Repository navigation
Configuration Deployment Config
Production orchestration reference for deploying Spector across containerized, Kubernetes, and major public cloud infrastructures. Covers Docker volume layouts, Helm chart parameters, kernel sysctl tuning, and multi-cloud Terraform modules.
The official Spector Docker container (ghcr.io/spectrayan/spector:latest) uses a dual-tier runtime architecture:
flowchart LR
subgraph Host["Host / Client"]
ClientBrowser["Web Browser (UI)"]
AgentClient["Agent / SDK Client"]
end
subgraph Container["Spector Container (ghcr.io/spectrayan/spector)"]
direction TB
Nginx["Nginx Reverse Proxy<br/>Port 8080"]
Synapse["Spector Synapse Backend<br/>Port 7070 (Virtual Threads)"]
Dashboard["Cortex Web Dashboard<br/>Static Angular SPA Assets"]
VolumeData["/data Volume Mount<br/>(Panama FFM MMAP Storage)"]
Nginx -->|/api/*| Synapse
Nginx -->|/*| Dashboard
Synapse --> VolumeData
end
ClientBrowser -->|HTTP 8080| Nginx
AgentClient -->|HTTP 7070 or 8080/api| Nginx
On docker stop or Kubernetes pod eviction (SIGTERM), entrypoint.sh traps the signal to guarantee zero data loss:
- Nginx is ordered to quit (
nginx -s quit), immediately closing external client ingress. -
SIGTERMis forwarded to the Java PID, triggering Spector's internal JVM shutdown hook. - Spector finishes in-flight requests, flushes all dirty off-heap Panama memory pages (
vectors.mmap), closes open WAL chunk files, and exits cleanly.
| Container Port | Service | Host Binding Example | Purpose |
|---|---|---|---|
8080 |
Nginx (Proxy + UI) | -p 8080:8080 |
Unified frontend endpoint: serves Cortex dashboard at / and proxies REST API at /api/v1/*. |
7070 |
Spector Synapse API | -p 7070:7070 |
Direct backend API port for high-throughput headless agent SDKs. |
| Container Mount Path | Mode | Description |
|---|---|---|
/data |
Read-Write | Root persistent volume mount point. |
/data/memory |
Read-Write | Cognitive memory tier bundles, partitioned files (semantic-xxx.mem), and strength data. |
/data/identity |
Read-Write | Master key, tenant/user identity keystores, and credentials. |
/data/db |
Read-Write | Embedded metadata database (H2/catalog). |
/data/docs |
Read-Only / RW | Optional folder scanned by the batch document ingestion subsystem. |
/app/spector.yml |
Read-Only | Optional custom YAML configuration mounted to override default settings. |
/run/secrets/ |
Read-Only | Docker secrets mount directory for encrypted API credentials. |
docker run -d \
--name spector \
-p 8080:8080 \
-p 7070:7070 \
-v spector-data:/data \
-v $(pwd)/spector.yml:/app/spector.yml:ro \
-e SPECTOR_EMBEDDING_PROVIDER=ollama \
-e SPECTOR_EMBEDDING_BASE_URL=http://host.docker.internal:11434 \
-e SPECTOR_EMBEDDING_MODEL=nomic-embed-text \
-e SPECTOR_EMBEDDING_DIMS=768 \
ghcr.io/spectrayan/spector:latestThe official Helm chart is located under deploy/helm/spector. Below is the complete reference table for all configurable parameters in values.yaml:
| Parameter | Type | Default | Description |
|---|---|---|---|
replicaCount |
Integer | 1 |
Number of Spector pod replicas. Note: Persistent disk persistence requires ReadWriteOnce or partition replication in cluster mode. |
image.repository |
String | ghcr.io/spectrayan/spector |
Container image repository. |
image.tag |
String | "" |
Overrides image tag (defaults to Chart.appVersion). |
image.pullPolicy |
String | IfNotPresent |
Kubernetes container image pull policy. |
serviceAccount.create |
Boolean | true |
Create dedicated Kubernetes ServiceAccount. |
podSecurityContext.fsGroup |
Integer | 1000 |
Group ID with filesystem permissions for /data. |
securityContext.runAsNonRoot |
Boolean | true |
Enforces non-root container execution. |
securityContext.runAsUser |
Integer | 1000 |
Spector service user ID. |
securityContext.readOnlyRootFilesystem |
Boolean | false |
Read-only container root (/data remains writable). |
securityContext.capabilities.drop |
List | ["ALL"] |
Drops all elevated Linux capabilities. |
sysctl.enabled |
Boolean | true |
Master toggle for Project Panama FFM kernel tuning. |
sysctl.useInitContainer |
Boolean | true |
Uses a privileged busybox initContainer to set node sysctls (required on managed cloud clusters like EKS, GKE, AKS). |
sysctl.vmMaxMapCount |
Integer | 262144 |
Virtual memory map limit for Panama off-heap files. |
sysctl.fsFileMax |
Integer | 1048576 |
System-wide maximum open file descriptors. |
service.type |
String | ClusterIP |
Kubernetes service type (ClusterIP, NodePort, LoadBalancer). |
service.ports.dashboard |
Integer | 7700 |
Service port for Cortex UI dashboard. |
service.ports.api |
Integer | 7070 |
Service port for Synapse REST API. |
ingress.enabled |
Boolean | false |
Enable Kubernetes Ingress controller resource. |
ingress.className |
String | "" |
Ingress class (e.g. nginx, alb, traefik). |
ingress.hosts[0].host |
String | spector.local |
Public ingress hostname. |
resources.requests.cpu |
String | 500m |
CPU compute request. |
resources.requests.memory |
String | 1Gi |
RAM allocation request. |
resources.limits.cpu |
String | 2000m |
Maximum CPU compute limit. |
resources.limits.memory |
String | 3Gi |
Maximum RAM allocation limit (tune based on vector count). |
persistence.enabled |
Boolean | true |
Attach PersistentVolumeClaim for storage durability. |
persistence.accessMode |
String | ReadWriteOnce |
PVC access mode. |
persistence.size |
String | 10Gi |
PVC storage allocation size. |
persistence.mountPath |
String | /data |
Path inside container where PVC is attached. |
persistence.storageClass |
String | "" |
StorageClass name (empty string uses cluster default). |
persistence.createStorageClass |
Boolean | false |
Whether Helm should provision a custom high-performance StorageClass. |
persistence.storageClassName |
String | spector-high-perf |
Name for custom provisioned StorageClass. |
persistence.provisioner |
String | ebs.csi.aws.com |
CSI driver provisioner for custom StorageClass. |
persistence.volumeBindingMode |
String | WaitForFirstConsumer |
Delays volume binding until pod is scheduled to a specific node zone. |
env |
Map | (See values.yaml) | Key-value dictionary of environment variables injected into the container. |
secretRef.name |
String | "" |
Existing Kubernetes Secret containing sensitive API keys (SPECTOR_EMBEDDING_API_KEY, etc.). |
nodeSelector |
Map | {} |
Node labels for pod scheduling. |
affinity |
Map | {} |
Pod and node affinity / anti-affinity rules. |
tolerations |
List | [] |
Node taints tolerated by the Spector pod. |
Because Spector uses memory-mapped files (vectors.mmap) and synchronous WAL logging, selecting the correct StorageClass is critical for query latency and write throughput:
| Cloud Platform | Recommended StorageClass | CSI Provisioner | Performance Profile |
|---|---|---|---|
| AWS EKS |
gp3 (or io2) |
ebs.csi.aws.com |
Minimum 3,000 IOPS, 125 MB/s throughput; scale IOPS for |
| GCP GKE |
hyperdisk-balanced / pd-ssd
|
pd.csi.storage.gke.io |
Ultra-low read latency for vector page faults. |
| Azure AKS |
managed-csi-premium (or ultra-disk) |
disk.csi.azure.com |
Premium SSD v2 or Ultra Disk with WaitForFirstConsumer. |
| Bare-Metal | Local NVMe (no-provisioner) |
kubernetes.io/no-provisioner |
Maximum throughput ( |
Spector includes native Terraform modules under deploy/terraform/modules/ for automated infrastructure provisioning.
