Architecture – Prometheus-X Components & Services

Architecture

ALT-AI (AffectLog's Trustworthy AI) is a dataset-first Trustworthy-AI assessment platform. This document describes the processing pipeline (how a dataset flows through the assessment) and the deployed runtime (the services that actually run), and records how the two map onto each other. For the formal deliverable-level design see design-document.md; for the area-by-area conformance record see design-conformance.md.

Processing pipeline

CSV / JSON / JSONL / Parquet
        ↓
   [Ingest Layer]           ← Polars lazy scanning, streaming chunks
        ↓
   [SecurityLayer]          ← PII detection, HMAC-SHA256 pseudonymisation
        ↓
   [Transform Layer]        ← CSV→xAPI JSONL, Becomino template inference
        ↓
   [Profiling Layer]        ← Schema, descriptive, temporal, sparsity, entropy
        ↓
   [Metrics Layer]          ← Gini, Coverage@K, fairness, representation
        ↓
   [Compliance Layer]       ← JSON-LD, Data Card, Model Card, SOP, GDPR inventory
        ↓
   [Recipe Runner]          ← YAML-driven pipeline orchestration
        ↓
   [FastAPI Backend]        ← OpenAPI 3.1 REST API
        ↓
   [React Dashboard]        ← Vite + TypeScript frontend

Key design decisions

  1. Streaming-first: Never load full 1M+ datasets into memory. Polars lazy scanning + chunked iteration.
  2. Privacy-by-default: Raw personal identifiers never appear in output artifacts (AFFECTLOG_ALLOW_RAW_IDENTIFIERS=false, AFFECTLOG_PSEUDONYMIZE=true).
  3. Dataset-only mode: Model adapters are optional — audits run without any ML model.
  4. Recipe-driven: Pipeline behaviour is configured via YAML recipes, not hardcoded logic.
  5. Reproducible: Every run produces a config_hash, audit_manifest.json, and deterministic IDs.

Component map

Component Module Purpose
ModelAdapter src/affectlog/models/ Standardized ML model interface
ExplanationGenerator src/affectlog/explanations/ SHAP + permutation importance
ResultsProcessor src/affectlog/reports/ Dashboard payload, markdown, CSV
SecurityLayer src/affectlog/privacy/ PII detection + pseudonymisation
PDCClient src/affectlog/pdc/ Prometheus-X connector (mock + real)

See classDiagram-v1.1.png and sequenceDiagram-v1.1.png for the UML class and sequence diagrams (rendered PNGs; no editable source is currently tracked).

Runtime components (deployed system)

The reference self-hosted deployment is defined in docker-compose.yml. The services that actually run:

Service Image / build Exposed port Internal Health check Persistence
postgres postgres:16-alpine 5432 5432 pg_isready volume postgres_data
redis redis:7-alpine — 6379 redis-cli ping volume redis_data
api build Dockerfile 8000 8000 curl /healthz bind mounts ./data, ./runs, ./configs
worker build Dockerfile.worker — — — (Celery) bind mounts ./data, ./runs, ./configs
frontend build Dockerfile.frontend 3000 → 80 80 — —
mailpit axllent/mailpit 8025 (UI), 1025 (SMTP) — — — (dev email sink)

Notes:

Host-development vs Docker self-hosted mode

Authentication and authorization boundary

Deployment model

Four distinct deployment contexts, in increasing order of hardening:

  1. Local host development — single .env, no containers required; fastest inner loop.
  2. Docker Compose self-hosting — the reference stack in docker-compose.yml. It is a working, security-conscious starting point (fail-fast on missing DB password, pseudonymisation on, raw exports off, dev cookies), but it is not by itself a complete production-hardening specification.
  3. AffectLog-controlled production operation — the managed edition, operated by AffectLog with production controls layered on top.
  4. Official Prometheus-X source publication — the public Community-Edition source of record in the consortium organization.

A production deployment of the self-hosted stack must additionally address, as applicable:

The reference Compose stack does not claim to provide all of the above; it provides a reproducible baseline that a deploying institution hardens.

Repository promotion model

Source flows through three stages, each with a distinct role. No stage auto-pushes to the next.

roy-saurabh/edge_affectlog
        │  validated development promotion (reviewed PR)
        ▼
roy-saurabh/t-ai-affectlog                 ← AffectLog production / release repo
        │  reviewed public upstream promotion (cross-repo PR)
        ▼
Prometheus-X-association/t-ai-affectlog     ← official consortium source of record