves 0–8 shipped — do not follow dump Part 6)
Earlier deep audits: docs/audits/AUDIT_DEEP_STRUCTURE_2026-08-19.md, docs/audits/AUDIT_INDUSTRY_STACK_2026-08-25.md
Companion docs: docs/docs/ops/diagnosis-map.md, docs/docs/guide/architecture.md, AGENTS.md
Honesty note: This map prioritizes production-wired paths and catalogs all source modules under main packages. Generated artifacts (docs/node_modules, docs/build, __pycache__, .venv) are excluded. Library-only modules are labeled [LIBRARY] .
Kazma is a multi-platform autonomous agent framework : one LangGraph supervisor brain , many mouths (Telegram/Discord/Slack/Web/TUI/kazma ask/kazma acp), one IDE/tool execution layer , and optional swarm multi-worker orchestration . Platform IDs never enter LangGraph state. Danger tools require HITL (three execution paths: graph interrupt, swarm bus, pipeline checkpoint) plus one gate registry (hitl_gates.db). Swarm FanOut is tri-state , not first-wins. Config is runtime-mutable via ConfigStore (SQLite or Postgres). There is no kazma-memory package.
Requirement Notes Python 3.11–3.14 Default data kazma-data/ SQLite WALOptional RAG [rag] → ChromaDB + sentence-transformersOptional multi-replica [postgres] + KAZMA_DATABASE_URLDefault bind Loopback preferred; Docker 0.0.0.0 with secret
Single-operator trusted host by default.
Production profile: KAZMA_PRODUCTION=1 (Docker code_exec, YOLO off, vault key required, workspace root required).
Multi-user SaaS foundation: platform RBAC + OIDC + opaque sessions + Postgres cutover.
Not: multi-primary multi-region write DBs without external DB product.
┌──────────────────────────────────────────────────────────────────────────────┐
│ Web UI / SSE (graph) / WS (telemetry) CLI TUI Gateway adapters │
│ Telegram/Discord/Slack GitHub OAuth/webhooks MCP IDE bridge │
└───────────────────────────────┬──────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────────────────────────┐
│ EDGE: FastAPI lifespan (app.py) │
│ Auth middleware (secret / opaque session / API token / OIDC session) │
│ Tenant middleware (prod: ignore spoofed X-Tenant-ID; JWT or default) │
│ CORS · i18n · static · health/live · health/ready (DB ping) │
└───────────────────────────────┬──────────────────────────────────────────────┘
┌─────────────────────┼─────────────────────┐
SessionManager Gateway SessionStore Swarm Task APIs
(chat threads) (platform isolation) (TaskStore)
└─────────────────────┼─────────────────────┘
┌──────────────────────────────────────────────────────────────────────────────┐
│ KazmaAgent / agent_runner → build_supervisor_graph (wires nodes) │
│ graph_supervisor / graph_tool_worker / graph_respond │
│ Checkpointer: AsyncSqliteSaver | AsyncPostgresSaver │
│ Interrupt HITL + hitl_gates.db · turn_input · context integrity trim │
│ SubAgentManager → build_child_graph (auto-deny danger) │
└───────────────────────────────┬──────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────────────────────────┐
│ LocalToolRegistry (SoT) · UnifiedToolExecutor (local + MCP force_danger) │
│ shell_exec (allowlist + env scrub) · python_exec (Docker jail / blocklist)│
│ IdeService → same tools + HITL · native skills (kazma-skills) │
└───────────────────────────────┬──────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────────────────────────┐
│ dispatch / broadcast / pipeline / fanout / consult │
│ handoff_guards (depth 5, visits 2) · ReliabilityRegistry (breakers/retry) │
│ FanOutBus tri-state HITL · NullBus fail-closed │
│ TaskStore (SQLite|Postgres) · SSE bridge · checkpoint_manager │
└───────────────────────────────┬──────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────────────────────────┐
│ ConfigStore (settings / vault / Soul) · SessionManager · checkpoints │
│ hitl_gates.db · turn journal / agent_artifacts.db │
│ TaskStore · cron.db · memory_state.db + memory_ops.db (split, do not merge) │
│ WorkspaceStore · optional Postgres (KAZMA_PG_TABLES, not whole-DB) │
└──────────────────────────────────────────────────────────────────────────────┘
