惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
B
Blog RSS Feed
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
B
Blog
博客园 - 司徒正美
Vercel News
Vercel News
A
About on SuperTechFans
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
Stack Overflow Blog
Stack Overflow Blog
L
LINUX DO - 热门话题
Y
Y Combinator Blog
F
Full Disclosure
月光博客
月光博客
C
Cyber Attacks, Cyber Crime and Cyber Security
MongoDB | Blog
MongoDB | Blog
The Cloudflare Blog
The Hacker News
The Hacker News
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
A
Arctic Wolf
Scott Helme
Scott Helme
V
Visual Studio Blog
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
P
Privacy International News Feed
Spread Privacy
Spread Privacy
G
GRAHAM CLULEY
Microsoft Security Blog
Microsoft Security Blog
N
News and Events Feed by Topic
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
PCI Perspectives
PCI Perspectives
小众软件
小众软件
博客园 - 【当耐特】
Cloudbric
Cloudbric
S
Secure Thoughts
L
LINUX DO - 最新话题
Google Online Security Blog
Google Online Security Blog
T
Troy Hunt's Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus.
ginccc · 2026-04-16 · via Hacker News - Newest: "AI"

EDDI Banner Image

E.D.D.I — Multi-Agent Orchestration Middleware for Conversational AI

OpenSSF Best Practices OpenSSF Scorecard Codacy Badge

CI CodeQL Tests Coverage

Docker Pulls Repository: AI Ready

E.D.D.I (Enhanced Dialog Driven Interface) is a production-grade, config-driven multi-agent orchestration middleware for conversational AI. It coordinates users, AI agents, and business systems through intelligent routing, persistent memory, and API orchestration — without writing code.

Built with Java 25 and Quarkus. Ships as a Red Hat-certified Docker image. Native support for MCP (Model Context Protocol), A2A (Agent-to-Agent), Slack, OpenAPI, and OAuth 2.0.

Latest version: 6.1.0 · Website · Documentation · License: Apache 2.0


📑 Table of Contents

  • 🏁 Quick Start
  • 💡 Why EDDI?
  • 📸 See It In Action
  • ✨ Features
  • 🧩 Quarkus SDK
  • 📖 Documentation
  • 📋 Compliance & Privacy
  • 🏗️ Development
    • Prerequisites
    • Quarkus Dev Mode
    • Maven Command Reference
    • Build & Docker
    • Kubernetes
  • 🤝 Contributing
  • 🔒 Security
  • 📜 Code of Conduct

🏁 Quick Start

The fastest way to get EDDI running is the one-command installer. It sets up EDDI + your choice of database via Docker Compose, deploys the Agent Father starter agent, and walks you through creating your first AI agent.

Linux / macOS / WSL2:

curl -fsSL https://raw.githubusercontent.com/labsai/EDDI/main/install.sh | bash

Windows (PowerShell):

Invoke-WebRequest -UseBasicParsing -Uri "https://raw.githubusercontent.com/labsai/EDDI/main/install.ps1" -OutFile "install.ps1"
Unblock-File .\install.ps1
.\install.ps1

Requires Docker. The wizard auto-generates a unique vault encryption key for secret management.

🔧 Installer options
bash install.sh --defaults                 # All defaults, no prompts
bash install.sh --db=postgres --with-auth  # PostgreSQL + Keycloak
bash install.sh --full                     # Everything enabled (DB + auth + monitoring)
bash install.sh --local                    # Build Docker image from local source

The --local flag is for contributors testing pre-release builds:

./mvnw package -DskipTests    # Build the Java app
bash install.sh --local        # Build Docker image + start containers

🔄 Updating

The installer creates an eddi CLI wrapper that makes updating easy:

This pulls the latest Docker image from the registry and restarts the containers. It works even when the same tag (e.g. latest) was re-published — Docker always checks the remote digest for changes.

eddi command not found? The CLI lives at ~/.eddi/eddi (Linux/macOS) or ~/.eddi/eddi.cmd (Windows). Either restart your terminal so the PATH takes effect, or use the full path:

# Linux / macOS
~/.eddi/eddi update

# Windows (PowerShell)
& "$HOME\.eddi\eddi.cmd" update
Manual update (without the CLI)

If the eddi CLI isn't available, run the equivalent docker commands from your install directory (~/.eddi by default):

cd ~/.eddi
docker compose --env-file .env -f docker-compose.yml pull
docker compose --env-file .env -f docker-compose.yml up -d

Adjust the -f flags to match your setup (e.g. add -f docker-compose.auth.yml if using Keycloak).

