惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
博客园_首页
G
Google Developers Blog
有赞技术团队
有赞技术团队
Vercel News
Vercel News
Last Week in AI
Last Week in AI
博客园 - 三生石上(FineUI控件)
Jina AI
Jina AI
IT之家
IT之家
The GitHub Blog
The GitHub Blog
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - Franky
A
About on SuperTechFans
The Register - Security
The Register - Security
腾讯CDC
月光博客
月光博客
GbyAI
GbyAI
博客园 - 叶小钗
Blog — PlanetScale
Blog — PlanetScale
D
Docker
D
DataBreaches.Net
博客园 - 聂微东
C
Check Point Blog
T
The Blog of Author Tim Ferriss
人人都是产品经理
人人都是产品经理
F
Full Disclosure
Martin Fowler
Martin Fowler
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
美团技术团队
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 司徒正美
小众软件
小众软件
量子位
L
LangChain Blog
S
SegmentFault 最新的问题
Hugging Face - Blog
Hugging Face - Blog
大猫的无限游戏
大猫的无限游戏
MongoDB | Blog
MongoDB | Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
InfoQ
F
Fortinet All Blogs

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - think41/extrasuite: Token-efficient pull/edit/push workflow for AI agents editing Google Workspace files (Sheets, Docs, Slides, Forms) GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店 GitHub - EdoardoBambini/Agent-Armor-Iaga: AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens. HN Vibes — Week 15, Apr 7–13 2026 GitHub - chojs23/ec: Easy terminal-native 3-way git mergetool vim-like workflow GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - JakOb-dotcom/cloud-sandbox-security-analysis: Technical analysis and Proof of Concept (PoC) regarding environment variable exfiltration in containerized cloud sandboxes via side-channel data leaks. Springboards - Flint Alpha Show HN: A simpler coding agent harness GitHub - audiodude/sudomake-friends GitHub - 256thFission/mini-mythos: OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities Show HN: OpenParallax: OS-level privilege separation for AI agent execution Hacker News Sorted - Chrome 应用商店 Show HN: How to Install Docker on Ubuntu 24.04 LTS: Complete 2026 Guide GitHub - himanshudongre/smriti GitHub - sverrirsig/claude-control: macOS desktop dashboard for monitoring and managing multiple Claude Code sessions GitHub - ory/dockertest: Write better integration tests! Dockertest helps you boot up ephermal docker images for your Go tests with minimal work. Chiral - Chrome 应用商店 Show HN: Two Claudes collaborating through shared memory on a $100 mini-PC GitHub - pmichaillat/latex-cv: Minimalist LaTeX template for academic CVs GitHub - oguzbilgic/posse: A web UI for Anthropic Managed Agents. GitHub - sshiraz/depsly: Dependency risk analysis tool for npm packages ABI Add safari/agent-harness — Safari browser automation via safari-mcp by achiya-automation · Pull Request #212 · HKUDS/CLI-Anything GitHub - Halfblood-Prince/trustcheck: Verify PyPI package attestations and improve Python supply-chain security GitHub - oguzbilgic/kern-ai: Agents that do the work and show it. GitHub - bruits/satteri: High-performance Markdown and MDX processing for the JavaScript ecosystem GitHub - tylergibbs1/feedstock: High-performance web crawler and scraper for TypeScript, powered by Bun and Playwright GitHub - Grimm67123/grimmbot: The self-improving sandboxed and open-source AI agent. With persistent memory and scheduling. GitHub - whitevanillaskies/whitebloom: Local whiteboard that blooms. GitHub - hwdsl2/docker-whisper: Docker image for a self-hosted Whisper speech-to-text server with speaker diarization and OpenAI-compatible transcription and translation APIs. Powered by faster-whisper. Supports all Whisper models, NVIDIA GPU (CUDA) acceleration, JSON/SRT/VTT output, SSE streaming, offline mode, and multi-arch (amd64, arm64). GitHub - yisding/reviewwiggum GitHub - MarwanAlsoltany/serrors: Structured errors for Go: sentinel hierarchies, typed data, custom formatting, and slog integration. GitHub - soatok/age-php