├── serve.py # Alternate WebUI entry (hardened secrets)
├── pyproject.toml # Workspace package + extras [rag,postgres,…]
├── kazma.yaml # Product defaults
├── kazma.local.yaml.example # Local overrides template
├── docker-compose.yml # Single-node container
├── docker-compose.postgres.yml
├── docker-compose.ha.yml # Multi-replica + optional nginx
├── Dockerfile # [rag,postgres] image
├── scripts/ # backup, restore, migrate, smoke, entrypoint
├── docs/ # Docusaurus site + audits + ops + this map
├── tests/ # Root regression suite
├── loadtests/ # k6/locust
├── examples/ # Sample skills + demos
├── kazma-core/ # Brain, swarm, tools, safety, db
├── kazma-ui/ # FastAPI web + static + SSE
├── kazma-gateway/ # Platform adapters + slash + routers
├── kazma-tui/ # Textual dashboard/IDE
├── kazma-cli/ # `kazma` CLI
├── kazma-skills/ # Native skill packages + YAML manifests
├── kazma-data/ # Runtime DBs (local; do not commit secrets)
Module Purpose __init__.pyPackage exports agent_runner.pyKazmaAgent lifecycle, graph ensure, turn timeout, Postgres/SQLite checkpointer audit_logger.pyStructured security/ops audit events authority.pyContext authority / compaction threshold helpers authorization_flow.py[LIBRARY] Cross-division approval flowscompaction.pyMessage history compaction config_loader.pyMerged YAML (kazma.yaml + kazma.local.yaml) config_schema.pyPydantic config models config_store.pyRuntime settings SoT (SQLite or Postgres) constants.pyShared constants (danger tool lists — prefer CANONICAL) cost_breaker.pySession budget circuit breaker cultural_context.py / cultural_context_enrichment.pyCultural prompt enrichment dialect_detector.pyArabic dialect detection division_sandbox.py[LIBRARY] Division-scoped sandboxexceptions.pyShared exception types git_identity.pyBot git author identity for commits google_llm.pyGoogle/Vertex LLM paths http_pool.pyShared httpx client pool kuwaiti_tokenizer.py / msa_tokenizer.pyArabic tokenization helpers language_lock.pyResponse language lock llm_provider.pyOpenAI-compatible LLM client, retries, reconfigure aclose logging_config.pyLogging setup majlis.py[LIBRARY] Cultural orchestrator shellmcp_client.pyLegacy/alternate MCP client helpers metrics.pyMetrics helpers model_registry.py / model_registry_store.pyProvider/model resolution + persistence pacing.pyReply pacing for gateways paths.pyData path resolution permissions.py[LIBRARY] YAML permission managerpersonalities.pyPersonality prompts providers.pyProvider catalog helpers rbac.pyDivision RBAC engine (enterprise) retry.pyGeneric retry utilities router.py / routing_engine.pyRouting helpers / unified worker routing service_container.pyDI container settings_manager.py / settings_mcp.pySettings facades shutdown.pyGlobal graceful-shutdown flag state.pyAgent state types summarizer.pySummarization utility telemetry.pyTelemetry collection tenant_context.pyContextVar tenant_id time_travel.pyCheckpoint time-travel helpers token_counter.py / tokenizer.pyToken counting tone_adapter.pyTone adaptation for platforms tracing.pyLangfuse/tracer integration url_utils.pyURL helpers agent/ agent/graph_builder.pyWires the graph; does not contain HITL/retry bodies agent/graph_supervisor.pySupervisor node + _call_llm_with_retry (transient only) agent/graph_tool_worker.pyCommitment gate + HITL interrupt() + execute agent/graph_respond.pyRespond node; skips synthesis on turn_failed agent/hitl_supersede.pyCancel pending HITL on new turn agent/artifacts.pyDurable proposals/scratchpad (not graph state) agent/nonstop.pyNonStopConfig schema & settings layer agent/pipeline_schema.pyPipeline-related schemas agent/resilient_chat.pyResilient chat wrapper with retries, failover & ledger agent/state.pySupervisor state / NodeName; scratchpad merge reducer agent/sub_agent.pySubAgentManager spawn + auto_deny HITL agent/supervisor_watchdog.pySupervised execution envelope & stall watchdog agent/tool_registry.pyLocalToolRegistry SoT + built-in tools (file_append) agent/turn_input.pyBuild messages from checkpointer + user turn agent_skills/ Agent Skills install/discover/parse cron/ scheduler.py SQLite cron + concurrency + shutdowndb/ Postgres backend selection + pool + helpers delegation/ [LIBRARY] Parallel multi-agent designdocs/ [LIBRARY] Doc generatorhub/ Skill hub API/CLI/registry/validator ide/ IdeService, env_context, workspace_scope mcp/ AsyncMCPManager + UnifiedToolExecutor + classify_mcp_tool memory/ V2 cognitive engine (recall.py, memory_state.db / memory_ops.db, worker_bootstrap.py — eight schedulers) models/ Provider discovery (SSRF-guarded), model router observability/ ops_alerts, daily digest, firing ledgersafety/ hitl, hitl_gates.py, commitment/, yolo, prompt_fence security/ ssrf, ssrf_pin.py (pin-IP), vault, web_sessions, platform_rbac, oidc stores/ workspaces, bookmarks swarm/ Full orchestration (see §3.3) system/ installer, maintenance, runtime_manager tools/ Standalone tool implementations + swarm ShellTool registry voice/ STT/TTS/VAD chaos/ Chaos testing hooks cli/ Wizard helpers
Module Purpose app.pyFastAPI factory, lifespan, gateway/cron/swarm boot, router mount auth.pySecret/session/API-token auth, tenant middleware, RBAC path gates saas_api.pyMulti-user + tenants admin API session_manager.pyChat sessions (SQLite|Postgres) sse_chat/Primary SSE chat stream + YOLO intercept + HITL frames (package) turn_runtime.py / turn_document.pyTurn Delivery V2 — close_turn is the only closer hitl_status.py / hitl_gate_bridge.pyGate registry readers for Web sse_utils.pySSE framing helpers chat.pyChat page + WebSocket chat path ide_api.py/api/ide/* file/run/git/swarmworkspace_api.pyWorkspace web routes settings.pySettings HTML/API (masked secrets) dashboard.pyDashboard + session list APIs swarm_panel/*Swarm UI APIs (tasks/workers/metrics) swarm_sse.pySwarm task event streams agents.py / mcp_ui.py / skills_ui.pyFeature pages + APIs providers.py / models_route.py / models.pyProvider/model management UI health.pylive/ready public; /health/details sensitive (L-1) metrics.pyPrometheus metrics routes_direct/Login, approve, system, gateway wiring, OIDC, many APIs routes_voice.py / routes_voice_ws.pySTT/TTS REST + WS routes_chaos.pyChaos UI APIs telemetry_route.pyTelemetry SSE/snapshot gateway_monitor.pyGateway status start/stop hitl_approval.pyHITL API helpers i18n/en/ar translations (one catalog module per UI section) services.pyService status helpers static/js/*Alpine/UI modules (chat, ide, swarm, settings, streaming) templates/*Jinja pages (chat, ide, swarm, settings, login, …)
Module Purpose gateway.pyAdapter orchestration queue adapters/telegram*.pyTelegram bot + bus + callbacks + STT adapters/discord*.py / slack*.pyDiscord/Slack adapters + HITL buses agent_handler/graph.pyInbound message → agent graph agent_handler/hitl.pyGateway HITL ownership fail-closed agent_handler/commands.pySlash + /ide commands agent_handler/store.pyPlatform session isolation agent_handler/swarm_*.pySwarm dispatch/output from gateway routers/github*.pyGitHub OAuth, clone, API routers/workspaces.py / workspace.pyWorkspace CRUD + prod root confine routers/git.py / bookmarks.py / pipeline.pyGit ops, bookmarks, pipelines stores/checkpoint.pyCheckpointManager + Postgres/SQLite saver stores/sqlite.pyGateway session SQLite store mcp_server.pyIDE MCP server bridge slash_commands.py / suggestions.pyCommand catalog / UX swarm_notify.pyOpt-in Telegram notify (maybe_notify_dispatch when SWARM_BOT_TOKEN is set) telegram_format.py / typing_keepalive.py / rate_feedback.pyPlatform UX helpers
kazma-cli: main (serve/wizard/status), gateway, swarm, update, project, completions, banner, migrate.
kazma-tui: Textual app, chat/dashboard/editor/files/swarm screens, widgets (HITL modal, palette, toasts).
kazma-skills/native/*: Packaged skills (git, cron, crawler, vault, health, code-review, …) + YAML manifests.
No kazma-memory package. Arabic tokenizer is kazma_core/msa_tokenizer.py; V2 memory is kazma_core.memory.
