Skip to content

Current Stack, Solution, and IA Map

현재 스택 · 솔루션 · IA 맵 (Current Stack, Solution, and IA Map)

Section titled “현재 스택 · 솔루션 · IA 맵 (Current Stack, Solution, and IA Map)”

마지막 검토: 2026-05-10

이 문서는 더 오래된 스택 스냅샷을 대체합니다. FractalOps 스택 소유권, 솔루션 배치, 정보 구조(IA), 외부 기술 가정의 현재 라우팅 문서이자 단일 원천(SSOT)입니다.

협상 불가 제품 경계 (Non-Negotiable Product Boundary)

Section titled “협상 불가 제품 경계 (Non-Negotiable Product Boundary)”

FractalOps는 조직의 메타 컨트롤 플레인입니다.

onboarding -> work -> proposal -> proof -> reflective improvement

이 루프를 운영하는 데 필요한 실행 substrate는 강하게 소유합니다. 인접 도구는 런타임 실행·identity·secret·proof·lineage·delivery 상태를 직접 제공하지 않는 한 통합 endpoint로 남습니다.

  1. Constitution 및 canonical architecture
  2. 런타임 토폴로지 및 스택 운영 카탈로그
  3. Kubernetes/Argo GitOps 매니페스트
  4. 패키지 매니페스트 및 lockfile
  5. 외부 공식 벤더 문서
  6. 역사적 문서

역사적 문서는 이 페이지를 덮어쓸 수 없습니다. 요구사항이 이 페이지와 충돌하면, 오래된 요구사항 페이지를 갱신하거나 여기로 다시 연결하세요.

flowchart TB
  portal["Portal"] --> proposal["Proposal Plane"]
  proposal --> studio["Studio / Agent Execution"]
  studio --> run["AgentSquad 또는 AgentSquad run"]
  run --> ws["Daytona workspace / execution slot"]
  ws --> adapter["agent process adapter"]
  adapter --> armory["Armory MCP & skills"]
  armory --> gh["GitHub App PR / issue 증거"]
  gh --> proof["Semantics + DataHub + ClickHouse + Chronicle"]
PlaneFractalOps RoleNot Allowed
SemanticsOntology, identity, lineage meaningBulk telemetry store
DataHubCatalog, searchable lineage, entity/aspect metadataMutation gate or proof authority
MimirRuntime metrics and build/cache time seriesProof facts or ontology
GlitchTipApplication error/performance tracking (Sentry-compatible)Metrics TSDB, ontology, or proof authority
ClickHouseProof facts, event analytics, warehouse projectionsLong-form wiki body store or metrics TSDB
Chronicle/WORMLong-term evidence artifacts and provenanceUI state store
GitHub AppIssue, PR, review, merge identityHuman PAT route for agents
OpenBaoSecret and runtime credential authorityPlain env drift
OpenTelemetryTrace/metric/log signal transportProduct ontology replacement

현재 패키지 베이스라인 (Current Package Baseline)

Section titled “현재 패키지 베이스라인 (Current Package Baseline)”
AreaCurrent Baseline
Python>=3.11, managed through uv
BackendFastAPI, Pydantic v2, SQLAlchemy v2, Supabase SQL migrations
Agent processCodex, Claude, and Antigravity CLI adapters
Durable workflowTemporal Python SDK
RDF/ontologyrdflib
ObservabilityOpenTelemetry API/SDK/OTLP HTTP, Mimir metrics store
Error trackingGlitchTip 6.1.8 (Sentry-compatible), per-project DSN auto-provisioned by project_factory
Frontend package managerpnpm@10.24.0
PortalAstro >=6.4.0, React 19, Tailwind >=4.3.0, DaisyUI 5
Portal stateNanostores plus route-local React state where needed
Flow UI@xyflow/react; topology flows must share palette/node patterns
Browser automationPlaywright ^1.59.1, routed through PlaywrightGrid for runtime work

도구는 모두 repo-local입니다. make uv-bootstrap이 uv를 ./.tools/uv에만 설치하고, 모든 명령은 make 타깃 또는 ./.tools/uv/uv run으로 실행합니다(전역 pip install 금지).

스택 운영 카탈로그 (Stack Operation Catalog)

Section titled “스택 운영 카탈로그 (Stack Operation Catalog)”

라이브 FractalOps 스택 카탈로그(2026-05-10 생성)에서 가져왔습니다. 현재 목록은 CLI로 직접 확인할 수 있습니다.

