Saltar al contenido principal

Technical Health Assessment

This assessment is based on repository metadata, static code/manifests audit, README evidence, and open issue titles. It should be refreshed from GitHub before each release or go-live review.

Current status by domain​

DomainStatusEvidence / rationale
Core contractsHealthyalphaswarm_core has no open issues and remains dependency-light.
Hosted platformAt-risk before go-livealphaswarm_platform#18 is P0 for deployment prerequisites/CD runbook; many Helm/Terraform/K8s surfaces increase release complexity.
Monolith/data isolationCritical riskalphaswarm carries RLS strict-mode, missing policy, context writer, migration, and test debt.
IdentityNeeds integrated rollout proofalphaswarm_auth appears strong architecturally, but tenant-router/RLS/Entra flows require cross-repo validation.
Hosted UIAt-risk before go-livealphaswarm_ui#8 P0: replace mocks with backend-backed data and E2E coverage.
IDE/MCPAt-risk before go-livealphaswarm_ide#4 and alphaswarm_mcp#3 are P0 production hardening/go-live issues.
Agent runtimeModerate riskalphaswarm_agents has robustness and PII-redaction debt.
AI/ML governanceScaffolded/healthy but migration-dependentalphaswarm_mlops has no open issues, but README states source migrations proceed by gated rollout.
Learning/ScholarHigh riskalphaswarm_learning has P0 production data-path TODO and test collection failures.
ObservabilityRoadmap incompletealphaswarm_observe, KB federation, and research plane issues require more spans/read APIs/replay features.
DocsNeeds reconciliationalphaswarm_docs#19 calls out stale readiness docs vs current source-of-truth runbooks.

Open issue themes​

P0 / critical​

  • alphaswarm#32 — validate RLS strict-mode rollout and null-workspace backfill before go-live.
  • alphaswarm#31 — route broker venue order submissions through the OrderIntent airlock.
  • alphaswarm#137 — context-less writers fail closed under tenancy RLS enforcement.
  • alphaswarm#138 — 16 tenant-scoped tables with workspace_id lack RLS policy backstop.
  • alphaswarm#139 — apply agent-ledger RLS DDL to every target DB before enforcement.
  • alphaswarm_platform#18 — complete minimum go-live deployment prerequisites and CD runbook.
  • alphaswarm_ui#8 — replace go-live mock surfaces with backend-backed data and E2E coverage.
  • alphaswarm_ide#4 — complete IDE go-live checklist for image, identity, DNS/TLS, MCP, monitoring.
  • alphaswarm_mcp#3 — harden MCP deployment for production readiness.
  • alphaswarm_learning#1 — replace Scholar graph/LLM TODO stubs with production data paths.
  • alphaswarm_client#4 — finish and validate hosted demo-mode deployment for classic client.

P1 / should-fix​

  • alphaswarm#143 — Alembic cannot upgrade head from empty.
  • alphaswarm#145 — bootstrap does not seed default tenancy rows.
  • alphaswarm#142 — Alpha Vantage loader tests fail due to attribute drift.
  • alphaswarm#141 — destructive Postgres RLS test with hardcoded port.
  • alphaswarm#144 — frozen screening dashboard schema not vendored.
  • alphaswarm_config#29 — credentials subpackage imports monolith.
  • alphaswarm_docs#19 — stale readiness docs need source-of-truth reconciliation.
  • alphaswarm_observe#2 — evals/lineage/read API, registry/annotation/alert/replay roadmap.
  • alphaswarm_api#1 — remove generated and IDE artifacts.

P2 / cleanup and quality​

  • Dead code in strategies/momentum.py.
  • Health collector under-counting under RLS.
  • Config validation benign fail-open in screening datasets.
  • Agent registry default directory import-time resolution.
  • Empty tool_call_id runtime robustness.
  • RAG ingest parser provenance/hash drift.
  • Additional retrieval/federation/research spans.

Prioritized follow-up plan​

PriorityWorkstreamOwners / reposAcceptance criteria
P0Tenant isolation go-live gatealphaswarm, alphaswarm_platform, alphaswarm_authAll RLS DDL applied, missing policies resolved, strict-mode validation passed, default seed rows proven, rollback documented.
P0Hosted deployment readinessalphaswarm_platform, alphaswarm_ops_console, alphaswarm_docsCD runbook complete, Helm/Terraform smoke tests documented, rollback path tested, ops console confirm gates verified.
P0Customer-facing UI readinessalphaswarm_ui, alphaswarm_controller, alphaswarm_apiMock surfaces replaced, BFF backed by services, E2E coverage against staging-like environment.
P0MCP/IDE production pathalphaswarm_mcp, alphaswarm_ide, alphaswarm_authIdentity, DNS/TLS, MCP connectivity, monitoring, and deployment image checklist complete.
P1Docs reconciliationalphaswarm_docs, all service ownersThis audit lands in docs repo; stale readiness pages replaced or linked to canonical runbooks.
P1AI/ML observability coveragealphaswarm_observe, alphaswarm_kb_federation, alphaswarm_research, alphaswarm_agentsAGENT/EVAL/RETRIEVAL/federation spans emitted and visible in read API dashboards.
P1Package-boundary cleanupalphaswarm_config, alphaswarm_api, alphaswarm_agents, alphaswarm_learningMonolith imports removed/guarded, generated artifacts removed, tests pass.
P2Health debt burn-downIndividual repo ownersCosmetic/quality issues closed; no new P0/P1 regressions.

Business-team follow-ups​

  • Decide release/go-live criteria for hosted platform, UI, IDE, and MCP based on the P0 list above.
  • Assign explicit owners for tenant isolation/RLS, deployment readiness, UI go-live, MCP/IDE, and docs reconciliation.
  • Confirm customer-facing identity story: Entra-only hosted app, staff admin flow, worker/device auth, and support process.
  • Define customer documentation boundaries: public marketing/docs vs internal operations/security runbooks.
  • Maintain a roadmap view linking MLOps governance maturity to product claims around model risk, evaluations, and agent reliability.

Development-team follow-ups​

  • Add or update tests for RLS migrations and tenant-router auth modes before strict enforcement.
  • Add service catalog automation to alphaswarm_docs from GitHub metadata and repo manifests.
  • Ensure each deployable repo documents image name, chart path, health endpoints, env vars, and rollback.
  • Require issue labels for priority/domain to make future health reports machine-sortable.
  • Add CI checks that prevent generated artifacts, IDE files, raw secrets, and stale doc links from entering service repos.