Located at deploy/terraform/modules/aws-ecs:
| Variable | Type | Default | Description |
|---|---|---|---|
name |
String | spector |
Application and resource naming prefix. |
aws_region |
String | (Required) | AWS target region (e.g., us-east-1). |
cluster_id |
String | (Required) | ID of target AWS ECS cluster. |
subnets |
List(String) | (Required) | VPC subnets where Fargate tasks will be placed. |
security_groups |
List(String) | [] |
Security group IDs attached to the ECS task. |
assign_public_ip |
Boolean | false |
Assign public IP (useful for public subnets without NAT). |
image |
String | ghcr.io/spectrayan/spector:latest |
Container image URI. |
cpu |
String | 1024 |
Fargate CPU units (1024 = 1 vCPU). |
memory |
String | 2048 |
Fargate RAM allocation in MB. |
dimensions |
Number | 384 |
Cognitive memory vector dimensionality. |
embedding_provider |
String | (Required) | Provider type (ollama, openai, google, anthropic, etc.). |
| Output Name | Description |
|---|---|
service_name |
The name of the provisioned ECS Service. |
task_definition_arn |
Full ARN of the generated ECS Task Definition. |
service_id |
Unique ID of the ECS Service. |
Located at deploy/terraform/modules/gcp-cloudrun:
| Variable | Type | Default | Description |
|---|---|---|---|
project_id |
String | (Required) | GCP project identifier. |
region |
String | (Required) | GCP region (e.g., us-central1). |
service_name |
String | spector |
Name of the Cloud Run service. |
image |
String | ghcr.io/spectrayan/spector:latest |
Container image URI. |
cpu |
String | 2 |
Number of vCPUs allocated. |
memory |
String | 2Gi |
Memory allocated to the container. |
min_instances |
Number | 1 |
Keep 1 instance warm to prevent cold-start index reloads. |
max_instances |
Number | 10 |
Auto-scaling ceiling. |
filestore_mount |
String | "" |
Optional Cloud Filestore NFS mount path for /data. |
| Output Name | Description |
|---|---|
service_url |
Public HTTPS URL for the deployed Cloud Run service. |
service_name |
Unique Cloud Run resource identifier. |
Located at deploy/terraform/modules/azure-aca:
| Variable | Type | Default | Description |
|---|---|---|---|
resource_group_name |
String | (Required) | Azure resource group name. |
location |
String | (Required) | Azure data center location (e.g., eastus). |
container_app_environment_id |
String | (Required) | ID of target Container Apps Managed Environment. |
app_name |
String | spector |
Name of the Container App. |
cpu |
Number | 1.0 |
Container CPU cores. |
memory |
String | 2.0Gi |
Container memory. |
storage_account_name |
String | "" |
Storage account backing Azure Files volume for /data. |
azure_file_share_name |
String | "" |
Azure File share name mounted to /data. |
| Output Name | Description |
|---|---|
fqdn |
Fully Qualified Domain Name of the container application. |
app_id |
Unique Azure Container App resource ID. |
Spector uses AES-256-GCM envelope encryption with HKDF-SHA256 per-tenant key derivation for its universal credentials vault (credentials table, ADR-0076, Issue #1052).
-
Production Environments: When running in any profile outside
devandtest(including the default production profile),SPECTOR_MASTER_ENCRYPTION_KEY(orspector.security.master-key) must be explicitly provided. If unset or blank, Spector refuses to boot and fails fast with taxonomy error[SPE-820-002 / SPE-SEC-002]:[SPE-820-002 / SPE-SEC-002] Master encryption key is required outside dev/test profiles (set SPECTOR_MASTER_ENCRYPTION_KEY or spector.security.master-key) -
Development Mode (
devprofile): If unset, Spector falls back to a deterministic development key and prints a prominentWARNbanner alerting developers that the configuration is insecure for production. -
Testing Mode (
testprofile): Falls back to a deterministic key with debug logging to allow automated test suites to execute without manual key management.
Generate a cryptographically secure 256-bit random key before deploying:
# 256-bit hexadecimal key (recommended)
openssl rand -hex 32
# Alternative: 256-bit Base64 key
openssl rand -base64 32-
Environment Variable:
export SPECTOR_MASTER_ENCRYPTION_KEY="<64-hex-char-secret-key>"
-
Docker Secrets (Recommended for Swarm / Compose):
Mount the secret at
/run/secrets/spector_master_encryption_key. The container'sentrypoint.shautomatically reads and exports it into the backend process. -
Kubernetes Secret / Helm:
Inject via
secretRef.nameor container environment variable invalues.yaml:env: SPECTOR_MASTER_ENCRYPTION_KEY: valueFrom: secretKeyRef: name: spector-secrets key: master-encryption-key
- Because the master key serves as the Key Encryption Key (KEK) for stored credentials, rotating it requires a phased re-encryption process:
- Export or decrypt existing credentials using the current active key.
- Deploy the new master key.
- Re-encrypt and persist credentials under the new key.
- In future BYOK releases (Phase 3 / ADR-0069), key derivation and rotation are delegated to customer-managed KMS endpoints (AWS KMS, GCP KMS, Azure Key Vault, HashiCorp Vault Transit).