GitHub - Luthiraa/markitme GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits GitHub - tombedor/excalicharts GitHub - wh1le/excalidraw-edit: Open and edit .excalidraw files from the terminal. Offline, auto-saves to disk. MalExt Sentry - Malicious Extension Scanner - Chrome 应用商店 GitHub - syi0808/asciianimesvg: Generate animated ASCII art SVGs from text. CLI, Rust library, WASM, and web editor. GitHub - zaina-ml/ml_forge: A visual-based graph node editor for training computer vision models. GitHub - anakin87/llm-rl-environments-lil-course: 🌱 A little course on Reinforcement Learning Environments for evaluating and training Language Models GitHub - takaakit/superpowers-uml: Superpowers-UML modifies Superpowers to ensure a software development workflow in which AI agents design through UML modeling. AdriByte Studio - Sviluppo Web e Soluzioni Digitali GitHub - chouligi/angel-copilot: Your personalized Angel Investment Advisor Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 GitHub - agenteractai/lodmem: Level Of Detail Context Management for Agents GitHub - ostefani/subnetlens: A fast, concurrent network scanner with a TUI and plain-text CLI, built in Go. It discovers live hosts on your network, scans their open ports, resolves hostnames, and fingerprints operating systems—delivered. Cyber Pulse: Agentic Intel - Apps on Google Play Whisper API: Self-Hostable Speech to Text Transcription The Agent-Web Protocol Stack: A Research Thesis GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Show HN: Provepy – A Python decorator that proves your code using Lean and LLMs Show HN: Pardonned.com – A searchable database of US Pardons GitHub - patrickdappollonio/dux: Dux is a terminal UI that lets you run multiple AI coding agents side by side, each in its own git worktree, with full companion terminals, macros, commit generation, and a command palette that knows more tricks than you do. kMC Crystal Simulator Show HN: HyperFlow – A self-improving agent framework built on LangGraph GitHub - stef41/vibescore: 🎵 Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing. GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. imgur.com GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. GitHub - nowork-studio/toprank: Open-source Claude Code skills for SEO, SEM, Google Ads GitHub - tacomanator/sash: Lightweight macOS menu bar app for reliably cycling through windows of the current application. Appents | Social Media Management for Product-First Teams GitHub - pnhoang/youtube-spam-blocker: Automatically detects and hides spam messages in YouTube Live chat. Set rate limits, keyword filters, and block repeat offenders. GitHub - decisionnode/DecisionNode: CLI + Local MCP - A shared structured memory store across Claude Code, Cursor, Windsurf, Antigravity, and every MCP client. Semantically queryable. GitHub - AvaCodeSolutions/django-email-learning: An open source Django app for creating email-based learning platforms with IMAP integration and React frontend components. The $100K Gap in Kubernetes Security Tooling Function Calling Harness: From 6.75% to 100%
GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus.
ginccc · 2026-04-16 · via Hacker News: Show HN

EDDI Banner Image

E.D.D.I — Multi-Agent Orchestration Middleware for Conversational AI

OpenSSF Best Practices OpenSSF Scorecard Codacy Badge

CI CodeQL Tests Coverage

Docker Pulls Repository: AI Ready

E.D.D.I (Enhanced Dialog Driven Interface) is a production-grade, config-driven multi-agent orchestration middleware for conversational AI. It coordinates users, AI agents, and business systems through intelligent routing, persistent memory, and API orchestration — without writing code.

Built with Java 25 and Quarkus. Ships as a Red Hat-certified Docker image. Native support for MCP (Model Context Protocol), A2A (Agent-to-Agent), Slack, OpenAPI, and OAuth 2.0.

