Sign inSign up

compagnonsdudev/kex-agent-ai

By compagnonsdudev

•Updated 6 days ago

Image
0

2.0K

compagnonsdudev/kex-agent-ai repository overview

⁠Kex Agent AI

A governed AI agent for Kafka operations. It watches your integration processes through MCP tools, explains what it sees, and asks a named human before it acts — every decision carrying its confidence, its evidence and an audit trail.

Built on Spring Boot 4 / Spring AI 2, Java 25. Ships with a browser console (the Control Center) served by the agent itself, no build step and no CDN. The console manages MCP connections at runtime, shows session activity and lifecycle, and includes a Playground for tools, resources and parameterized resource templates.

⁠Tags

TagWhat it is
latestMost recent stable release
x.y.zAn exact release — what you pin in production
sha-<short>A single commit, kept for traceability

Pre-releases never move latest — a docker pull without a tag should not bring back code nobody has finished judging.

linux/amd64 only: an arm64 image would mean QEMU and an emulated Maven build, an order of magnitude more build time. Each image ships an SBOM, and is scanned for vulnerabilities before it is pushed — the scan runs on a locally loaded build, so a vulnerable image is never published first and judged afterwards. After the push it is pulled back from the registry and started, because a successful push says the layers left, not that the manifest is servable.

⁠Quick start

Against a Kafka SQL Explorer you already run:

docker run --rm -p 8081:8081 \
  -e ANTHROPIC_API_KEY=sk-ant-... \
  -e KEX_AGENT_API_KEY="$(openssl rand -hex 32)" \
  -e KAFKA_EXPLORER_URL=http://host.docker.internal:8080 \
  compagnonsdudev/kex-agent-ai:latest

Then open http://localhost:8081⁠ and paste the same bearer once — it lives in sessionStorage and never leaves the browser. Or talk to the API directly:

curl -X POST localhost:8081/api/agent/chat \
  -H "Authorization: Bearer $KEX_AGENT_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{"message":"List the topics whose name starts with demo. and tell me which ones are empty."}'

The whole stack — Kafka 4.3 (KRaft), Explorer with its MCP server on, and this agent wired to it — is one docker compose up away from the repository⁠.

⁠MCP from the browser

Under Technical → MCP servers, connections can be tested before they are added, enabled or disabled, restricted per tool, diagnosed, and imported/exported. HTTP, SSE and stdio transports are supported. The same workspace exposes active/idle MCP sessions and recent activity. Its Playground lets you call tools, browse/read resources and select resource templates; template fields are generated immediately from the selected template instead of requiring a URI to be assembled manually.

Runtime connections can be encrypted and persisted with KEX_MCP_STORAGE_KEY. For stdio servers, executables remain opt-in through KEX_MCP_STDIO_ALLOWED_COMMANDS. MCP sessions expire after 30 minutes of inactivity by default.

⁠Kafka operational reviews

On an agent image built after this feature is released, and with a compatible Kafka SQL Explorer MCP server connected, the agent can answer (check its advertised tools):

AskMCP evidenceInterpretation
"Is the orders topic compliant in prod?"kex_topic_policy_review(topic, environment)Compares the observed settings with an operator-configured rule for that environment; NOT_CONFIGURED is not a pass.
"Is this consumer falling behind?"kex_consumer_lag_trend(topic, groupId)Needs two complete readings; the first or an expired baseline has no measured trend.
"Where does orders.dlq lead?"kex_dlq_review(queueTopic)Reads bounded Kafka evidence and reports the declared source, retry topics, monitoring reference and replay runbook. No automatic replay.

Configure topic policies and DLQ routes on Kafka SQL Explorer, not on the agent. For a baseline that survives Explorer restarts or works across replicas, configure its shared lag history directory on a writable volume with interprocess locking. See Kafka SQL Explorer's deployment example⁠ and the agent's MCP guide⁠. The agent distinguishes declarations from live observations and treats unavailable data as unmeasured.

⁠Configuration

VariableRole
KEX_AGENT_API_KEYBearer for the agent's own API. Without it every /api/** route answers 503 — the agent refuses to serve rather than serve unauthenticated
ANTHROPIC_API_KEYModel provider key. Absent, the agent starts and reports itself DEGRADED rather than pretending to be healthy
KAFKA_EXPLORER_URLBase URL of the Kafka SQL Explorer MCP server
EXPLORER_MCP_AUTH_TOKENBearer for that MCP server, when it requires one
KEX_AGENT_LLM_PROVIDERanthropic (default) or openai — the latter also covers OpenRouter-compatible gateways
KEX_MCP_STORAGE_KEYEncrypt and persist MCP connections created from the Control Center
KEX_MCP_STDIO_ALLOWED_COMMANDSExplicit allowlist of executables accepted for stdio MCP servers

An unreachable MCP server never blocks startup: the agent boots, says so, and keeps serving what it still can. Every setting, with its reasons⁠.

⁠Health and observability

EndpointContent
/actuator/healthLiveness and readiness — the only route left open, deliberately
/actuator/prometheusMetrics, bearer required
/swagger-ui.htmlThe API, documented from the running instance

The container exposes 8081 and runs as an unprivileged user (10001:10001).

⁠Persistence

/var/lib/kex holds everything the agent remembers outside a database: long-term facts, skills a human approved, the operating charter, and the encrypted MCP connections created from the console. It is declared as a volume — mount a named one over it, or those survive only as long as the container does:

docker run --rm -p 8081:8081 -v kex_state:/var/lib/kex ... compagnonsdudev/kex-agent-ai:latest

With the shared-memory profile and a PostgreSQL datasource, memory, skills, the supervision audit and the decision state move to the database instead — which is what you want behind a load balancer, where a decision approved on one replica has to exist for the others. The encrypted MCP connections stay on disk either way, so the volume is never pointless.

⁠What it will not do

The Kafka SQL Explorer MCP server is read-only by default. In front of it the agent observes and recommends; it does not act. Where a capability can act, autonomy is declared per capability, an execution mode can only narrow it, and anything below the confidence floor goes back to a human. Nothing here is a default you inherit by accident: an unlisted capability is forbidden.

Tag summary

Content type

Image

Digest

sha256:1fb9c9f2a…

Size

244.9 MB

Last updated

6 days ago

docker pull compagnonsdudev/kex-agent-ai