| Durable change log |
Kafka, partitioned by document identifier, 13-month retention via tiered storage to MinIO |
Open source, self-hosted |
Redpanda; NATS JetStream; Pulsar; a managed stream service |
Keyed partitioning gives per-document ordering, and long retention lets the transport double as the replay and deletion record |
ADR-11 |
| Chunk ledger (system of record) |
PostgreSQL with Patroni, synchronous standby in a second zone, partitioned by tenant |
Open source, self-hosted |
CockroachDB; YugabyteDB; a managed relational service |
The one store with RPO 0, needing transactions, a cheap set-difference query for the diff, and operational familiarity |
ADR-04 |
| Normalised text and snapshots |
MinIO, erasure-coded, objects under tenant-scoped keys |
Open source, self-hosted |
Ceph RGW; SeaweedFS; cloud object storage |
S3-compatible, cheap per TB, and the natural home for both retained text and index snapshots |
ADR-08 |
| Vector cache |
Redis, partitioned per tenant, keyed by (chunk hash, contract) |
Open source, self-hosted |
Dragonfly; Valkey; Memcached |
A cost mechanism rather than a correctness one, so a simple, fast, losable store is exactly right |
ADR-07 |
| Embedding inference |
KubeRay with Ray Serve, running a text-embedding server, replicas pinned by image and weight digest |
Open source, self-hosted |
KServe; Triton; vLLM-based serving; a managed embedding API |
Autoscaled replicas bound to node pools by taint, which is what makes three lanes with different capacity postures expressible |
ADR-15 |
| Vector index |
Qdrant, one collection per (tenant partition, contract), snapshots to MinIO |
Open source, self-hosted |
Milvus; Weaviate; pgvector; Vespa; a managed vector service |
Cheap collection creation makes one-index-per-contract affordable, and payload filtering supports the version predicate atomic visibility needs |
ADR-01 |
| Lexical index |
OpenSearch over the same chunk rows |
Open source, self-hosted |
Elasticsearch; Tantivy; Vespa as a single hybrid engine |
The degradation path when the vector tier is unavailable, and half of within-contract hybrid fusion |
ADR-03 |
| Index aliases |
etcd, compare-and-swap per (tenant, corpus), watched by the retrieval gateway |
Open source, self-hosted |
Consul; the relational catalogue itself; a vector store's native alias feature |
A tiny, strongly consistent, watchable pointer store — exactly the shape of the alias, and separable from the catalogue's history |
ADR-02 |
| Rebuild and migration orchestration |
Argo Workflows and CronWorkflows, holding migration state in PostgreSQL |
Open source, self-hosted |
Temporal; Airflow; Dagster |
Long-running, resumable, Kubernetes-native jobs for a 14-day rebuild, a nightly sweep and a restore |
ADR-02 |
| Extraction and OCR |
Tika-based parsers and Tesseract in egress-restricted pods, bounded in time, memory, depth and expansion ratio |
Open source, self-hosted |
Unstructured; a commercial document-intelligence API |
The least-trusted compute in the system, so it must be isolated rather than merely sandboxed by convention |
ADR-08 |
| Quality, drift and cost analytics |
ClickHouse for evaluation runs, drift series and cost attribution |
Open source, self-hosted |
DuckDB on object storage; Druid; a cloud warehouse |
Columnar scans over thirteen months of runs and series, which is a different access pattern from anything else in the platform |
ADR-16 |
| Workload identity and secrets |
SPIRE for SVIDs, OpenBao for source credentials, Keycloak for human identity |
Open source, self-hosted |
cert-manager with an internal CA; HashiCorp Vault; a cloud identity service |
mTLS between every workload, short-lived source credentials rotatable without a pipeline outage, and operators separated from workloads |
ADR-13 |
| Retrieval edge |
Envoy, terminating mTLS and resolving the alias from a watched cache |
Open source, self-hosted |
NGINX; Traefik; a service mesh ingress |
Resolving the alias at the edge from a cached pointer is what keeps a control-plane outage off the retrieval path |
ADR-02 |
| Observability |
OpenTelemetry collection, Prometheus with Mimir, Grafana, Loki and Tempo |
Open source, self-hosted |
VictoriaMetrics; a managed observability platform |
Oldest-unembedded age per lane is both SLI and scaling trigger, so metrics have to be first-class rather than a side channel |
ADR-09 |