Latest version: 6.1.0 · Website · Documentation · License: Apache 2.0


📑 Table of Contents

  • 🏁 Quick Start
  • 💡 Why EDDI?
  • 📸 See It In Action
  • ✨ Features
  • 🧩 Quarkus SDK
  • 📖 Documentation
  • 📋 Compliance & Privacy
  • 🏗️ Development
    • Prerequisites
    • Quarkus Dev Mode
    • Maven Command Reference
    • Build & Docker
    • Kubernetes
  • 🤝 Contributing
  • 🔒 Security
  • 📜 Code of Conduct

🏁 Quick Start

The fastest way to get EDDI running is the one-command installer. It sets up EDDI + your choice of database via Docker Compose, deploys the Agent Father starter agent, and walks you through creating your first AI agent.

Linux / macOS / WSL2:

curl -fsSL https://raw.githubusercontent.com/labsai/EDDI/main/install.sh | bash

Windows (PowerShell):

Invoke-WebRequest -UseBasicParsing -Uri "https://raw.githubusercontent.com/labsai/EDDI/main/install.ps1" -OutFile "install.ps1"
Unblock-File .\install.ps1
.\install.ps1

Requires Docker. The wizard auto-generates a unique vault encryption key for secret management.

🔧 Installer options
bash install.sh --defaults                 # All defaults, no prompts
bash install.sh --db=postgres --with-auth  # PostgreSQL + Keycloak
bash install.sh --full                     # Everything enabled (DB + auth + monitoring)
bash install.sh --local                    # Build Docker image from local source

The --local flag is for contributors testing pre-release builds:

./mvnw package -DskipTests    # Build the Java app
bash install.sh --local        # Build Docker image + start containers

🔄 Updating

The installer creates an eddi CLI wrapper that makes updating easy:

This pulls the latest Docker image from the registry and restarts the containers. It works even when the same tag (e.g. latest) was re-published — Docker always checks the remote digest for changes.

eddi command not found? The CLI lives at ~/.eddi/eddi (Linux/macOS) or ~/.eddi/eddi.cmd (Windows). Either restart your terminal so the PATH takes effect, or use the full path:

# Linux / macOS
~/.eddi/eddi update

# Windows (PowerShell)
& "$HOME\.eddi\eddi.cmd" update
Manual update (without the CLI)

If the eddi CLI isn't available, run the equivalent docker commands from your install directory (~/.eddi by default):

cd ~/.eddi
docker compose --env-file .env -f docker-compose.yml pull
docker compose --env-file .env -f docker-compose.yml up -d

Adjust the -f flags to match your setup (e.g. add -f docker-compose.auth.yml if using Keycloak).

🐳 Docker Compose (Manual)

If you prefer manual control over Docker Compose:

# Default (EDDI + MongoDB)
docker compose up

# PostgreSQL instead of MongoDB
EDDI_DATASTORE_TYPE=postgres docker compose -f docker-compose.yml -f docker-compose.postgres.yml up

# With Keycloak authentication
docker compose -f docker-compose.yml -f docker-compose.auth.yml up

# With Prometheus + Grafana monitoring
docker compose -f docker-compose.yml -f docker-compose.monitoring.yml up

# Full stack (all overlays)
docker compose -f docker-compose.yml -f docker-compose.auth.yml \
  -f docker-compose.monitoring.yml -f docker-compose.nats.yml up

Available compose overlays: docker-compose.auth.yml (Keycloak), docker-compose.monitoring.yml (Prometheus+Grafana), docker-compose.nats.yml (NATS JetStream), docker-compose.postgres.yml / docker-compose.postgres-only.yml, docker-compose.local.yml (build from source).

docker pull labsai/eddi    # Pull latest from Docker Hub

hub.docker.com/r/labsai/eddi


💡 Why EDDI?

Most multi-agent frameworks (LangGraph, CrewAI, AutoGen) are Python/Node libraries — great for prototyping, hard to govern in production. EDDI approaches from the opposite direction: a deterministic engine built to safely govern non-deterministic AI.

