Architecture v0.3.0 — AWS, auth & policy, docs¶
Scope from decision D18 and contracts §8–§10. Everything from v0.2.0 plus:
AWS path (§8) — built and unit-tested, never applied to a real account¶
deploy/terraform/aws: EKS clusterramen(one small managed node group), DynamoDB tableramen(pk/sk single table, on-demand), S3 bucketramen-<account>-groups, Secrets Manager, ECR reposramen/console+ramen/worker, console IAM role via IRSA, AWS Load Balancer Controller + Fluent Bit → CloudWatch Logs installed from Terraform, self-signed cert imported into ACM.deploy/cloudformation/ramen.yaml: the same base resources as one template for teams that cannot run Terraform.- Helm
provider: aws: console Ingress classalb(groupramen, internet-facing, HTTPS 443); each zone gets an Ingress in the same ALB group for/mcp/<group>/<zone>. ALB cannot rewrite paths, so the node accepts/mcp/<group>/<zone>as an alias of/mcpwhenRAMEN_MCP_PATH_PREFIXis set. - Runtime
bucket.synchandless3://(boto3) as it doesgs://. - Console adapter
ramen_console.cloud.aws: same canary flow; logs via CloudWatch Logs Insights; rebalance via weighted target groups; IP rules via WAFv2 IPSet + web ACL on the ALB; service accounts via IAM roles trusting the cluster OIDC provider. Secrets backendaws: Secrets Managerramen/<group>/<env|all>/<zone|all>/<NAME>.
Auth, policy, tool blocking (§9)¶
- OAuth/OIDC providers from yaml/env (
RAMEN_OAUTH_<NAME>_*), a button per provider on the login page, role mapping by claim,auth.password_login: falsetoggle with a break-glassRAMEN_ADMIN_FORCE_PASSWORD=1. - Email: SMTP from
RAMEN_SMTP_*, invite on user create, password reset, optional magic-link login;RAMEN_SMTP_HOST=file://<dir>dev backend. - SA policy engine: group admins request
permissions; super admins approve; the adapter binds the mapped cloud role (ramen_console/policy/permissions.py). Denied-by-rule → 409, audited. - Tool blocking: per-environment
blocked: [names]→RAMEN_BLOCKEDon deploy → node hides them from list calls and answers-32601; block/unblock toggles on the group page. - CSRF: per-session token on HTML forms (
ramen_csrfcookie + hidden field /X-Ramen-CSRF); API-key calls exempt.
Docs and release material (§10)¶
This site (MkDocs Material, GitHub Pages on push to main and on tags), README with real screenshots,
llms.txt + JSON-LD, generated version tracker, skills/ for cloud-ops agents, launch drafts.