Terminal window
fops stacks list --compact
# stack_list_command (backend/src/fractalops/cli_commands/operations.py) →
# {"count": N, "stacks": [{"stackId": ..., "primaryOperationId": ..., "operationCount": ...}, ...]}
fops stacks operations <stack-id> # 한 스택의 연산 목록
fops stacks validate # 스택 운영 카탈로그 검증
StackPrimary OperationOwnership Class
argocdargocd/fractalops-argocd-self.application.yamlGitOps substrate
clickhousebootstrap_clickhousewarehouse/proof fact plane
cloudflaredinstall_cloudflared_openbaoedge connector
daytonacreate_project_daytona_workspaceexecution workspace substrate
datahubargocd/runtime/resources/datahub.application.yamlcatalog/lineage plane
dokployconfigure_dokploy_git_transportpersistent backing services + static delivery endpoint
evidencebootstrap_supabaseSupabase Storage backed by SeaweedFS evidence storage
fractalopsargocd/runtime/resources/fractalops-*.application.yamlproduct runtime
gitopsreconcile_connector_ssottopology reconciliation
headlampargocd/runtime/resources/headlamp.application.yamlKubernetes operator UI endpoint
k3sreconcile_k3s_oidcKubernetes execution substrate
kafkabootstrap_kafkaevent/log stream substrate
langboardcreate_project_daytona_workspaceproject lifecycle and issue surface
openbao-secret-deliveryreconcile_connector_ssotsecret delivery chain
penpotbootstrap_daytona_penpot_argocddesign endpoint
pomeriumargocd/runtime/resources/pomerium.application.yamlzero-trust access edge
runtime-storagestorage_surface_metricsstorage pressure and cleanup
nexusreconcile_nexus_fractalopsinternal package + docker/build cache registry (folds the former registry-cache LXC)
windmillwindmill_runbook_catalogrunbook and lightweight automation endpoint
LayerCurrent Direction
Clusterk3s remains the near-term runtime cluster.
NetworkingCilium CNI is the target network/security substrate.
IngressGateway API is the target Kubernetes ingress contract.
PolicyDefault deny NetworkPolicy first; then explicit service egress/ingress.
Pod securityKyverno enforces Pod Security Standards, Restricted where possible.
SecretsExternal Secrets pulls from OpenBao/Vault-compatible scopes; seed material is written to OpenBao by a SPIRE-authenticated issuer, not static defaults.
Image trustSigstore/Cosign for signatures and attestations.
Workload identitySPIFFE/SPIRE SVIDs bound to per-workload ServiceAccounts; OpenBao JWT auth checks the SPIFFE subject before runtime read or seed issuance.
mTLSCilium mTLS or Istio Ambient only after SPIFFE identity is stable.
BuildPlatform CI image builds are GitOps-pinned and use the Nexus build cache. There is no per-project or in-sandbox build pipeline; dev previews are bare processes (see Dev Preview Plane).
CacheNexus owns package/OCI/build cache distribution; cache-plane owns Redis-compatible ephemeral app cache through Valkey Operator.
AutoscalingHPA exists for API/Portal/Worker; queue/resource metrics must drive future scale policy.

솔루션 소유권 매트릭스 (Solution Ownership Matrix)

Section titled “솔루션 소유권 매트릭스 (Solution Ownership Matrix)”
SolutionUser SurfaceExecution SurfaceTruth Owner
Portalyamonco/fractalops-frontend:portal Astro shellFastAPI routes and generated API facadeFrontend repo + Assembly GitOps
Project delivery/projects/*, /work/*AgentSquad on Daytona + Temporal/StudioGitHub App + Semantics
Research/research/*, /domains/research/*Research-mode AgentSquad on same runtimeAstro/Starlight repo + DataHub/wiki
AgentSquad/admin/agents/agentsquad, CLIStudio run for FractalOps self-improvementFractalOps repo issues
Platform image buildCI release pipelineGitOps-pinned image builds with the Nexus build cacheBuild evidence + registry
Dev preview planeProject workspace UIBare dev server in the Daytona sandbox + daytona-proxy signed URL; <slug>.monstore.io per projectDev Preview Plane + project delivery guard
Persistent servicesProject workspace UIDokploy (databases, static-site / vercel-sim hosting, big-facility compose)Project delivery guard
Browser proofPortal/Daytona/Agent Control SurfacePlaywrightGrid MCPChronicle evidence refs
Error trackingProject apps + GlitchTip MCP triageGlitchTip (Sentry-compatible) on fractalops-postgresqlPer-project DSN + GlitchTip org
Search/wikiResearch and AgentSquad toolsSearXNGgrid + Agent Memory ArchiveWiki body + DataHub catalog
LineagePortal lineage pagesRDF/OpenLineage/DataHub projectionSemantics/DataHub/ClickHouse
SecretsPortal credential brokerOpenBao, External Secrets, SPIFFE where availableOpenBao

프런트엔드 소스/빌드 소유권은 비공개 repo yamonco/fractalops-frontend에 있습니다. 이 repo는 백엔드 계약, 런타임 자동화, GitOps 원하는 상태만 유지합니다.