Dimension Typical Python/Node Frameworks EDDI
Concurrency GIL or single-threaded event loop Java 25 Virtual Threads — true OS-level parallelism
Agent Logic Embedded in application code Versioned JSON configurations — update behavior without redeployment
Security Model Often relies on sandboxed code execution No dynamic code execution at all; envelope-encrypted vault, SSRF protection
Compliance Requires custom implementation GDPR, HIPAA, EU AI Act infrastructure built-in
Audit Trail Application-level logging HMAC-SHA256 immutable ledger with cryptographic agent signing
Deployment pip/npm + manual infrastructure One-command Docker install, Kubernetes/OpenShift-ready

"The engine is strict so the AI can be creative."Project Philosophy


📸 See It In Action

📊 Dashboard

EDDI Dashboard

Platform overview with active agents, workflows, quick actions, and recent conversations

🤖 Agent Fleet

Agents List

All deployed agents at a glance with status, descriptions, and one-click chat

💬 Live Conversation

Conversation View

Real-time conversation with visible actions, step timing, and tool calls

🗣️ Multi-Agent Debate

Group Conversations

Peer Review with phased discussion: Opinion → Critique → Revision → Synthesis

🛡️ Secrets Vault

Secrets Vault

Envelope-encrypted secrets with rotation tracking, checksums, and per-agent access control

💰 Tenant Quotas

Tenant Quotas

Rate limits, cost budgets, and live usage monitoring per tenant

More screenshots: LLM Config, Logs, User Memory, Schedules, Agent Detail

⚡ LLM Task Configuration

LLM Configuration

System prompt, model parameters, cascading, RAG, context window, and budget settings

📋 Real-Time Logs

Logs

Live log stream with per-call cost tracking, token counts, warnings, and errors

🧠 Persistent User Memory

User Data

Cross-session memory with categorized entries, visibility scoping, and conflict detection

⏰ Scheduled Execution

Schedules

Cron jobs and heartbeats with fire history, retry logic, and dead-letter tracking

🔧 Agent Detail

Agent Detail

Full agent config: environments, workflows, A2A, security, capabilities, and memory policy


✨ Features

🤖 Multi-Agent Orchestration

  • 🔀 Intelligent Routing — Direct conversations to different agents based on context, rules, and intent
  • 🗣️ Group Conversations — Multi-agent debates with 5 built-in discussion styles: Round Table, Peer Review, Devil's Advocate, Delphi, and Debate
  • 💬 Slack Integration — Deploy agents to Slack channels and run multi-agent debates directly in threads
  • 🪆 Nested Groups — Compose groups of groups for tournament brackets, red-team vs blue-team, and panel reviews
  • 👥 Managed Conversations — Intent-based auto-routing with one conversation per user per intent
  • 🎯 Capability Matching — Discover and route to agents by skill, confidence score, and custom attributes
  • 🧙 Agent Father — Meta-agent that creates other agents through conversation (ships out of the box)

🧠 LLM Provider Support (12 Providers)

Category Providers
Cloud APIs OpenAI · Anthropic Claude · Google Gemini · Mistral AI
Enterprise Cloud Azure OpenAI · Amazon Bedrock · Oracle GenAI · Google Vertex AI
Self-Hosted Ollama · Jlama · Hugging Face
Compatible Any OpenAI-compatible endpoint (DeepSeek, Cohere, etc.) via baseUrl

🔗 Standards & Interoperability

EDDI implements open standards — not proprietary APIs:

Standard Role What It Enables
MCP (Model Context Protocol) Server (42 tools) + Client Control EDDI from Claude Desktop, Cursor, or any MCP client. Connect agents to external MCP tool servers
A2A (Agent-to-Agent Protocol) Full implementation Cross-platform agent communication, Agent Cards, and skill discovery
OpenAPI 3.1 Native generation + consumption Auto-generated spec. Paste any OpenAPI spec → get a fully deployed API-calling agent
OAuth 2.0 / OIDC Keycloak integration Authentication, authorization, and multi-tenant isolation
SSE (Server-Sent Events) Streaming transport Real-time chat responses, group discussion feeds, and live log streaming