Path Purpose scripts/backup_kazma.py / restore_kazma.pyDR zip backup/restore scripts/migrate_sqlite_to_postgres.pyFull store migration scripts/smoke_production.pyProduction smoke suite scripts/docker-entrypoint.shOptional auto-migrate then uvicorn deploy/nginx-ha.confMulti-replica reverse proxy sample
Concern Location Behavior Graph build graph_builder.py wires; bodies in graph_supervisor / graph_tool_worker / graph_respondReAct loop; max tool iterations HITL interrupt graph_tool_worker.tool_worker_node + hitl_configDanger tools interrupt(); registry row in hitl_gates.db Resume POST /api/approve/{thread_id}, gateway /hitlClaim registry + Command(resume=…) Double-gate prevent _hitl_approved_ctx ContextVarexecute() must not mint a second web gate (H-8)Turn assembly turn_input.pyCheckpointer history + user message Sub-agents sub_agent.py + build_child_graphAuto-deny danger, timeout, tool filter Persistence agent_runner / stores/checkpoint.pySQLite or AsyncPostgresSaver HITL supersede hitl_supersede.pyNew user message cancels stale interrupt
Path Module Notes Agent tools LocalToolRegistryfile_, shell_exec, python_exec, memory_ , config_*, spawn_agent(s), context_info MCP mcp/manager.pyforce_danger=True; prod HITL for non-allowlistcode_exec tools/code_exec.pyDocker network=none preferred; import blocklist local shell_exec tool_registry shlex + asyncio.to_thread(subprocess…) (Windows SelectorEventLoop — never bare create_subprocess_exec); _EXEC_CAPABLE_ARGS; env scrub; HITL IDE ide/service.pyAll mutations via registry execute
Danger SoT: safety/hitl.CANONICAL_DANGER_TOOLS → swarm _EXTENDED_DANGER.
Component Module Orchestrator swarm/engine.pyPatterns patterns.py, broadcast.py, consultation.pyHandoff limits handoff_guards.py (depth 5, visits 2)Reliability reliability.py, reliability_registry.pyDispatch worker_dispatch.py, dispatch_inner.pyPersistence task_store.py (SQLite|Postgres)Lifecycle task_lifecycle.py, task_control.pyHITL pipeline checkpoint.py, checkpoint_manager.pyBus bus.py + platform adapters; FanOut tri-state HITLAutoscaler autoscaler.py (maybe_scale only on NoCapableWorkersError)Gate registry checkpoint_manager._gate_register_pipeline / _gate_settle_pipelineMemory V2 recall.search via phonebook (fenced); not a 4-layer adapter
Service Module Cycle Swarm message bus swarm/bus.pyPub approval/report/alerts; FanOut tri-state Cron scheduler cron/scheduler.pyMust have graph_builder=; delivery_target at schedule time Memory worker memory/worker_bootstrap.pyEight schedulers (6h backup, 6h sleep, 24h reconsolidation, 15m GC, digest, ledger, drill, session purge) SSE telemetry telemetry_route.pyStream until is_shutting_down SSE chat sse_chat/ packagePer-turn stream; journal projection Swarm SSE swarm_sse.py / panelTask events Gateway queue gateway.pyAdapter inbound → handler Ops alerts observability/ops_alerts.pyIn-app FanOut + Telegram-direct; Guard is a separate process Shutdown signal shutdown.pyGlobal flag for loops
Store Backend Notes ConfigStore SQLite WAL / Postgres kazma_settings Vault refs; Soul key self_improvement.agent_evolution SessionManager SQLite / kazma_chat_sessions LRU warm cache + lock TaskStore SQLite / Postgres tables WAL + json_each workers filter Checkpoints aiosqlite / AsyncPostgresSaver HITL execution truth HITL gates hitl_gates.db (SQLite WAL)HITL decision truth; single-process Artifacts agent_artifacts.dbDurable proposals; graph is read-through V2 memory hot memory_state.dbBeliefs, episodes, entities — do not merge with ops V2 memory ops memory_ops.dbDurable queue + audit Cron cron.dbReminders; not SessionStore at fire time FTS5 SQLite + lock Keyword memory (V2) Vector / KB sqlite-vec / pgvector / Chroma optional Isolated from chat recall WorkspaceStore SQLite Repo identity columns
Surface Tech App factory FastAPI + lifespan shutdown drain Auth Secret / opaque session / API token / OIDC Chat SSE is the only turn transport (/api/chat/stream); WS is telemetry / cursor only; client projects TurnDocument IDE /ide page + /api/ide/* + CodeMirror ide.jsSwarm panel /swarm + /api/swarm/*Settings Alpine + mask_deep + kazmaConfirm/kazmaPrompt Health /health/live + /health/ready public; /health/details auth (L-1); /health/deep canary
Auth scope: Open = always open; Secret = KAZMA_SECRET / session / token when secret set; Admin = platform role admin (multi-user).