에이전트 팀 타입 (Agent Team Types)

Section titled “에이전트 팀 타입 (Agent Team Types)”

동일한 Studio, Temporal, Daytona, mailbox, GitHub App, DataHub 계보 레일을 재사용합니다. 에이전트 역할 순서, handoff 그래프, MCP/skill 적재, write 정책, repository scope, PR 제출자 정책은 Studio Team Contract가 소유합니다. 템플릿 카탈로그, Armory, 프로젝트 프로필 하이드레이션, 생성 reconciliation은 자체 역할 맵을 들지 말고 그 계약으로부터 렌더링해야 합니다.

Team TypePurposeRequired Agents
agentsquadFractalOps self-improvementCore-8 plus explicit extension packs
agentsquadProject deliveryplanner, curator, backend, frontend, tester, committer, compactor, closer
researchInvestigation and documentationinquirer, curator, scout, auditor, actor, scribe, tester, committer, closer

Research는 별도 런타임이 아닙니다. 하나의 research request, 하나의 mono repo, 하나의 Daytona workspace, 하나의 Astro/Starlight 문서 표면을 만듭니다. 후속 요청마다 그 research repo에 ticket과 PR이 생깁니다.

Portal은 랜딩 페이지가 아니라 운영 표면입니다.

GroupRoutesPurpose
Home/, /workspace, /work/*operator daily work and launch path
Projects/projects, /projects/:slug/*project assets, team, studio, proof, operations
Research/research, /research/*, /domains/research/*search, wiki, evidence, lineage, experiments
Runtime/runtimes, /admin/agents/*, /operations, /ops/*runtime state and operator controls
Data/data, /datasets, /domains, /glossarycatalog and domain graph navigation
Review/review/*, /proposals/*, /proof/*approvals, evidence gaps, proof closure
Packages/packages/*, /repos/*, /credentialspackage, repository, and credential surfaces
Admin/admin/*access workbench, templates, semantics, evidence renewal

페이지 조립 규칙 (Page Composition Rules)

Section titled “페이지 조립 규칙 (Page Composition Rules)”
LayerRule
TemplatePortalShell and PortalPageShell own persistent shell and copilot docking.
OrganismPage-specific business surfaces live under organisms.
MoleculeReusable controls, flow nodes, tables, selectors, disclosure panels.
AtomBadges, icons, brand mark, small chips.
Runtime stateGlobal shell/copilot state stays persistent; page state must not recreate global docks.

데이터 및 계보 아키텍처 (Data And Lineage Architecture)

Section titled “데이터 및 계보 아키텍처 (Data And Lineage Architecture)”

현재 방향:

flowchart LR
  action["Agent action"] --> event["structured event"]
  event --> otel["OpenTelemetry signal"]
  otel --> ch["ClickHouse fact"]
  ch --> rdf["Semantics RDF identity"]
  rdf --> dh["DataHub entity/aspect/search projection"]
  dh --> chr["Chronicle evidence ref\n(증거 산출물 존재 시)"]

OpenLineage는 이벤트 모델이 맞는 곳에서 portable run/job/dataset 계보 이벤트에 사용해야 합니다. FractalOps 고유의 agent/issue/PR/browser/proof 메타데이터는 병렬 ad hoc 이벤트 모양이 아니라 custom facet/aspect로 표현해야 합니다.

DataHub는 이미 entity와 aspect 중심으로 설계되어 있으므로, FractalOps는 다음을 투영합니다: project, repository, agent squad generation, run attempt, workspace lease, browser lease, tool loadout, issue and PR delivery, evidence artifact, wiki/search knowledge asset, dataset/feature/API/route lineage. (투영 함수 근거: tach.tomlsemantics.domain.datahub 인터페이스 — fops_project_projection, fops_run_attempt_projection, fops_workspace_lease_projection, fops_proof_closure_projection 등.)

검색 및 위키 계약 (Search And Wiki Contract)

Section titled “검색 및 위키 계약 (Search And Wiki Contract)”

SearXNGgrid는 풍부화된 검색 게이트웨이처럼 동작해야 합니다.