💭 Memory & Context Management

  • 💾 Persistent User Memory — Agents remember facts, preferences, and context across conversations via structured key-value entries with visibility scoping (global, agent, group)
  • 🧠 LLM Memory Tools — Built-in tools agents can call to read, write, and search their own persistent memory
  • 💤 Dream Consolidation — Background memory maintenance: stale entry pruning, contradiction detection, and fact summarization (inspired by Anthropic's research on background memory consolidation)
  • 🪟 Token-Aware Windowing — Intelligent context packing with model-specific tokenizer support and anchored opening steps
  • 📝 Rolling Summary — Incremental LLM-powered summarization of older turns with a Conversation Recall Tool for drill-back into compressed history
  • 🔧 Property Extraction — Config-driven slot-filling with longTerm / conversation / step scoping — EDDI's importance extraction mechanism
  • 🛡️ Memory Policy (Commit Flags) — Strict write discipline marks failed task output as uncommitted (hidden from LLM context) and injects concise error digests for graceful degradation
  • 🔄 Conversation State — Full history with undo/redo support

📚 RAG (Retrieval-Augmented Generation)

  • 📦 7 Embedding Providers — OpenAI, Ollama, Azure OpenAI, Mistral, Bedrock, Cohere, Vertex AI
  • 🗄️ 5 Vector Stores — pgvector, In-Memory, MongoDB Atlas, Elasticsearch, Qdrant
  • 🌐 httpCall RAG — Zero-infrastructure RAG via any search API (BM25, Elasticsearch, custom)
  • 📥 REST Ingestion API — Async document ingestion with status tracking

🛠️ Built-In AI Agent Tools

Tool Description
🔍 Web Search DuckDuckGo or Google Custom Search
🧮 Calculator Sandboxed recursive-descent math parser (no eval(), no code injection)
🌐 Web Scraper SSRF-protected content extraction from web pages
📄 PDF Reader SSRF-protected document extraction
☁️ Weather · 🕐 DateTime Real-time data tools
📊 Data Formatter · 📝 Text Summarizer Data transformation tools
🔌 HTTP Calls as Tools Expose your own REST APIs as LLM-callable tools with full security sandboxing
🧠 User Memory Read/write/search persistent user memory
🔙 Conversation Recall Drill back into summarized conversation history
📎 Multimodal Attachments Image, PDF, audio, and video input with MIME-based routing

⏰ Scheduled Execution & Heartbeats

  • 🫀 Heartbeat Triggers — Periodic agent wake-ups at configurable intervals for proactive behavior (inspired by OpenClaw's heartbeat architecture)
  • ⏲️ Cron Scheduling — Standard cron expressions for timed agent execution
  • 🔄 Conversation Strategiespersistent (reuse same conversation across fires) or new (fresh context each time)
  • 📊 Fire Logging — Complete execution history with status, duration, cost tracking, and retry logic
  • 🌙 Dream Cycles — Scheduled background memory consolidation with cost ceilings per run

📈 Smart Model Cascading

  • 📉 Cost Optimization — Try cheap/fast models first, escalate to powerful models only when confidence is low
  • 📊 4 Confidence Strategies — Structured output, heuristic, judge model, or none
  • 💰 Per-Conversation Budgets — Automatic cost tracking with budget caps and eviction
  • 🏢 Tenant Cost Ceilings — Monthly cost budgets per tenant with automatic enforcement

🔐 Enterprise Security & Compliance

Security Architecture
  • 🏦 Secrets Vault — Envelope encryption (PBKDF2 + AES-256) with tenant-scoped DEK/KEK rotation. Never plaintext in DB
  • 🛡️ SSRF Protection — All tools validate URLs against private IPs, internal hostnames, and non-HTTP schemes before any request
  • 🔒 Sandboxed Evaluation — Recursive-descent math parser only. No eval(), no script engines, no reflection-based execution
  • 🔑 OAuth 2.0 / Keycloak — Multi-tenant authentication, authorization, and role-based access control
  • ✍️ Agent Signing — Ed25519 cryptographic identity per agent; audit entries signed with agent private keys
  • 🚫 No Dynamic Code Execution — Custom logic runs in external MCP servers, outside the EDDI security perimeter
Regulatory Compliance
Regulation EDDI Support
EU AI Act Immutable HMAC-SHA256 audit ledger, decision traceability, risk classification guidance
GDPR Cascading data erasure (Art. 17), data portability (Art. 15/20), restriction of processing (Art. 18), per-category retention, pseudonymization
CCPA Right to delete, right to know, data portability
HIPAA Deployment guide, BAA template, LLM provider BAA matrix, session timeout guidance
International PIPEDA 🇨🇦 · LGPD 🇧🇷 · APPI 🇯🇵 · POPIA 🇿🇦 · PDPA 🇸🇬🇹🇭🇲🇾 · PIPL 🇨🇳 compatibility documented
  • 📜 Audit Ledger — Every agent decision recorded in a write-once, HMAC-secured, append-only ledger
  • 🔍 Compliance Startup Checks — Advisory warnings on boot for TLS and database encryption gaps
  • 🗑️ GDPR Orchestration — One-call cascading erasure across 6 stores + audit trail pseudonymization
  • 📤 Data Portability — Complete user data export (memories, conversations, audit entries) via REST and MCP