🐳 Docker Compose (Manual)

If you prefer manual control over Docker Compose:

# Default (EDDI + MongoDB)
docker compose up

# PostgreSQL instead of MongoDB
EDDI_DATASTORE_TYPE=postgres docker compose -f docker-compose.yml -f docker-compose.postgres.yml up

# With Keycloak authentication
docker compose -f docker-compose.yml -f docker-compose.auth.yml up

# With Prometheus + Grafana monitoring
docker compose -f docker-compose.yml -f docker-compose.monitoring.yml up

# Full stack (all overlays)
docker compose -f docker-compose.yml -f docker-compose.auth.yml \
  -f docker-compose.monitoring.yml -f docker-compose.nats.yml up

Available compose overlays: docker-compose.auth.yml (Keycloak), docker-compose.monitoring.yml (Prometheus+Grafana), docker-compose.nats.yml (NATS JetStream), docker-compose.postgres.yml / docker-compose.postgres-only.yml, docker-compose.local.yml (build from source).

docker pull labsai/eddi    # Pull latest from Docker Hub

hub.docker.com/r/labsai/eddi


💡 Why EDDI?

Most multi-agent frameworks (LangGraph, CrewAI, AutoGen) are Python/Node libraries — great for prototyping, hard to govern in production. EDDI approaches from the opposite direction: a deterministic engine built to safely govern non-deterministic AI.

Dimension Typical Python/Node Frameworks EDDI
Concurrency GIL or single-threaded event loop Java 25 Virtual Threads — true OS-level parallelism
Agent Logic Embedded in application code Versioned JSON configurations — update behavior without redeployment
Security Model Often relies on sandboxed code execution No dynamic code execution at all; envelope-encrypted vault, SSRF protection
Compliance Requires custom implementation GDPR, HIPAA, EU AI Act infrastructure built-in
Audit Trail Application-level logging HMAC-SHA256 immutable ledger with cryptographic agent signing
Deployment pip/npm + manual infrastructure One-command Docker install, Kubernetes/OpenShift-ready

"The engine is strict so the AI can be creative."Project Philosophy


📸 See It In Action

📊 Dashboard

EDDI Dashboard

Platform overview with active agents, workflows, quick actions, and recent conversations

🤖 Agent Fleet

Agents List

All deployed agents at a glance with status, descriptions, and one-click chat

💬 Live Conversation

Conversation View

Real-time conversation with visible actions, step timing, and tool calls

🗣️ Multi-Agent Debate

Group Conversations

Peer Review with phased discussion: Opinion → Critique → Revision → Synthesis

🛡️ Secrets Vault

Secrets Vault

Envelope-encrypted secrets with rotation tracking, checksums, and per-agent access control

💰 Tenant Quotas

Tenant Quotas

Rate limits, cost budgets, and live usage monitoring per tenant

More screenshots: LLM Config, Logs, User Memory, Schedules, Agent Detail

⚡ LLM Task Configuration

LLM Configuration

System prompt, model parameters, cascading, RAG, context window, and budget settings

📋 Real-Time Logs

Logs

Live log stream with per-call cost tracking, token counts, warnings, and errors

🧠 Persistent User Memory

User Data

Cross-session memory with categorized entries, visibility scoping, and conflict detection

⏰ Scheduled Execution

Schedules

Cron jobs and heartbeats with fire history, retry logic, and dead-letter tracking

🔧 Agent Detail

Agent Detail

Full agent config: environments, workflows, A2A, security, capabilities, and memory policy


✨ Features

🤖 Multi-Agent Orchestration

  • 🔀 Intelligent Routing — Direct conversations to different agents based on context, rules, and intent
  • 🗣️ Group Conversations — Multi-agent debates with 5 built-in discussion styles: Round Table, Peer Review, Devil's Advocate, Delphi, and Debate
  • 💬 Slack Integration — Deploy agents to Slack channels and run multi-agent debates directly in threads
  • 🪆 Nested Groups — Compose groups of groups for tournament brackets, red-team vs blue-team, and panel reviews
  • 👥 Managed Conversations — Intent-based auto-routing with one conversation per user per intent
  • 🎯 Capability Matching — Discover and route to agents by skill, confidence score, and custom attributes
  • 🧙 Agent Father — Meta-agent that creates other agents through conversation (ships out of the box)

🧠 LLM Provider Support (12 Providers)