  1. 웹 소스를 질의한다.
  2. 내부 위키/검색 인덱스를 더 높은 우선순위로 질의한다.
  3. source, freshness, confidence, lineage ref와 함께 병합된 결과를 반환한다.
  4. stale 위키 결과를 명시적으로 표시한다.
  5. stale 결과가 교정되면 에이전트가 위키 갱신 proposal을 만들게 한다.
  6. 갱신을 DataHub와 ClickHouse로 투영한다.

위키 본문 저장소와 DataHub 카탈로그는 두 개의 단절된 제품으로 갈라지면 안 됩니다. DataHub/Elasticsearch류 발견은 entity/계보 검색에 재사용하고, 위키 콘텐츠는 본문/소스 저장소로 남깁니다.

외부 참조 베이스라인 (External Reference Baseline)

Section titled “외부 참조 베이스라인 (External Reference Baseline)”

공식 문서 확인일 2026-05-10:

StackCurrent External AssumptionOfficial Source
AstroAstro docs track latest; FractalOps Portal pins >=6.4.0.https://docs.astro.build/en/upgrade-astro/
DaytonaWorkspaces, lifecycle, scheduling, and warm workspace reconciliation remain first-class Daytona concepts.https://daytona.com/docs/
DataHubUse entities/aspects and metadata graph, not custom one-off catalog tables.https://docs.datahub.com/docs/metadata-modeling/metadata-model/
OpenLineageUse JSON-schema/OpenAPI event model and custom facets for extension.https://openlineage.io/docs/spec/
PomeriumIdentity-aware proxy for BeyondCorp/zero-trust access.https://www.pomerium.com/docs
OpenBaoSecret generation and encryption service; keep it as secret authority.https://openbao.org/
SPIFFE/SPIREKubernetes PSAT node attestation and workload registration are the target identity model.https://spiffe.io/docs/latest/deploying/configuring/
CiliumGateway API and policy integration are the target network model.https://docs.cilium.io/en/latest/network/servicemesh/gateway-api/gateway-api.html
KyvernoPod Security Standards can be enforced as Kyverno policies.https://kyverno.io/policies/pod-security/
WindmillUse scripts/flows/apps/workers/MCP for lightweight runbooks, not as durable execution replacement.https://www.windmill.dev/docs/core_concepts/mcp
Sigstore/CosignPrefer identity-based/keyless signing and attestation verification.https://docs.sigstore.dev/cosign/signing/overview/
Cloudflare TunnelOutbound cloudflared tunnel is the edge connector; avoid inbound host exposure.https://developers.cloudflare.com/tunnel/
GitHub AppAgents use GitHub App installation tokens for repo/issue/PR work.https://docs.github.com/rest/reference/apps

Deprecation 및 정리 규칙 (Deprecation And Cleanup Rules)

Section titled “Deprecation 및 정리 규칙 (Deprecation And Cleanup Rules)”
Retired/DriftCurrent Rule
alternate orchestration engines as product truthRemoved. Studio owns execution state and Temporal owns durable cadence.
local browser alternate pathNot canonical. Use PlaywrightGrid.
human PAT for agentsNot allowed. Use GitHub App.
local Docker daemon in DaytonaForbidden. docker is hard-walled in the sandbox; dev previews are bare processes (see Dev Preview Plane) and persistent services live on Dokploy.
in-sandbox compose/build-and-ship planeRemoved. There is no per-project build pipeline; platform images are CI-built and GitOps-pinned.
dagger / buildx-dev / mutagen / fops project-dev / proxy.daytonaRemoved. Preview = bare dev server + daytona-proxy signed URL on monstore.io.
raw local IP as identityNot allowed. Use domain/runtime asset/SPIFFE identity.
full graph snapshots in high-frequency evidence rowsNot allowed. Store digest summaries and lineage refs.
OpenFGA/OPA duplicated app auth mesh (removed)Cut over to SpiceDB (Zanzibar ReBAC) as the single application-resource permission SSOT.

문서 유지 규칙 (Documentation Maintenance Rule)

Section titled “문서 유지 규칙 (Documentation Maintenance Rule)”

스택이나 IA 변경은 이 페이지를 먼저 갱신한 다음, 좁은 per-stack 페이지를 갱신합니다.

필요한 갱신 증거:

fops stacks list --compact
gh repo clone yamonco/fractalops-frontend /tmp/fractalops_frontend && find /tmp/fractalops_frontend/portal/src/pages -maxdepth 4 -type f
package/lockfile delta
platform/k8s/argocd and platform/k8s/apps delta
official upstream docs link when behavior depends on a vendor feature