⚙️ Configuration-Driven Architecture

  • 📄 JSON Configs, Not Code — Agent behavior defined in versioned, diffable JSON documents
  • 🔧 Lifecycle Pipeline — Pluggable task pipeline: Input → Parse → Rules → API/LLM → Output
  • 📦 Composable Agents — Agents assembled from reusable, version-controlled workflows and extensions
  • 🧪 Behavior Rules — IF-THEN logic engine for routing, orchestration, and business logic
  • 📤 Import / Export — Agents portable as ZIP files with automatic secret scrubbing on export
  • 🔄 Agent Sync — Live instance-to-instance sync with structural matching, content diffing, and selective resource picking — no ZIP intermediary needed
  • 📝 Prompt Snippets — Reusable, versioned system prompt building blocks available as {{snippets.safety_rules}}
  • 📎 Content Type Routing — MIME-based behavior rule conditions for multimodal attachment routing

🚀 Cloud-Native & Observable

  • 🐳 One-Command Install — Interactive wizard sets up EDDI + database + starter agent via Docker
  • ☸️ Kubernetes / OpenShift — Kustomize overlays, Helm charts, HPA, PDB, NetworkPolicy
  • 📊 Prometheus & Grafana — 50+ Micrometer metrics at /q/metrics (tools, vault, memory, scheduling, conversations). Pre-built Grafana dashboard included
  • 🔭 OpenTelemetry Tracing — Per-task distributed traces via OTLP (Jaeger, Tempo, Datadog). Every pipeline task emits spans with task.id, task.type, conversation.id, and agent.id
  • 🩺 Health Checks — Liveness & readiness probes at /q/health/live and /q/health/ready
  • 🔄 NATS JetStream — Async event bus for distributed processing
  • Virtual Threads — Java 25 virtual threads for true OS-level concurrency (no Python GIL or Node.js event loop bottleneck)
  • 🗃️ DB-Agnostic — Choose MongoDB or PostgreSQL; switch with one env var. Single Docker image for both
  • 🏗️ Red Hat Certified — Container certification with automated preflight checks in CI/CD

📖 Monitoring Guide: See docs/monitoring/monitoring-guide.md for architecture overview, metrics reference, alerting rules, and a production checklist.

🖥️ Manager Dashboard & Chat UI

  • 🎨 React 19 Manager — Modern admin dashboard for agent building, testing, deployment, and monitoring
  • 💬 Chat Widget — Embeddable React chat UI with SSE streaming and Keycloak auth
  • 🔍 Audit Trail Viewer — Timeline-based compliance and debugging UI
  • 📋 Logs Panel — Live SSE log streaming + searchable history
  • 🔑 Secrets Manager — Write-only vault UI with copy-reference support
  • 🌍 11 Languages — English, German, Spanish, French, Portuguese, Chinese, Japanese, Korean, Arabic (RTL), Hindi, Thai

🧩 Quarkus SDK

Building a Quarkus app that talks to EDDI? Use the quarkus-eddi extension:

<dependency>
    <groupId>io.quarkiverse.eddi</groupId>
    <artifactId>quarkus-eddi</artifactId>
    <version>6.1.0</version>
</dependency>
@Inject EddiClient eddi;

String answer = eddi.chat("my-agent", "Hello!");

Features: Dev Services (auto-starts EDDI in dev mode), fluent API, SSE streaming, @EddiAgent endpoint wiring, @EddiTool MCP bridge. See the quarkus-eddi README for full docs.


📖 Documentation

Guide Description
Getting Started Setup and first steps
Developer Quickstart Build your first agent in 5 minutes
Architecture Deep dive into EDDI's design and pipeline
LLM Configuration Connecting to 12 LLM providers
Behavior Rules Configuring agent routing logic
HTTP Calls External API integration
RAG Knowledge base retrieval setup
MCP Server 42 tools for AI-assisted agent management
A2A Protocol Agent-to-Agent peer communication
Slack Integration Deploy agents to Slack and run group discussions
Group Conversations Multi-agent debate orchestration
User Memory Cross-conversation fact retention
Memory Policy Commit flags and strict write discipline
Model Cascading Cost-optimized multi-model routing
Scheduling & Heartbeats Cron schedules, heartbeats, dream consolidation
Agent Sync Live instance-to-instance sync and upgrade imports
Import / Export ZIP-based agent portability and merge
Prompt Snippets Reusable system prompt building blocks
Attachments Multimodal attachment pipeline
Capability Matching A2A skill discovery and routing
Security SSRF protection, sandboxing, and hardening
Secrets Vault Envelope encryption and auto-vaulting
Audit Ledger EU AI Act-compliant audit trail
Kubernetes Deploy with Kustomize or Helm
Monitoring & Tracing Prometheus, Grafana, OpenTelemetry, alerting
Red Hat & OpenShift RHEL support, certified container, automated release
Agent Father Deep Dive How the meta-agent works
Full Documentation Complete documentation site

📋 Compliance & Privacy

EDDI provides built-in infrastructure for regulatory compliance:

Guide Covers
GDPR / CCPA Data erasure, export, Art. 18 restriction of processing, per-category retention, and consent guidance
HIPAA Healthcare deployment guide — encryption, BAAs, LLM provider matrix, session management
EU AI Act AI risk classification, decision traceability, immutable audit ledger
Privacy & Data Processing Data flows, LLM provider matrix, international regulations (PIPEDA, LGPD, APPI, POPIA, PDPA, PIPL)
Compliance Data Flow Single-page data flow diagram for auditors
Incident Response Breach response runbook (GDPR 72h, CCPA 45 days, HIPAA 60 days)

🏗️ Development

Prerequisites

Tool Version Notes
Java (JDK) 25 Eclipse Temurin recommended
Maven 3.9+ Bundled via mvnw / mvnw.cmd wrapper — no install needed
MongoDB 6.0+ Local instance or Docker (docker run -d -p 27017:27017 mongo:7)
Docker Latest For integration tests and container builds

Windows users: Replace ./mvnw with .\mvnw.cmd in all commands below.

Quarkus Dev Mode

Dev mode starts the application with live reload — code changes are picked up automatically without restarting:

# Linux / macOS
./mvnw compile quarkus:dev

# Windows (PowerShell)
.\mvnw.cmd compile quarkus:dev

Then open http://localhost:7070. The Quarkus Dev UI is available at http://localhost:7070/q/dev.

Dev mode also enables:

  • Continuous testing — press r in the terminal to re-run tests on changes
  • Dev UI — browse endpoints, CDI beans, configuration, and health checks
  • Live reload — Java and resource changes apply instantly

💡 Secrets Vault: To use the secrets vault (storing API keys encrypted), set the master key before starting:

# Linux/macOS
export EDDI_VAULT_MASTER_KEY=my-dev-passphrase

# Windows (PowerShell)
$env:EDDI_VAULT_MASTER_KEY = "my-dev-passphrase"

# Or in a .env file (already in .gitignore)
echo "EDDI_VAULT_MASTER_KEY=my-dev-passphrase" > .env

Without this, the vault is disabled and secret management returns HTTP 503. Any passphrase works for local development. See Secrets Vault for production setup.

