Saltar al contenido principal

2026-08-13

Window: 2026-07-15 → 2026-08-13 (491 commits on alphaswarm). Catch-up entry summarizing the July–August development push by theme.

In plain English: this period was about making the platform safer and more auditable before real money moves. Strategy promotions now have to carry statistical evidence, human approvals expire instead of lingering, order latency is measured at six named checkpoints, and market-data vendor credentials moved out of process environment variables. Most new behaviour ships default-off behind feature flags, so nothing changes for existing deployments until an operator turns it on.

Highlights​

  • Promotion evidence (ARP slices 1–3): a unified TrialLedger records every research trial so deflated-Sharpe / overfitting statistics use an honest trial count; the lab EvidenceBundle is wired into the PromotionGateChain, and paper execution refuses to run without an ApprovedPromotion token. Bounded, point-in-time-filtered graph MCP tools (data.graph.temporal_context, data.graph.dependency_impact, data.graph.risk_neighbors, data.graph.sync_status) expose lineage without a raw Cypher surface. All default-off.
  • Approval-queue expiry: human-in-the-loop approvals for orders, promotions, and ingestion now stamp a TTL at enqueue time; a beat sweeper flips overdue rows to expired, and decide-time guards return HTTP 410 for stale decisions. Closes the gap where an old approval could fire late. Default-off (approval_expiry_enforcement_enabled). See Approval queues.
  • Six-clock order latency: six named clocks along the order path (md.event_lag → strategy.decide → oms.gate → oms.persist → broker.submit_ack → ams.apply_fill) plus end-to-end decision-to-fill, exported as OpenTelemetry histograms with a Grafana dashboard (as-six-clocks). Auto-on in paper/dev/local/test/CI. See Six-clock latency.
  • First-class alphaswarm module (ADRs 033–039): Phase 1 of the transformation plan landed — an opt-in compatibility facade (alphaswarm/facade/), an ExecutionProfile translator, a legacy Direction → PositionSide map, and a CI guard that bans legacy identifiers from reappearing.
  • Vendor-agnostic market data: every Alpaca and IBKR entry point now routes through shared vendor homes under alphaswarm/streaming/vendors/; broker/vendor keys resolve through the CredentialResolver (BYOK) before any settings fallback, so money-plane workers no longer need vendor API keys in process env. See Market-data vendors.
  • Streaming governance (ADR-0020/0021): Confluent wire framing with a dual-read decoder, schema ids from a committed bootstrap manifest (no live registry on the produce hot path), catalog-first stream addressing via KafkaDataFeed.from_feed_urn, and the 36 /streaming/* diagnostic routes turned default-off. See Streaming governance.

By area​

Research → live promotion​

  • TrialLedger (trial_families / trial_attempts, migration 0160): the single denominator for DSR/PBO statistics, seeded from lab sweep stamps. Ledger-derived N is flag-gated (ALPHASWARM_TRIAL_LEDGER_N_ENFORCE); enabling it does not auto-demote existing promotions.
  • EvidenceBundle → PromotionGateChain: promotion fails closed without DSR/PBO/trial evidence when ALPHASWARM_PROMOTION_LAB_EVIDENCE_ENFORCE is strict. Evidence crosses the plane_money_promotion boundary via a registered probe port — never a direct alphaswarm.lab import.
  • Approval expiry: enqueue TTL stamp + guarded beat sweeper + decide-time guards across order / promotion / ingestion queues; one audit event per queue sweep and an order.approval_expired lifecycle fact. Legacy rows with NULL expires_at are never default-expired.

Trading & observability​

  • Six-clock metrics: paper-path pilot first, then a DB-backed oms.persist pilot (real-Postgres p50 ≈ 34.5 ms), MD/strategy edge clocks stamping ingest_ns at feed and session boundaries, and an OTLP harvest path with a per-worker MeterProvider. PromQL names align to the unprefixed series emitted by prometheusremotewrite (oms_gate_seconds_*).
  • Paper brokerage now uses unlimited-rate paper capabilities, so simulated fills are not throttled by live rate-limit models.