Method Endpoint Path Auth Scope HITL / Danger Description & Module GET /healthOpen — Basic health (routes_direct) GET /health/liveOpen — LB liveness (health.py) GET /health/readyOpen — Readiness + DB ping (health.py) GET /health/detailsSecret — Debug details — not public (Wave 8 L-1; leaks model/MCP) (health.py) GET /health/deepOpen — Real roundtrip canary, TTL 30s (health.py) GET /api/statusOpen — App status GET /api/telemetryOpen — Light telemetry GET /loginOpen — Multi-mode login page GET/POST /api/auth/*Open (login/status/oidc) — Auth bootstrap (routes_direct) GET /api/auth/meSecret — Principal POST /api/chat/streamSecret Graph HITL SSE agent chat (sse_chat) WS /ws/chat (if mounted)Secret Graph HITL WS chat (chat.py) POST /api/approve/{thread_id}Secret Resume interrupt HITL approve/deny/yolo scope GET/POST /api/ide/*Secret Bus HITL on mutate IDE backend (ide_api) GET/POST /api/swarm/*Secret Pipeline HITL Swarm control panel GET /api/swarm/tasks/{id}/streamSecret — Task SSE CRUD /api/settings/*Secret/Admin — Settings (settings.py) CRUD /api/saas/*Admin — Users/tenants (saas_api) GET/POST /api/mcp/*Secret/Admin MCP force_danger MCP server mgmt GET/POST /api/skills/*Secret — Skills UI GET/POST /api/agents/*Secret — Agents status/traces GET/POST /api/models/*, /api/providers/*Secret SSRF on discovery Models/providers GET/POST /api/workspace*, /api/workspaces*Secret Path confine Workspaces GET/POST /api/github/*Mixed (OAuth open callback) — GitHub OAuth/API GET/POST /api/git/*Secret shell HITL Git ops POST /api/voice/*Secret — STT/TTS GET /api/gateway/*Secret — Gateway monitor GET /metricsSecret — Prometheus POST /api/webhooks/telegramWebhook secret Agent tools Telegram webhook GET /, /chat, /ide, /swarm, …Pages: shells open; data via API — SPA-like pages GET /settings, /dashboardSecret (HTML gated) — Admin pages
/health/details is in SENSITIVE_PREFIXES. /health/live and /health/ready stay public.
Tool / Command Name Type Default Danger Sandbox Module file_read / file_list / file_search / codebase_searchLocal safe Workspace scope tool_registry + code_indexfile_write / file_deleteLocal danger Workspace + HITL tool_registryshell_execLocal danger Allowlist + env scrub + HITL tool_registrypython_exec / code_execLocal danger Docker jail / blocklist + HITL code_execmemory_search / memory_storeLocal safe / write Vector/FTS tool_registryconfig_read / config_saveLocal secrets masked / blocked sensitive ConfigStore tool_registryspawn_agent / spawn_agentsLocal danger (swarm extended)SubAgentManager tool_registry / sub_agentcurrent_datetime / context_infoLocal safe — tool_registryread_url / web_searchLocal tools pkg SSRF + pin-IP validate_url + PinHostAsyncTransport (no proxy); assert_peer_publictools/read_url, security/ssrf_pin.pyMCP tools (dynamic) MCP danger/unknown force HITL; prod non-allowlist HITL MCP server process mcp/managerkazma serveCLI — Auth required non-loopback kazma_cli/mainkazma gateway *CLI — HTTP to UI gateway.pykazma swarm *CLI dispatch may HITL HTTP API swarm.pykazma update / project / docsCLI — local CLI modules /ide * slashGateway cmd danger via tools IdeService commands.py/yoloChat/SSE bypass HITL if allowed yolo.py sse_chat / gateway/hitl approve|denyGateway resume hitl.py agent_handler