- Home
-
Getting Started
- Quick Start
- Installation
- Developer Guide
- JDK API Status
- MCP Server
- Java SDK
- Java API Reference
- Python SDK
- TypeScript SDK
- Spring AI Integration
- CLI Reference
- REST API
- API Playground
- Error Codes
- Configuration
- Deployment
-
Cognitive Memory
- Overview
- Getting Started
- Use Cases
- API Reference
- Concepts
- Pathways
- Scoring features
- Profiles
- Experimental
- Internals
- Design ancestry
-
Memory Kernel
- Overview
- Bundle Architecture
- Memory Shapes
- Binary Layouts & Tags
- WAL & Durability
-
Region Reference
- Overview & Index
- Partition Regions
-
Runtime Regions
- Working Memory
- Co-Activation Matrix
- Index MIDX
- Index IDPL
- Hebbian Graph
- Temporal Chains
- Temporal Facts
- Entity Directory
- Entity Names Pool
- HyperEntity Graph
- Entity Types Registry
- Relation Types Registry
- BM25 Lexical Index
- Checkpoint
- Insula (Somatic Self-Model)
- Continuity
- Provenance
- SPLADE Sparse Index
- Entity Reverse Index
- Identity Regions
- Synapse & Cortex
-
Architecture
- System Overview
- Core Concepts
- Ingestion Pipeline
- MCP Integration
- Distributed Mode
- Event Notifications
- Namespace Sharding
- Single-Namespace Scale & Capacity Limits
- Scale Benchmark Empirical Results
- Writer Quiesce Pause Empirical Results
- Kill-Owner Failover Empirical Results
- Salience & Importance Architecture
- GPU Acceleration
- Performance Tuning
- Test Framework & LLM Judge
- Chat & Visual Test Infrastructure
- Security & Data
-
Architecture Decision Records (ADRs)
- Overview
- Template
- Master Catalog (0001-0085)
-
Memory Kernel & Storage Formats
- ADR-0001: Graph Compression Strategy for Entity Graph
- ADR-0002: Multi-Partition Recall Fan-Out & Frozen Reten...
- ADR-0003: Completing Hypergraph Entity-Graph Graduation
- ADR-0004: Mmap Bundle Architecture & File Descriptor Sc...
- ADR-0005: spector-memory Technical Debt Hardening
- ADR-0042: Graph Recall Architecture and Cognitive Trave...
- ADR-0043: Single-VMA Bundle Layout Specification
- ADR-0044: Memory Kernel Isolation, Composition, and Layout
- ADR-0045: Spector Memory Import & Export Pipeline
- ADR-0046: Single Engram, Four Stores Storage Architecture
- ADR-0047: Episodic Memory and Engram Model Hierarchy
- ADR-0057: Remediation of Hardcoded Memory Offsets and Alignment Constants
- ADR-0062: Spector Memory Organization — Three-Plane Architecture
- ADR-0082: Index Plane Lifecycle, Derived Views, and Reconciliation
-
Active Inference Self-Model Engine (AISME)
- ADR-0006: Episodic Conversation Architecture
- ADR-0007: ReflectPathway — Biological Sleep Consolidation
- ADR-0008: Cognitive Substrate Evolution (TANGLE, GPM, M...
- ADR-0009: AISME Phase 1 — Homeostatic Affective Core
- ADR-0010: AISME Phase 2 — Free-Energy Guided Recall
- ADR-0011: AISME Phase 3 — Modern Hopfield Associative M...
- ADR-0012: AISME Phase 4 — Neural Manifold Distance (NMD)
- ADR-0013: AISME Phase 5 — Predictive Coding Narrative Self
- ADR-0014: AISME Phase 6 — Consciousness Continuity Metr...
- ADR-0015: AISME Phase 7 — Synaptic Relay Wiring & Pathw...
- ADR-0016: AISME Phase 8 — Closed-Loop Epistemic Learning
- ADR-0017: AISME Phase 9 — Generative Counterfactuals & ...
- ADR-0018: AISME Phase 10 — WanderPathway & Kernel Conti...
- ADR-0019: AISME Phase 11 — Expected Free Energy Policy ...
- ADR-0020: AISME Phase 12 — Continuous Self-Dynamics
- ADR-0023: AISME Complete Loop Closure & CognitiveVector...
- ADR-0024: Polymorphic SoulContext Hierarchy in AISME
- ADR-0027: Soul-Conditioned & Salience-Modulated Persona...