Category Providers
Cloud APIs OpenAI · Anthropic Claude · Google Gemini · Mistral AI
Enterprise Cloud Azure OpenAI · Amazon Bedrock · Oracle GenAI · Google Vertex AI
Self-Hosted Ollama · Jlama · Hugging Face
Compatible Any OpenAI-compatible endpoint (DeepSeek, Cohere, etc.) via baseUrl

🔗 Standards & Interoperability

EDDI implements open standards — not proprietary APIs:

Standard Role What It Enables
MCP (Model Context Protocol) Server (42 tools) + Client Control EDDI from Claude Desktop, Cursor, or any MCP client. Connect agents to external MCP tool servers
A2A (Agent-to-Agent Protocol) Full implementation Cross-platform agent communication, Agent Cards, and skill discovery
OpenAPI 3.1 Native generation + consumption Auto-generated spec. Paste any OpenAPI spec → get a fully deployed API-calling agent
OAuth 2.0 / OIDC Keycloak integration Authentication, authorization, and multi-tenant isolation
SSE (Server-Sent Events) Streaming transport Real-time chat responses, group discussion feeds, and live log streaming

💭 Memory & Context Management

  • 💾 Persistent User Memory — Agents remember facts, preferences, and context across conversations via structured key-value entries with visibility scoping (global, agent, group)
  • 🧠 LLM Memory Tools — Built-in tools agents can call to read, write, and search their own persistent memory
  • 💤 Dream Consolidation — Background memory maintenance: stale entry pruning, contradiction detection, and fact summarization (inspired by Anthropic's research on background memory consolidation)
  • 🪟 Token-Aware Windowing — Intelligent context packing with model-specific tokenizer support and anchored opening steps
  • 📝 Rolling Summary — Incremental LLM-powered summarization of older turns with a Conversation Recall Tool for drill-back into compressed history
  • 🔧 Property Extraction — Config-driven slot-filling with longTerm / conversation / step scoping — EDDI's importance extraction mechanism
  • 🛡️ Memory Policy (Commit Flags) — Strict write discipline marks failed task output as uncommitted (hidden from LLM context) and injects concise error digests for graceful degradation
  • 🔄 Conversation State — Full history with undo/redo support

📚 RAG (Retrieval-Augmented Generation)

  • 📦 7 Embedding Providers — OpenAI, Ollama, Azure OpenAI, Mistral, Bedrock, Cohere, Vertex AI
  • 🗄️ 5 Vector Stores — pgvector, In-Memory, MongoDB Atlas, Elasticsearch, Qdrant
  • 🌐 httpCall RAG — Zero-infrastructure RAG via any search API (BM25, Elasticsearch, custom)
  • 📥 REST Ingestion API — Async document ingestion with status tracking

🛠️ Built-In AI Agent Tools

Tool Description
🔍 Web Search DuckDuckGo or Google Custom Search
🧮 Calculator Sandboxed recursive-descent math parser (no eval(), no code injection)
🌐 Web Scraper SSRF-protected content extraction from web pages
📄 PDF Reader SSRF-protected document extraction
☁️ Weather · 🕐 DateTime Real-time data tools
📊 Data Formatter · 📝 Text Summarizer Data transformation tools
🔌 HTTP Calls as Tools Expose your own REST APIs as LLM-callable tools with full security sandboxing
🧠 User Memory Read/write/search persistent user memory
🔙 Conversation Recall Drill back into summarized conversation history
📎 Multimodal Attachments Image, PDF, audio, and video input with MIME-based routing

⏰ Scheduled Execution & Heartbeats

  • 🫀 Heartbeat Triggers — Periodic agent wake-ups at configurable intervals for proactive behavior (inspired by OpenClaw's heartbeat architecture)
  • ⏲️ Cron Scheduling — Standard cron expressions for timed agent execution
  • 🔄 Conversation Strategiespersistent (reuse same conversation across fires) or new (fresh context each time)
  • 📊 Fire Logging — Complete execution history with status, duration, cost tracking, and retry logic
  • 🌙 Dream Cycles — Scheduled background memory consolidation with cost ceilings per run

📈 Smart Model Cascading

  • 📉 Cost Optimization — Try cheap/fast models first, escalate to powerful models only when confidence is low
  • 📊 4 Confidence Strategies — Structured output, heuristic, judge model, or none
  • 💰 Per-Conversation Budgets — Automatic cost tracking with budget caps and eviction
  • 🏢 Tenant Cost Ceilings — Monthly cost budgets per tenant with automatic enforcement

