Skip to content

kl3inIT/OrgMemory

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

232 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

OrgMemory

OrgMemory is a governed organizational memory layer for enterprise AI work. It turns uploads and approved connector evidence into versioned, citable Knowledge Assets without weakening source permissions.

The current repository contains a canonical source-ingestion ledger, stable Knowledge Asset identities with immutable versions, permission-aware hybrid retrieval, an in-app Assistant, and the foundations for a secure knowledge graph. It is a production-shaped POC foundation, not an approved production deployment.

Current Stack

Java 25, Spring Boot 4.1, Spring Modulith 2.1, Spring AI 2.0, PostgreSQL with pgvector, Flyway, Gradle 9.6, pnpm 11, React 19, Vite 8, TypeScript 7, Tailwind CSS 4, shadcn/ui, TanStack Query/Router, and AI SDK UI components.

Repository

core/          domain, application services, JPA, and Flyway
apps/api/      REST, OIDC, secure search, OpenAPI, migration owner
apps/worker/   background source ingestion and indexing boundary
apps/mcp/      authenticated read-only MCP delivery adapter
integrations/  provider adapters, including the official OpenFGA Java SDK
web/           React app shell, secure search, and document management
docs/          vision, roadmap, decisions, specs, tests, and increments

Local Development

.\gradlew.bat demoBootstrap
.\gradlew.bat :apps:api:bootRun --args='--spring.profiles.active=dev'
# In another terminal after Flyway has created the schema:
.\gradlew.bat demoSeed
corepack pnpm -C web install
corepack pnpm -C web gen:api
corepack pnpm -C web dev --host 127.0.0.1 --port 5173

The development path always uses OIDC plus OpenFGA; there is no permitAll profile. Keycloak authenticates users, explicit issuer/subject bindings map them to internal users, and OpenFGA grants application permissions. The API can boot without an LLM key only when ORGMEMORY_ASSISTANT_RETRIEVAL_ENGINE=CANONICAL_HYBRID is selected explicitly. The default GRAPH_RAG runtime requires configured chat and embedding models; authorization fails closed when OpenFGA is unavailable. Never commit .env or provider secrets.

Production starts with --spring.profiles.active=prod. That profile has no local-secret fallbacks: database, OIDC, OpenFGA, object-storage, and OpenAI settings must be supplied explicitly. The API also rejects known development credentials and non-HTTPS public OIDC/web origins before serving traffic. See application-prod.yml for the required environment-variable names.

The reproducible synthetic POC fixtures are documented in demo/README.md. The original XLSX is provenance only; no spreadsheet-specific code is loaded by the application runtime.

The browser is an OIDC BFF client: it stores only an HttpOnly Spring session cookie, never Keycloak tokens. REST SDKs and TanStack Query options are generated with Hey API from contracts/openapi.json; regenerate after changing the API contract.

Verification

.\gradlew.bat --no-daemon compileJava
.\gradlew.bat --no-daemon clean test
corepack pnpm -C web typecheck
corepack pnpm -C web build

Documentation

Start with CLAUDE.md when working as a coding agent.

About

OrgMemory MVP - organizational AI capability registry

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages