Saltar al contenido principal

Operational Guide

This page gives an operator-oriented map for using, administering, deploying, and troubleshooting AlphaSwarm services.

Service usage entrypoints​

User typeEntry pointRepositoriesNotes
Public visitorMarketing/docs/legal sitealphaswarm_website, alphaswarm_docsPublic site should not call privileged APIs.
Hosted customer/operatorAuthenticated platform dashboardalphaswarm_ui, alphaswarm_auth, alphaswarm_controller, alphaswarm_apiEntra-only login; BFF proxies authenticated requests.
AlphaSwarm staffStaff adminalphaswarm_admin, alphaswarm_authTenant onboarding/admin workflows and internal management.
Local power userLocal client and CLIalphaswarm_client, alphaswarm_cli, alphaswarm_localLocal/hybrid development and operator workflows.
Developer/agent builderIDE, MCP, agent runtimealphaswarm_ide, alphaswarm_mcp, alphaswarm_agentsTool/MCP connectivity and agent spec/runtime work.
Worker operatorWorker CLI/processalphaswarm_workerOAuth device flow, registration, Celery and optional engine nodes.
Platform operatorOps consolealphaswarm_ops_console, alphaswarm_platform, alphaswarm_localPrivileged fetch/deploy/action UI; keep confirm gates for production.

Administrative operations​

Tenant onboarding and identity​

  1. Use alphaswarm_admin for staff-mediated tenant-link and customer onboarding workflows.
  2. Ensure alphaswarm_auth provider adapters, RBAC roles/scopes, and device/WebAuthn settings are configured for the target environment.
  3. Verify hosted UI still uses Entra-only auth and that /signup compatibility flows redirect into the approved login path.
  4. Validate tenant router OIDC issuer/audience/JWKS settings before exposing a cell.
  5. Confirm tenant/workspace RLS migrations and default tenancy seed rows before enabling strict enforcement.

Worker onboarding​

  1. Install or deploy alphaswarm_worker.
  2. Authenticate with OAuth device flow.
  3. Register the device/worker with an operator-approved name.
  4. Run Celery queues or optional engine nodes only after verifying role/scopes and queue assignment.
  5. For production, require authentication/registration flags rather than permissive local defaults.

Agent/model operations​

  1. Author or update an AgentSpec in the runtime-owned repository or approved registry path.
  2. Hash-lock and register the spec before execution.
  3. Route workflows through controller/orchestration surfaces.
  4. Emit AGENT/TOOL/RETRIEVAL/EVAL spans to alphaswarm_observe.
  5. For model changes, require dataset/model/prompt cards, eval gates, and promotion records in alphaswarm_mlops.

Deployment operations​

OperationPreferred authorityGuardrail
Hosted platform rolloutalphaswarm_platformUse Helm/Terraform/CD runbooks; finish P0 go-live prerequisites first.
Local/hybrid stackalphaswarm_localKeep local Compose/Helm separate from hosted production.
Operator UI deploy actionalphaswarm_ops_consoleUse predeclared actions, confirm-gated production, no ad-hoc shell commands.
Docs publicationalphaswarm_docsRun docs CI/link checks before merging.
Service package releaseOwning service repoUpdate changelog/changeset and validate package-specific tests.

Troubleshooting checklist​

SymptomFirst checksLikely repos
User cannot log inEntra tenant link, session/BFF route, auth service health, tenant router JWT validation.alphaswarm_ui, alphaswarm_auth, alphaswarm_platform
Request routes to wrong cellTenant registry, pinned tenants, tier claim, rendezvous hash config, router readiness.alphaswarm_platform
Tenant data missing or blockedRLS context, workspace/tenant headers, migrations, default seed rows.alphaswarm, alphaswarm_auth, alphaswarm_platform
Agent run failsAgentSpec hash/registry, MCP availability, KB/data dependencies, LLM provider config, eval gate.alphaswarm_agents, alphaswarm_mcp, alphaswarm_kb, alphaswarm_mlops
Worker does not drain queuesDevice auth/registration, queue names, broker connectivity, optional engine dependencies.alphaswarm_worker, alphaswarm_controller, alphaswarm_orchestration
Hosted UI shows mock/stale dataBFF route wiring, controller/API backing service, E2E coverage, environment variables.alphaswarm_ui, alphaswarm_controller, alphaswarm_api
Telemetry gapSDK integration, span taxonomy, exporter endpoint, privacy filters, ingestion service roadmap.alphaswarm_observe, alphaswarm_observe_js, alphaswarm_kb_federation, alphaswarm_research

Safe operations policy​

  • Default to read-only reconnaissance before any live operational change.
  • Do not run destructive Kubernetes, Helm, Terraform, Cloudflare, AWS, or database mutations without an explicit gate and runbook.
  • Do not touch live trading flows in the alphaswarm namespace without signed approval.
  • Never print tokens, kubeconfigs, private keys, cookies, raw secret payloads, or credential files in logs/docs/issues.
  • Prefer metadata-only diagnostics and redacted summaries.
  • Keep future mutating control behind controller /manage governance rather than direct ad-hoc cluster actions.

Minimum runbook set to publish​

  1. Hosted platform go-live checklist and rollback plan.
  2. Tenant-router OIDC/JWT/CBA rollout and smoke-test plan.
  3. RLS strict-mode migration and validation plan.
  4. Entra customer tenant onboarding and staff onboarding.
  5. Worker registration and queue-drain operations.
  6. AgentSpec lifecycle and run replay.
  7. Data/KB ingest, provenance, graph sync, and federated retrieval checks.
  8. Observability ingestion, span taxonomy, alerting, and replay.