🔐 Enterprise Security & Compliance

Security Architecture
  • 🏦 Secrets Vault — Envelope encryption (PBKDF2 + AES-256) with tenant-scoped DEK/KEK rotation. Never plaintext in DB
  • 🛡️ SSRF Protection — All tools validate URLs against private IPs, internal hostnames, and non-HTTP schemes before any request
  • 🔒 Sandboxed Evaluation — Recursive-descent math parser only. No eval(), no script engines, no reflection-based execution
  • 🔑 OAuth 2.0 / Keycloak — Multi-tenant authentication, authorization, and role-based access control
  • ✍️ Agent Signing — Ed25519 cryptographic identity per agent; audit entries signed with agent private keys
  • 🚫 No Dynamic Code Execution — Custom logic runs in external MCP servers, outside the EDDI security perimeter
Regulatory Compliance
Regulation EDDI Support
EU AI Act Immutable HMAC-SHA256 audit ledger, decision traceability, risk classification guidance
GDPR Cascading data erasure (Art. 17), data portability (Art. 15/20), restriction of processing (Art. 18), per-category retention, pseudonymization
CCPA Right to delete, right to know, data portability
HIPAA Deployment guide, BAA template, LLM provider BAA matrix, session timeout guidance
International PIPEDA 🇨🇦 · LGPD 🇧🇷 · APPI 🇯🇵 · POPIA 🇿🇦 · PDPA 🇸🇬🇹🇭🇲🇾 · PIPL 🇨🇳 compatibility documented
  • 📜 Audit Ledger — Every agent decision recorded in a write-once, HMAC-secured, append-only ledger
  • 🔍 Compliance Startup Checks — Advisory warnings on boot for TLS and database encryption gaps
  • 🗑️ GDPR Orchestration — One-call cascading erasure across 6 stores + audit trail pseudonymization
  • 📤 Data Portability — Complete user data export (memories, conversations, audit entries) via REST and MCP

⚙️ Configuration-Driven Architecture

  • 📄 JSON Configs, Not Code — Agent behavior defined in versioned, diffable JSON documents
  • 🔧 Lifecycle Pipeline — Pluggable task pipeline: Input → Parse → Rules → API/LLM → Output
  • 📦 Composable Agents — Agents assembled from reusable, version-controlled workflows and extensions
  • 🧪 Behavior Rules — IF-THEN logic engine for routing, orchestration, and business logic
  • 📤 Import / Export — Agents portable as ZIP files with automatic secret scrubbing on export
  • 🔄 Agent Sync — Live instance-to-instance sync with structural matching, content diffing, and selective resource picking — no ZIP intermediary needed
  • 📝 Prompt Snippets — Reusable, versioned system prompt building blocks available as {{snippets.safety_rules}}
  • 📎 Content Type Routing — MIME-based behavior rule conditions for multimodal attachment routing

🚀 Cloud-Native & Observable

  • 🐳 One-Command Install — Interactive wizard sets up EDDI + database + starter agent via Docker
  • ☸️ Kubernetes / OpenShift — Kustomize overlays, Helm charts, HPA, PDB, NetworkPolicy
  • 📊 Prometheus & Grafana — 50+ Micrometer metrics at /q/metrics (tools, vault, memory, scheduling, conversations). Pre-built Grafana dashboard included
  • 🔭 OpenTelemetry Tracing — Per-task distributed traces via OTLP (Jaeger, Tempo, Datadog). Every pipeline task emits spans with task.id, task.type, conversation.id, and agent.id
  • 🩺 Health Checks — Liveness & readiness probes at /q/health/live and /q/health/ready
  • 🔄 NATS JetStream — Async event bus for distributed processing
  • Virtual Threads — Java 25 virtual threads for true OS-level concurrency (no Python GIL or Node.js event loop bottleneck)
  • 🗃️ DB-Agnostic — Choose MongoDB or PostgreSQL; switch with one env var. Single Docker image for both
  • 🏗️ Red Hat Certified — Container certification with automated preflight checks in CI/CD

📖 Monitoring Guide: See docs/monitoring/monitoring-guide.md for architecture overview, metrics reference, alerting rules, and a production checklist.

