ruvnet--ruflo
23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
182 行
7.0 KiB
Markdown
182 行
7.0 KiB
Markdown
# ruflo-iot-cognitum
|
||
|
||
IoT device lifecycle, telemetry anomaly detection, fleet management, and witness chain verification for Cognitum Seed hardware.
|
||
|
||
## Hardware
|
||
|
||
This plugin requires a **Cognitum Seed** device. Get one at **https://cognitum.one** — the Seed is an edge appliance with on-device vector store, Ed25519 identity, OTA firmware, mesh networking, and a witness chain. Default address when attached via USB-C is `http://169.254.42.1` (link-local, no auth) or `https://169.254.42.1:8443` (LAN, bearer auth required for state-mutating operations).
|
||
|
||
## Overview
|
||
|
||
Treats every Cognitum Seed device as a Ruflo agent with hardware capabilities. Devices progress through a 5-tier trust model, emit telemetry vectors for anomaly detection, participate in mesh networks, and maintain Ed25519 witness chains for provenance.
|
||
|
||
Backed by `@claude-flow/plugin-iot-cognitum` (239 tests, 39 source files).
|
||
|
||
## Installation
|
||
|
||
```bash
|
||
claude --plugin-dir plugins/ruflo-iot-cognitum
|
||
```
|
||
|
||
## Agents
|
||
|
||
| Agent | Model | Role |
|
||
|-------|-------|------|
|
||
| `device-coordinator` | sonnet | Device lifecycle, 5-tier trust scoring, mesh coordination |
|
||
| `telemetry-analyzer` | sonnet | Z-score anomaly detection, SONA learning, AgentDB persistence |
|
||
| `fleet-manager` | sonnet | Fleet CRUD, firmware rollout state machine, fleet policies |
|
||
| `witness-auditor` | haiku | Witness chain epoch verification, gap detection |
|
||
|
||
## Skills
|
||
|
||
| Skill | Usage | Description |
|
||
|-------|-------|-------------|
|
||
| `iot-register` | `/iot-register <endpoint>` | Register a Seed device |
|
||
| `iot-fleet` | `/iot-fleet <create\|list\|add\|remove\|delete>` | Fleet management |
|
||
| `iot-anomalies` | `/iot-anomalies <device-id>` | Detect telemetry anomalies |
|
||
| `iot-firmware` | `/iot-firmware <deploy\|advance\|rollback\|status\|list>` | