Skip to content

Architecture v0.3.0 — AWS, auth & policy, docs

Scope from decision D18 and contracts §8–§10. Everything from v0.2.0 plus:

AWS path (§8) — built and unit-tested, never applied to a real account

  • deploy/terraform/aws: EKS cluster ramen (one small managed node group), DynamoDB table ramen (pk/sk single table, on-demand), S3 bucket ramen-<account>-groups, Secrets Manager, ECR repos ramen/console + ramen/worker, console IAM role via IRSA, AWS Load Balancer Controller + Fluent Bit → CloudWatch Logs installed from Terraform, self-signed cert imported into ACM.
  • deploy/cloudformation/ramen.yaml: the same base resources as one template for teams that cannot run Terraform.
  • Helm provider: aws: console Ingress class alb (group ramen, internet-facing, HTTPS 443); each zone gets an Ingress in the same ALB group for /mcp/<group>/<zone>. ALB cannot rewrite paths, so the node accepts /mcp/<group>/<zone> as an alias of /mcp when RAMEN_MCP_PATH_PREFIX is set.
  • Runtime bucket.sync handles s3:// (boto3) as it does gs://.
  • Console adapter ramen_console.cloud.aws: same canary flow; logs via CloudWatch Logs Insights; rebalance via weighted target groups; IP rules via WAFv2 IPSet + web ACL on the ALB; service accounts via IAM roles trusting the cluster OIDC provider. Secrets backend aws: Secrets Manager ramen/<group>/<env|all>/<zone|all>/<NAME>.

Auth, policy, tool blocking (§9)

  • OAuth/OIDC providers from yaml/env (RAMEN_OAUTH_<NAME>_*), a button per provider on the login page, role mapping by claim, auth.password_login: false toggle with a break-glass RAMEN_ADMIN_FORCE_PASSWORD=1.
  • Email: SMTP from RAMEN_SMTP_*, invite on user create, password reset, optional magic-link login; RAMEN_SMTP_HOST=file://<dir> dev backend.
  • SA policy engine: group admins request permissions; super admins approve; the adapter binds the mapped cloud role (ramen_console/policy/permissions.py). Denied-by-rule → 409, audited.
  • Tool blocking: per-environment blocked: [names] → RAMEN_BLOCKED on deploy → node hides them from list calls and answers -32601; block/unblock toggles on the group page.
  • CSRF: per-session token on HTML forms (ramen_csrf cookie + hidden field / X-Ramen-CSRF); API-key calls exempt.

Docs and release material (§10)

This site (MkDocs Material, GitHub Pages on push to main and on tags), README with real screenshots, llms.txt + JSON-LD, generated version tracker, skills/ for cloud-ops agents, launch drafts.