Skip to content

Automation and Agents

BaddKharma edited this page Sep 28, 2026 · 4 revisions

Automation and Agents

redStackPRO is operated by a human on the canvas, and it is also legible to agents. Composing a topology, validating it, and compiling it to a runnable export are all available over a documented API and a command line, and a topology is plain JSON against a published schema, so an operator can point their own agent or LLM at it to read the repository and schema, learn how the tool works, and build and manipulate topologies on their behalf. The human stays primary and in charge; an agent is a secondary, operator-chosen augmentation.

redStackPRO does not host a shared API for third parties to call. You run your own instance and operate it, or let your own agent operate it, at the same trust as the person who started it.

What an agent reads

  • The document schema, at src/redstackpro/schema/topology/ and at GET /api/v1/registry/schema. The canvas renders its own forms from this rather than hardcoding fields.
  • The vocabulary, at GET /api/v1/registry/palette, /registry/providers and /registry/roles: the node kinds, providers and edge roles that exist.
  • The API contract at /docs and /openapi.json, which an LLM can ingest as tools.
  • docs/architecture.md, docs/schema.md and docs/validation.md for how the pipeline fits together and what each finding means.

The loop

  1. Read the schema and the registry to learn the vocabulary.
  2. Compose or edit a topology as JSON.
  3. POST /api/v1/validate with {"document": <topology>, "provider": "gcp"}. You get back valid, error and warning counts, and structured findings, each with a stable code, the target ids, a message and a remedy. Nothing is stored.
  4. Fix what the findings name, then validate again.
  5. POST /api/v1/compile with the same body. You get the working directory as a file map, or a 422 whose details carry the same findings, because the compiler refuses a document that still has errors.
  6. Run the export yourself. redStackPRO holds no cloud credentials.

The same loop runs from a shell with redstackpro validate and redstackpro compile, which read a topology and write the export without the API.

Identity today

The running instance trusts the local caller as a single administrative principal, which suits a single-user or self-hosted deployment. Agent identity is a first-class part of the model, not an afterthought, so authenticated and scoped access can arrive without reshaping the API. That authenticated, multi-tenant agentic path is part of the enterprise edition.

See Concepts for the topology and the export-only model, and Validation for the findings.

Clone this wiki locally