Runtime persistence. State, journals, audit trails, sessions, secrets.
| What Kindgi stores | Status | Purpose |
|---|---|---|
| Agents | Live | Agent definitions and versions |
| Tools | Live | Tool definitions and schemas |
| Guardrails | Live | Declarative check definitions |
| Flows | Live | Multi-agent flow definitions |
| Graphs | Live | Task graph definitions, version-pinned |
| Policies | Live | Per-tenant policy definitions |
| Providers | Live | Model and non-model provider configs |
| Adapters | Live | Binding metadata and versioning |
| MCP endpoints | Live | Registered MCP endpoints |
| Eval suites | Live | Evaluation suite definitions |
| Eval runs | Live | Historical evaluation results |
| Cost tracking | Live | Per-tenant cost aggregation |
| Sessions | Live | User and agent session state |
| OAuth state | Live | OAuth flow state |
| Idempotency | Live | Request deduplication |
| Event bus | Live | Runtime event journal |
| Audit events | Live | Signed audit trail |
| Environments | Live | Environment configuration |
| Platform metadata | Live | Multi-tenant platform state |
| Secrets (encrypted) | Live | Server-side encrypted at rest |
Where the runtime writes documents, generated artifacts, and downloadable audit bundles.
| Backend | Status | Notes |
|---|---|---|
| Filesystem | Live | Local disk or mounted volume |
| AWS S3 | Live | S3 + S3-compatible (MinIO, Wasabi) |
| Cloudflare R2 | Soon | R2 via S3-compatible client |
| Google Cloud Storage | Soon | GCS via Google SDK |
| Azure Blob Storage | Soon | Azure Blob via Azure SDK |
Ed25519 for provenance signatures. Envelope encryption for secrets at rest.
| Purpose | Status | Notes |
|---|---|---|
| Ed25519 signing | Live | Provenance DAG signatures, key rotation supported |
| libsodium KMS | Live | Encrypt secrets at rest in Postgres |
| AWS KMS | Soon | Cloud KMS with envelope encryption |
| GCP KMS | Soon | Cloud KMS |
| Azure Key Vault (KMS) | Roadmap | Azure managed KMS |
Kindgi is a container image. Deploy it anywhere your infrastructure runs containers.
| Runtime | Status | Notes |
|---|---|---|
| Docker Compose | Live | Single-command local boot for development |
| Kubernetes | Live | Any conformant cluster; Helm chart included |
| Amazon ECS | Live | Fargate or EC2 backing |
| Google GKE | Live | Autopilot or standard |
| Azure AKS | Live | Standard container hosting |
| Fly.io / Railway | Live | Any container-native PaaS |
Three ways to run Kindgi. Same runtime, different operator.
| Tier | Status | Notes |
|---|---|---|
| Local (dev) | Live | docker compose up — Postgres, api-server, and docs in a single command. Testcontainers-backed. No cloud accounts. |
| Self-hosted | Live | In your VPC, on your infrastructure. Bring your Postgres, blob backend, and container runtime. Design-partner deployments today. |
| Managed (Kindgi Cloud) | Private preview | We operate the runtime. Managed Postgres, rotating keys, SOC 2 in progress. Request early access. |