Maven Command Reference

Command What It Does
./mvnw compile quarkus:dev Start dev mode with live reload (port 7070)
./mvnw compile Compile sources only (fast feedback)
./mvnw clean compile Clean build — delete target/ and recompile from scratch
./mvnw test Run unit tests (excludes *IT.java integration tests)
./mvnw verify -DskipITs Compile + unit tests + package (no integration tests)
./mvnw verify Full build — compile + unit tests + integration tests (requires Docker)
./mvnw validate Run Checkstyle code style checks
./mvnw formatter:format Auto-format Java sources using the project Eclipse formatter
./mvnw package -DskipTests Build the JAR without running tests (for install.sh --local)
./mvnw clean package '-Dquarkus.container-image.build=true' Build the app + Docker image
./mvnw package -Plicense-gen -DskipTests Generate third-party licenses (Red Hat certification)
./mvnw quarkus:dev -Dsuspend Start dev mode and wait for debugger on port 5005
./mvnw quarkus:dev -Ddebug=false Start dev mode without the debug agent
Code coverage

JaCoCo is configured to run automatically during ./mvnw test. After tests complete, find the coverage report at:

target/site/jacoco/index.html
Useful system properties
Property Default Description
-Dquarkus.http.port=<port> 7070 Override the HTTP port
-Dquarkus.mongodb.connection-string=<uri> mongodb://localhost:27017 MongoDB connection
-Dquarkus.profile=<profile> dev Active Quarkus profile (dev, test, prod)
-DskipTests false Skip all tests
-DskipITs true Skip integration tests only

Build & Docker

# Build app + Docker image
./mvnw clean package '-Dquarkus.container-image.build=true'

# Build without container (for install.sh --local)
./mvnw package -DskipTests

# Generate third-party licenses (Red Hat certification)
./mvnw package -Plicense-gen -DskipTests

☸️ Kubernetes

# Quickstart (one-file deployment)
kubectl apply -f https://raw.githubusercontent.com/labsai/EDDI/main/k8s/quickstart.yaml

# Kustomize overlays
kubectl apply -k k8s/overlays/mongodb/     # MongoDB backend
kubectl apply -k k8s/overlays/postgres/    # PostgreSQL backend

# Helm
helm install eddi ./helm/eddi --namespace eddi --create-namespace

Includes overlays for auth (Keycloak), monitoring (Prometheus/Grafana), NATS messaging, Ingress, and production hardening (HPA, PDB, NetworkPolicy). See the Kubernetes Guide for details.


🤝 Contributing

We welcome contributions! Please read our Contributing Guide for details on setting up your development environment, code style, commit conventions, and the pull request process.

Every PR is automatically checked by CI (build + tests), CodeQL (security), dependency review, and AI-powered code review.

🔒 Security

EDDI ships with security-by-default for production deployments:

  • Authentication enforcedAuthStartupGuard fails startup if OIDC is disabled in production without explicit opt-out
  • Secrets encrypted at rest — Envelope encryption (PBKDF2 → AES-256-GCM) with per-deployment salt. Never plaintext in DB
  • SSRF protection — All LLM tool HTTP calls go through SafeHttpClient with private IP blocking, redirect validation, and scheme enforcement
  • Security headersX-Content-Type-Options, X-Frame-Options, Content-Security-Policy configured out of the box
  • CI/CD security gates — Every push/PR is scanned by:
    • CodeQL — Semantic SAST analysis with security-extended queries
    • Trivy — CVE scanning for both filesystem dependencies and Docker images (blocking on CRITICAL/HIGH)
    • Gitleaks — Git history scanning to prevent secret/credential leakage
    • ZAP — DAST API scanning against the live Docker image (report-only)
    • CycloneDX — SBOM generation for supply chain transparency
    • Jazzer — Coverage-guided fuzz testing for security-critical parsers (PathNavigator, MatchingUtilities)
    • All actions SHA-pinned to prevent supply-chain attacks

For vulnerability reports, see our Security Policy. For architecture details, see Security Architecture.

📜 Code of Conduct

This project follows the Contributor Covenant Code of Conduct.