- ADR-0048: Cross-Capture Graph & CoActivation Kernel
- ADR-0049: Identity Trajectory Lyapunov Stability
- ADR-0050: Event Density Gating and Dynamic Epistemic Co...
- ADR-0051: Bayesian Online Change-Point Episode Segmenta...
- ADR-0052: Differential Privacy and Edge Anonymization
- ADR-0053: Multimodal Composite Importance Scoring
- ADR-0054: Lifespan-Adaptive Forgetting & Retention Kernel
- ADR-0055: LSR & RFF Dense Associative Memory Engineerin...
- ADR-0056: Log-Sum-ReLU (LSR) & Random Fourier Features ...
- ADR-0058: Linguistic & Vocal Prosody Expression Engine
- ADR-0063: Spacetime Vector Search and Synaptic Relay Architecture
- ADR-0064: Spacetime Simulation on Wander, Dream, and Express Pathways
- ADR-0071: Remember Cognitive Pathway Architecture
- ADR-0072: Six-Phase Fused Cognitive Scoring Pipeline
- ADR-0073: Recall Cognitive Pathway and Multi-Phase Retrieval Architecture
- ADR-0074: Reflect Cognitive Pathway and Sleep Consolidation Architecture
- ADR-0078: Salience Network and Thalamic Cognitive Profiles Architecture
-
Platform, Synapse & Clustering
- ADR-0021: Nucleus Symmetric Hardware Abstraction Layer ...
- ADR-0022: Embodied Kinesics & Phenomenological MCP Engine
- ADR-0025: Declarative MCP Tool Definitions via JSON Sch...
- ADR-0026: Dual-Plane Concurrency & Async Queue Backpres...
- ADR-0028: Dual-Plane Memory Audit Architecture (Separat...
- ADR-0029: Episodic→Semantic Lineage Provenance Region
- ADR-0030: Unified Engram Encoding Header Architecture
- ADR-0031: Unified Configuration Architecture & Bypass E...
- ADR-0032: Persona Enactment — Soul as Policy over Memory
- ADR-0033: Decoupling Cognitive & Mathematical Kernels t...
- ADR-0034: Cell Topology, Namespace Ownership, and HA Cl...
- ADR-0035: Cognitive Pathway Framework Rearchitecture
- ADR-0036: Pathway Error Handling, Isolation, and Circui...
- ADR-0037: Ingestion Boundary and Sensory Relocation
- ADR-0038: SIMD-Accelerated BM25 Lexical Scoring Optimiz...
- ADR-0039: Robust Unified Rate Limiting Architecture
- ADR-0040: Universal Apache Camel Messaging Channels
- ADR-0041: Unified Connector Architecture for Ingestion
- ADR-0059: Java 27 Upgrade Strategy and Value Class Migration
- ADR-0060: Cognitive Continuity Layer and Decoded Mind Streams
- ADR-0061: In-Memory Multi-Tenant Quartz Scheduler
- ADR-0065: Client SDK Architecture, OpenAPI, and MCP Integration
- ADR-0066: Engine & CLI Stabilization — Issue #727 Hardening
- ADR-0067: Cell-Based High Availability and Namespace-Sticky Sharding
- ADR-0068: Phileas PII Redaction Engine for Spector Synapse
- ADR-0069: Synapse-Owned Tool Access Policy
- ADR-0070: Unified Error Taxonomy and Exception Handling Architecture
- ADR-0075: Extensible LLM and Multimodal Embedding Provider SPI
- ADR-0076: Zero-Dependency Pluggable Cache Abstraction
- ADR-0077: Model B Asynchronous Task Queue and Concurrency
- ADR-0079: Asynchronous Memory Event and Telemetry Notification Bus
- ADR-0080: Observed Memory and Pathway Metrics Telemetry Architecture
- ADR-0081: Dedicated Reactive Ingress and In-Process Path Router
- ADR-0083: Namespace-Isolated Memory Analytics & Telemetry
- ADR-0084: Dual-Plane Conversation Persistence
- ADR-0085: Dynamic Synapse Configuration Overrides and Runtime Propagation
-
Modules Registry
- Overview
- Foundation Layer (/nucleus)
- Cognitive Layer (/memory)
- Gateway Layer (/synapse)
- Benchmarks & UI
- Deep Dives
-
Community
- Governance
- Contributing
- FAQ
- Glossary
- Roadmap
- 🔬 Labs
- Third-Party Legal