Data plane​

  • Iceberg hardening: a default-off post-commit catalog/lineage reconciler (Redis intent outbox + Celery drain) closes the non-atomic gap between data commit and catalog registration; S3-backed warehouses must supply a SQL catalog URI so object-store data can't be orphaned on task recycle.
  • Vendor homes + BYOK ("Rule 55"): alpaca-py and ib_async clients are constructed only in alphaswarm/streaming/vendors/; a CI guard forbids vendor SDK imports outside the allowlist (ib_insync banned). Databento / Alpha Vantage keys moved to file mounts under /var/run/secrets.
  • Streaming: framed payloads resolve schemas by id with fail-closed behaviour on unknown ids; legacy bytes decode by topic during the dual-read transition. Topic governance counts failed dead-letter produces (alphaswarm_stream_deadletter_failed_total). ADR-0021 retired the curated Airbyte catalog and the Databento/Robinhood live scaffolds; data/sources/sec is marked legacy.
  • dbt semantic layer (in development): a committed-YAML metrics catalog and local compiler so agents and operators query named business metrics instead of hand-writing SQL — MCP tools data.dbt.* and /dbt/semantic/* routes. Warehouse execution is flag-gated; catalog/validate/compile are read-only. See dbt semantic layer.

Platform & multi-tenancy​

  • First-class module Phase 1: alphaswarm/facade/ re-export + Protocol layer; ExecutionProfile translator (default-off); Direction → PositionSide legacy map with wave-1 call-site migrations; empty-allowlist CI module-bans guard; opt-in perf and Postgres-RLS test scaffolds.
  • Control-plane fleet stores (migration 0155): cell capability sheets, tenant placement policies, append-only instance reports, and audited deploy-intent placements — DDL carried by the monolith because ADR-005 forbids the control plane importing it.
  • Supervisor leases (migration 0156): agent_run_lease with a partial unique index as the mutual-exclusion mechanism, plus a guarded lease sweeper and checkpoint retention (dry-run unless cxp_checkpoint_retention_apply is set).
  • Tenancy strategy defaults: resolve_tenancy_strategy picks shared-RLS for b2c, schema-per-tenant for b2b, database-per-enterprise for enterprise; an explicit strategy always wins.
  • ReBAC bridge: RebacAuthorizationPort adapts relationship-based authorization onto the core AuthorizationPort for document/bot share paths, fail-closed.
  • Schema readiness: /health and /readyz now distinguish "migrations pending" from "database down"; a from-zero bootstrap CI gate protects new-environment setup. A four-eyes approvals ledger requires two distinct approvers for privileged control actions.

LLM & agents​

  • LLM gateway shadow repoint (llm_gateway_route_enabled, default-off): two-gate wire-target swap to the in-cluster LiteLLM proxy; accounting/span/cache keys keep the original model id; reroute faults fail open to the direct path.
  • Semantic LLM router: signed adapter registry (HMAC-SHA256 over adapter identity, enforced at approve-time and load-time), finetune → adapter auto-registration, and an llm_router_admin API.
  • Fleet analyst perception tools (faw_tools_enabled, default-off): governed read-only market-perception tools — data.market.assess_macro, data.market.assess_vix, data.market.crypto_momentum, data.feature.news_sentiment — for the fleet analyst personas. Payloads are strictly descriptive (no recommendations).

Auth & API​

  • CLI OIDC discovery: /auth/config advertises a dedicated CLI OIDC client id and device scopes (ALPHASWARM_AUTH_CLI_OIDC_CLIENT_ID) so bare alphaswarm-cli device login works against hosts that only exposed the SPA client id.
  • Advisory central-auth probe: /readyz surfaces auth-service introspection reachability without gating Kubernetes readiness on it.
  • New route families worth knowing about: customers, customer_deployments, client_domains, license (+ GET /license/status), llm_router_admin, ml_control, security_master*, unified_data, widgets, action_proposals, coverage, data_diagnostics, inventory.

Documentation​

  • ADRs 033–039 accepted and published (first-class module program + NautilusTrader optional adapter boundary), with the transformation plan, evidence index, and legacy-import inventory.
  • Graph Data Pillar concept pages (ADR 032) and learning-service documentation landed.
  • OpenAPI specs re-synced (workflow identity projections, kb paths, /readyz central-auth probe).