🖥️ Manager Dashboard & Chat UI

  • 🎨 React 19 Manager — Modern admin dashboard for agent building, testing, deployment, and monitoring
  • 💬 Chat Widget — Embeddable React chat UI with SSE streaming and Keycloak auth
  • 🔍 Audit Trail Viewer — Timeline-based compliance and debugging UI
  • 📋 Logs Panel — Live SSE log streaming + searchable history
  • 🔑 Secrets Manager — Write-only vault UI with copy-reference support
  • 🌍 11 Languages — English, German, Spanish, French, Portuguese, Chinese, Japanese, Korean, Arabic (RTL), Hindi, Thai

🧩 Quarkus SDK

Building a Quarkus app that talks to EDDI? Use the quarkus-eddi extension:

<dependency>
    <groupId>io.quarkiverse.eddi</groupId>
    <artifactId>quarkus-eddi</artifactId>
    <version>6.1.0</version>
</dependency>
@Inject EddiClient eddi;

String answer = eddi.chat("my-agent", "Hello!");

Features: Dev Services (auto-starts EDDI in dev mode), fluent API, SSE streaming, @EddiAgent endpoint wiring, @EddiTool MCP bridge. See the quarkus-eddi README for full docs.


📖 Documentation

Guide Description
Getting Started Setup and first steps
Developer Quickstart Build your first agent in 5 minutes
Architecture Deep dive into EDDI's design and pipeline
LLM Configuration Connecting to 12 LLM providers
Behavior Rules Configuring agent routing logic
HTTP Calls External API integration
RAG Knowledge base retrieval setup
MCP Server 42 tools for AI-assisted agent management
A2A Protocol Agent-to-Agent peer communication
Slack Integration Deploy agents to Slack and run group discussions
Group Conversations Multi-agent debate orchestration
User Memory Cross-conversation fact retention
Memory Policy Commit flags and strict write discipline
Model Cascading Cost-optimized multi-model routing
Scheduling & Heartbeats Cron schedules, heartbeats, dream consolidation
Agent Sync Live instance-to-instance sync and upgrade imports
Import / Export ZIP-based agent portability and merge
Prompt Snippets Reusable system prompt building blocks
Attachments Multimodal attachment pipeline
Capability Matching A2A skill discovery and routing
Security SSRF protection, sandboxing, and hardening
Secrets Vault Envelope encryption and auto-vaulting
Audit Ledger EU AI Act-compliant audit trail
Kubernetes Deploy with Kustomize or Helm
Monitoring & Tracing Prometheus, Grafana, OpenTelemetry, alerting
Red Hat & OpenShift RHEL support, certified container, automated release
Agent Father Deep Dive How the meta-agent works
Full Documentation Complete documentation site

📋 Compliance & Privacy

EDDI provides built-in infrastructure for regulatory compliance:

Guide Covers
GDPR / CCPA Data erasure, export, Art. 18 restriction of processing, per-category retention, and consent guidance
HIPAA Healthcare deployment guide — encryption, BAAs, LLM provider matrix, session management
EU AI Act AI risk classification, decision traceability, immutable audit ledger
Privacy & Data Processing Data flows, LLM provider matrix, international regulations (PIPEDA, LGPD, APPI, POPIA, PDPA, PIPL)
Compliance Data Flow Single-page data flow diagram for auditors
Incident Response Breach response runbook (GDPR 72h, CCPA 45 days, HIPAA 60 days)

🏗️ Development

Prerequisites

Tool Version Notes
Java (JDK) 25 Eclipse Temurin recommended
Maven 3.9+ Bundled via mvnw / mvnw.cmd wrapper — no install needed
MongoDB 6.0+ Local instance or Docker (docker run -d -p 27017:27017 mongo:7)
Docker Latest For integration tests and container builds

Windows users: Replace ./mvnw with .\mvnw.cmd in all commands below.

Quarkus Dev Mode

Dev mode starts the application with live reload — code changes are picked up automatically without restarting:

# Linux / macOS
./mvnw compile quarkus:dev

# Windows (PowerShell)
.\mvnw.cmd compile quarkus:dev

Then open http://localhost:7070. The Quarkus Dev UI is available at http://localhost:7070/q/dev.

Dev mode also enables:

  • Continuous testing — press r in the terminal to re-run tests on changes
  • Dev UI — browse endpoints, CDI beans, configuration, and health checks
  • Live reload — Java and resource changes apply instantly

💡 Secrets Vault: To use the secrets vault (storing API keys encrypted), set the master key before starting:

# Linux/macOS
export EDDI_VAULT_MASTER_KEY=my-dev-passphrase

# Windows (PowerShell)
$env:EDDI_VAULT_MASTER_KEY = "my-dev-passphrase"

# Or in a .env file (already in .gitignore)
echo "EDDI_VAULT_MASTER_KEY=my-dev-passphrase" > .env

Without this, the vault is disabled and secret management returns HTTP 503. Any passphrase works for local development. See Secrets Vault for production setup.

