Hugging Face chat sends the tools and returns the tool calls
message.tool_calls, but HuggingFaceAdapter sent no tools (so tool_choice was dropped too) and never read tool_calls. Every HUGGINGFACE model therefore failed th...
The boot backfill counts row-less-by-design models apart
Every AIService start logged 'capability rows written for 21 model(s)' though completions models no capability Kamo uses (ruling SP01-T21), so they stay row-les...
A model list anyone can read no longer passes a wrong key
The Hugging Face router and OpenRouter answer GET /v1/models with 200 for no key and for a wrong key, so Test connection read OK and sync reconciled 140 models ...
Auto routing never picks a row-less model the catalogue says Kamo cannot call
The legacy router let a model with no capability rows through on the name rule legacy-completions *-instruct) get no rows by design, and their names pass the A...
An AI session or the System User holds no platform right in AIService
Master §11 'SP02 final fixes': a session whose intelligenceType is ARTIFICIAL resolves no platform right by any route (owner flag, god window, administrator row...
Family calls speak HTTP/1.1 on cleartext, never an h2c upgrade
The JDK client defaults to HTTP/2 and sends "Upgrade: h2c" with the first request to an http:// host. uvicorn (httptools) refuses the upgrade and drops the requ...
Chat, routing and the model picker run on the registry; capability backfill replaces the pricing backfill
Catalog and coverage, platform console API, internal registration and attestation, health sweep
Model endpoints — manual models, capability edits and verify, price rows, retire-not-delete
A context edit keeps an enabled LONG_CONTEXT in step, so the next capability write no longer restores the old value; a listed capability that needs details is r...
Provider endpoints on the registry — draft test, sync, verify, retire-not-delete, Provided-by-Kamo opt-out
Live capability probes — VERIFIED only from a passing probe; batch verify capped at 200
A chat probe fails on a 200 that is not a completion, names a failure as the connection check does (TLS included), cancels a call that runs out of time, and a 4...
Credentials from env or vault, org/platform visibility, platform-right authz, safe views, internal auth
Capability source precedence, the single capability writer, and the batch capability index
An adapter that denies TEXT_GENERATION speaks for the whole chat family; a switched-off LONG_CONTEXT never overwrites a reported context; remove leaves a tombst...
Deepgram, ElevenLabs, AssemblyAI, Cartesia families and the per-type adapter registry
Beyond the plan: the Perplexity chat check classifies failures as every other check does (spec 4.7.3); ElevenLabs and Cartesia refuse a missing voice and a voic...
Real model discovery for OpenAI-style, Anthropic, Google, Hugging Face, Ollama and catalogue-only vendors
Known-model catalogue (hints + unchanged prices) and name-hint classifier
A QUERY key reaches the provider encoded once
ChatAuth.url returns a URI. WebClient reads a String as a URI template and encoded the already-encoded key again (+ became %252B), so any key holding +, /, = or...
Pin kamo-shared-library 1.6.1, the only version that exists
The library moved to 1.6.1 and this service still asked for 1.6.0. There is no window in which both resolve: the library is never published to a remote, so the ...
No live credentials in application.yml defaults
The local-development defaults carried the database OWNER's password (${DB_PASSWORD:<literal>}), and apiservice/securityservice also the live changelog webhook ...
MCP configs need MANAGE_AI_SETTINGS, provider/MCP urls can't reach the cluster, quota policies are enforced
Three independent findings, fixed together because the first two share files and a class. 1. AiMcpController had zero right checks on create/update/delete/test...
Provider API keys never leave AIService, and only MANAGE_AI_SETTINGS can change a provider
GET /api/ai/providers and GET /api/ai/providers/{id} answered with each provider's DECRYPTED API key. The list is what every member's AI chat model picker loads...
Liveness probe on /actuator/health/liveness, not the DB-aware aggregate
The aggregate /actuator/health includes the DataSource indicator, so restarting the database failed liveness on every pod at once and restarted the whole platfo...
Release idle Hikari connections now that YSQL pooling is shared
The connection manager no longer pins sessions **************** so idle app connections no longer each hold a database backend. Keep the pool maximum, but stop ...
Accept OCI image indexes when resolving the built digest [skip ci]
The images are pushed as OCI image indexes, so asking the registry for a single image manifest only answered 404, the digest came back empty and the check faile...
Restart when a same-commit rebuild leaves pods on the old digest [skip ci]
The rollout step tried to detect a same-commit rebuild by comparing the Deployment's image reference before and after `set image`. "Apply manifests" has already...
An address opted out of marketing is not written to by the sales agent either
The agent's email check was topic-less, so an address that had stopped newsletters and campaigns - but was not on the whole do-not-email list - could still get ...
The sales agent honours the organization's email opt-out list
Before any email touch the outbound gate now asks the organization's email opt-out ledger about the contact's address. The address is the one the contact key po...
Prove the deploy by digest, not by tag
The preceding commit stops `set image` being a silent no-op. This asserts the outcome: after the rollout, the tag is resolved to a digest at the registry and th...
A rebuild of the same commit deployed nothing and reported success
The image is tagged with the commit SHA, so rebuilding the same commit produces an identical image reference. `kubectl set image` then changes nothing, the Depl...
Lock the shared sweeps, and run two pods
Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...
Let a rollout finish what the old pod was doing
Deploys replaced the only pod of each service with nothing to catch the requests in flight. Three settings, applied across the fleet: - preStop sleeps 10s befo...
A KB link goes to the article its text names
A member asked how to set their org up and got the setup checklist back, each step naming the article that explains it. All three links pointed at the same arti...
No upstream error text reaches a member, whichever provider failed
memberTextFor fell through to getMessage() for anything that was not an AiProviderException. Only the HuggingFace adapter classifies its refusals; every other o...
Retire a model the provider won't route, and stop quoting it at members
Follow-up to the router-catalogue fix. That stops unroutable models being LISTED; this stops one already in an org's catalogue from breaking the assistant and n...
List the Hugging Face models the router will actually serve
Chat goes to the Inference Providers router **************** but discoverModels asked the HUB for models that are "warm" somewhere — a different and much larger...
Remove the unreviewed-reply unread-count endpoints
Paired with the kamo-internal removal of the AI unread badge: the count never told the member anything actionable (no push channel backs it, so non-zero only ev...
Unreviewed-response counts and a mark-read
Keyed by session guid, which is what a tool window carries. Not audited as a disclosure: it returns counts and never a word of a transcript, and recording a bad...
Pin kamo-shared-library 1.6.0
The library moved to 1.6.0 while consumers stayed on 1.5.0. Consumer CI builds the library from a fresh clone into a cold ~/.m2 and ci-settings.xml mirrors Mave...
Size the pod above its own JVM heap ceiling [skip ci]
The image starts the JVM with -XX:MaxRAMPercentage=70 -XX:+AlwaysPreTouch, so the heap alone may take 70% of the container limit and pre-touch keeps every commi...
Administering models and reading usage take the rights that name them
AiModelController and AiUsageController checked organization ownership and no right. The 403s already in the model controller compare provider.getOrganizationId...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