Variable Name Default Required in Prod Purpose & Security Scope KAZMA_SECRETgenerated (loopback) Yes (non-loopback)Shared admin secret / API auth KAZMA_HOST127.0.0.1 (CLI/serve)Set explicitly Bind address KAZMA_PORT9090 CLI / 8000 Docker No Listen port KAZMA_TRUST_LAN0Keep 0 LAN auto-cookie KAZMA_PRODUCTIONunset Yes (1)Force Docker code_exec, YOLO off, vault required, workspace root KAZMA_VAULT_KEYauto-dev only Yes Encrypt secrets at rest KAZMA_ALLOW_YOLOunset No (off) Opt-in YOLO under production KAZMA_YOLO_TTL_SECONDS1h No YOLO expiry KAZMA_CODE_EXEC_DOCKERauto forcecode_exec jail policy KAZMA_CODE_EXEC_IMAGEpython:3.12-slim No Jail image KAZMA_WORKSPACEdata/workspace No Default workspace pin KAZMA_WORKSPACE_ROOTunset Yes if prodConfine workspace paths KAZMA_CLONE_DIR~/kazma-repos No Clone root KAZMA_DATABASE_URLunset Multi-replica Postgres shared state KAZMA_DB_BACKENDauto Optional force postgres / sqliteKAZMA_PG_POOL_MIN/MAX1 / 10 No Pool sizing KAZMA_PG_POOL_TIMEOUT5 No Seconds to wait for a free pool connection KAZMA_PUBLIC_URLunset OAuth/OIDC Fixed public base URL KAZMA_JWT_SECRETunset Multi-tenant JWT Verified tenant claims KAZMA_CORS_ORIGINSlocalhost list Prod: your origin CORS allowlist KAZMA_OPAQUE_SESSIONS1Keep on Opaque browser sessions KAZMA_SESSION_TTL_SECONDS14d No Session cookie TTL KAZMA_TURN_TIMEOUT_SECONDS600 No Graph wall timeout KAZMA_MCP_SAFE_ALLOWLISTempty Optional MCP tools skip HITL (prod) KAZMA_ALLOW_PRIVATE_LLMunset No Private URL discovery opt-in KAZMA_MULTI_USERunset SaaS Force multi-user mode KAZMA_OIDC_*unset SaaS SSO OIDC issuer/client/secret/redirect/role claim (id_token verified; no unverified fallback) KAZMA_PGVECTORauto on Postgres DSN No 0 keeps sqlite-vec; unset auto-selects pgvector for dense recallKAZMA_E2B_API_KEY / E2B_API_KEYunset Untrusted code Firecracker python_exec; KAZMA_E2B=0 kill-switch KAZMA_TEMPORAL_HOSTunset Multi-hour swarm Temporal wrap of swarm dispatch; KAZMA_TEMPORAL=0 kill-switch KAZMA_CODE_INDEXon No 0 disables symbol index / codebase_searchKAZMA_PROVIDER / KAZMA_MODELunset No Boot provider/model KAZMA_API_KEY / OPENAI_API_KEYunset Provider LLM keys (prefer ConfigStore/vault) TELEGRAM_BOT_TOKENunset Telegram Adapter TELEGRAM_WEBHOOK_SECRETgenerated if empty Webhook Inbound authenticity DISCORD_BOT_TOKEN / SLACK_*unset Platform Adapters GITHUB_TOKEN / GITHUB_OAUTH_*unset GitHub features PAT / OAuth app KAZMA_VECTOR_*path/collection/model RAG Vector memory KAZMA_EMBED_API_KEYunset Remote embed Embeddings KAZMA_BOT_NAME / EMAILdefaults No Git identity KAZMA_DEMO_MODEunset No Demo shortcuts KAZMA_CHAOS_ENABLEDunset No Chaos routes KAZMA_ENVunset production for error redactionError detail policy KAZMA_AUTO_MIGRATE0No Docker entrypoint migrate KAZMA_SMOKE_BASElocalhost:9090 No Smoke script base URL SWARM_BOT_TOKEN / SWARM_CHAT_IDunset Optional Swarm notify bot
Cross-reference: docs/audits/REMEDIATION_PLAN_2026-07-21.md (all WP 0.x–4.x marked complete in code).