Maven Command Reference

Command What It Does
./mvnw compile quarkus:dev Start dev mode with live reload (port 7070)
./mvnw compile Compile sources only (fast feedback)
./mvnw clean compile Clean build — delete target/ and recompile from scratch
./mvnw test Run unit tests (excludes *IT.java integration tests)
./mvnw verify -DskipITs Compile + unit tests + package (no integration tests)
./mvnw verify Full build — compile + unit tests + integration tests (requires Docker)
./mvnw validate Run Checkstyle code style checks
./mvnw formatter:format Auto-format Java sources using the project Eclipse formatter
./mvnw package -DskipTests Build the JAR without running tests (for install.sh --local)
./mvnw clean package '-Dquarkus.container-image.build=true' Build the app + Docker image
./mvnw package -Plicense-gen -DskipTests Generate third-party licenses (Red Hat certification)
./mvnw quarkus:dev -Dsuspend Start dev mode and wait for debugger on port 5005
./mvnw quarkus:dev -Ddebug=false Start dev mode without the debug agent
Code coverage

JaCoCo is configured to run automatically during ./mvnw test. After tests complete, find the coverage report at:

target/site/jacoco/index.html
Useful system properties
Property Default Description
-Dquarkus.http.port=<port> 7070 Override the HTTP port
-Dquarkus.mongodb.connection-string=<uri> mongodb://localhost:27017 MongoDB connection
-Dquarkus.profile=<profile> dev Active Quarkus profile (dev, test, prod)
-DskipTests false Skip all tests
-DskipITs true Skip integration tests only

Build & Docker

# Build app + Docker image
./mvnw clean package '-Dquarkus.container-image.build=true'

# Build without container (for install.sh --local)
./mvnw package -DskipTests

# Generate third-party licenses (Red Hat certification)
./mvnw package -Plicense-gen -DskipTests

☸️ Kubernetes

# Quickstart (one-file deployment)
kubectl apply -f https://raw.githubusercontent.com/labsai/EDDI/main/k8s/quickstart.yaml

# Kustomize overlays
kubectl apply -k k8s/overlays/mongodb/     # MongoDB backend
kubectl apply -k k8s/overlays/postgres/    # PostgreSQL backend

# Helm
helm install eddi ./helm/eddi --namespace eddi --create-namespace

Includes overlays for auth (Keycloak), monitoring (Prometheus/Grafana), NATS messaging, Ingress, and production hardening (HPA, PDB, NetworkPolicy). See the Kubernetes Guide for details.


🤝 Contributing

We welcome contributions! Please read our Contributing Guide for details on setting up your development environment, code style, commit conventions, and the pull request process.

Every PR is automatically checked by CI (build + tests), CodeQL (security), dependency review, and AI-powered code review.

🔒 Security

EDDI ships with security-by-default for production deployments:

  • Authentication enforcedAuthStartupGuard fails startup if OIDC is disabled in production without explicit opt-out
  • Secrets encrypted at rest — Envelope encryption (PBKDF2 → AES-256-GCM) with per-deployment salt. Never plaintext in DB
  • SSRF protection — All LLM tool HTTP calls go through SafeHttpClient with private IP blocking, redirect validation, and scheme enforcement
  • Security headersX-Content-Type-Options, X-Frame-Options, Content-Security-Policy configured out of the box
  • CI/CD security gates — Every push/PR is scanned by:
    • CodeQL — Semantic SAST analysis with security-extended queries
    • Trivy — CVE scanning for both filesystem dependencies and Docker images (blocking on CRITICAL/HIGH)
    • Gitleaks — Git history scanning to prevent secret/credential leakage
    • ZAP — DAST API scanning against the live Docker image (report-only)
    • CycloneDX — SBOM generation for supply chain transparency
    • Jazzer — Coverage-guided fuzz testing for security-critical parsers (PathNavigator, MatchingUtilities)
    • All actions SHA-pinned to prevent supply-chain attacks

For vulnerability reports, see our Security Policy. For architecture details, see Security Architecture.

📜 Code of Conduct

This project follows the Contributor Covenant Code of Conduct.