Federal Frontier SRE architecture
Our stack — FFO, Warrant, Remuda, local-first inference, posse/SME specialists on a shared Investigator harness (OpenCode Runner or Claude Code runner).
Audience: operators and stakeholders evaluating the Federal Frontier SRE stack against hosted multi-cluster Kubernetes assistants.
This page leads with our architecture. Hosted assistants are a useful reference for operator expectations; they are not the design north star.
Federal Frontier architecture (lead)
| Pillar | Role |
|---|---|
| Primary path | Problem (English brief or alert) → sre-dispatch Job → Remuda → Warrant/FAS |
| Dual runners | OpenCode Runner or Claude Code runner on the shared Investigator harness |
| Purpose-built Jobs | Task-shaped SRE agent Jobs (Remuda slice + first tools + playbook/scout brief) |
| Shared harness | One harness shape + posse roles — specialization is configuration |
| SME catalog | Automatic routing for known classes — not separate binaries or an agent farm |
| Posse roles | Scout / Sage / Wrangler / Marshal productized onto Remuda tool slices and prompts |
| Remuda (MCP) | Product MCP registry/router (Wanaku engine); Job selects the specialist namespace slice |
| FFO | TypeDB facility graph for topology and remediation scope |
| Warrant / FAS | Statute-backed risk and authz before remediation |
| Local-first | Gemma hot path on-prem; Bedrock Opus cold path with transcript |
| Estate | VitroAI · EKS and RKE2 · Outrider · Ceph · network · platform control — see Coverage |
The catalog currently lists five specialist routes on the primary path. See ADR-033 and /docs/sre/sme-catalog/.
Where hosted multi-cluster assistants typically differ
Hosted multi-cluster K8s assistants often optimize for SaaS multi-cluster UX, vendor-hosted correlation, and a large packaged playbook library in public-cloud environments.
Federal Frontier optimizes for sovereignty, facility truth (FFO), Remuda MCP on FMC, Warrant authz, and local-first inference — constraints that define the product shape.
| Concern | Federal Frontier |
|---|---|
| Air-gap / sovereignty | Local Gemma scout; cloud only on quality-gate miss |
| AuthZ | Warrant PEP + FAS / Keycloak OIDC on Remuda |
| Facility truth | FFO TypeDB, not events alone |
| Tool plane | Remuda namespace slices per specialist Job |
| Runtime model | Shared harness; OpenCode Runner or Claude Code runner; specialist routes accelerate known classes |
What we do not claim
- Drop-in UI parity with any hosted multi-cluster assistant.
- That every incident class already has a dedicated Remuda tool pack online.
- That catalog size is a substitute for lab verification.
Grow capability by wiring Remuda tools and classifiers on the shared harness — Jobs stay purpose-built by configuration; runners stay OpenCode Runner or Claude Code runner.
Eupraxia Labs · Federal Frontier · Platform docs