WP Target files Status 0.1 serve secret serve.pyRemediated — no assign of known secret; refuse bad; generate/loopback0.2 CLI bind kazma-cli/kazma_cli/main.pyRemediated — default 127.0.0.1; non-loopback needs secret0.3 compose docker-compose.yml, DockerfileRemediated — /health, vector path, prod env
WP Target files Status 1.1 shutdown kazma_ui/app.py _on_shutdownRemediated 1.2 reject active swarm/engine.py reject_checkpointRemediated 1.3 cancel finalize task_control.py, engine._finalize_taskRemediated 1.4 breaker probe reliability.py, worker_dispatch.pyRemediated 1.5 LLM aclose llm_provider.py reconfigureRemediated 1.6 NullBus swarm/bus.pyRemediated (False)1.7 YOLO prod safety/yolo.py, SSE/routesRemediated (+ KAZMA_ALLOW_YOLO)
WP Target files Status 2.1 discovery SSRF models/discovery.pyRemediated 2.2 code_exec tools/code_exec.pyHardened 2.3 shell policy agent/tool_registry.pyHardened 2.4 auth default-deny auth.pyRemediated 2.5 cron cron/scheduler.pyRemediated 2.6 HITL ownership agent_handler/hitl.py, routes_directRemediated 2.7 workspace root routers/workspaces.pyRemediated
Area Targets Status Opaque sessions / RBAC / OIDC web_sessions.py, platform_rbac.py, oidc.py, saas_api.pyShipped Postgres cutover config_store.py, session_manager.py, task_store.py, checkpoint.py, agent_runner.pyShipped DR / HA / smoke scripts/*, docker-compose.ha.yml, docs/ops/*Shipped
Risk Severity Notes Post-HITL shell/code still powerful High residual Intended after human approve; YOLO amplifies Untrusted MCP trust: trusted Medium Operator footgun Empty secret open mode on loopback Low–Medium Documented DX Dual docs trees / unwired libraries Low maintainability Cleanup plan Multi-primary multi-region DB N/A Infra product, not app
# Security-critical automated sample
& .venv\Scripts\ python.exe - m pytest tests / test_auth_middleware.py tests / test_hitl_wiring.py tests / test_mcp_hitl.py tests / test_pg_store_dual_backend.py - q
# Live smoke (server running)
& .venv\Scripts\ python.exe scripts\smoke_production.py -- base http: // 127.0 . 0.1 : 9090 -- secret $env:KAZMA_SECRET
Feature area Modules / surfaces Command Center / swarm live swarm.html, swarm.js, swarm_panel/*, swarm_sse.pyIDE CodeMirror editor ide.html, ide.js, ide_api.py, ide/service.py, tools/file_apply_patch.pySSE streaming chat sse_chat/ package, chat.js projector, turn_runtime.close_turnHITL Gate Registry safety/hitl_gates.py, hitl_status.py, chat.js _serverGatesWebSocket voice routes_voice_ws.py, voice.jsDocument Intelligence documents/*, documents_api.py, documents.html/js, gateway /documents, document_platform skill, TUI DocumentsPanel, scripts/certify_documents.pyGuardian health health.py, cron, circuit breakers, cost_breakerCultural/Arabic dialect, tokenizers, i18n ar, tone/pacing, majlis library Multi-agent SwarmEngine live; delegation/* library-only SaaS multi-user login multi-mode, /api/saas, header principal Postgres multi-replica db/*, dual stores, HA compose; document jobs + catalog on KAZMA_PG_TABLES when that backend is in use
Doc Role AGENTS.mdBuild contract (invariants §1–§33) docs/docs/guide/architecture.mdNarrative architecture docs/docs/guide/swarm-orchestration.mdSwarm patterns + HITL bus docs/audits/AUDIT_DEEP_2026-09-01_EXEC.mdBinding industrial audit (waves 0–8) docs/audits/AUDIT_DEEP_STRUCTURE_2026-08-19.mdDeep-structure audit docs/audits/AUDIT_PRODUCTION_READINESS_2026-07-21.mdHistorical production audit docs/audits/AUDIT_DOCUMENT_CERTIFICATION.mdDocument Intelligence cert report docs/docs/guide/document-intelligence.mdDocument product guide docs/audits/UNWIRED_INVENTORY.mdLibrary-only packages docs/docs/ops/diagnosis-map.mdMulti-path diagnosis docs/plans/GUARD_OPS_ALERTING_CAUSE_QUALITY.mdDeferred Guard/ops alerting
Refreshed 2026-09-02. Invariants live in AGENTS.md; this file is the module map. Do not list a kazma-memory package.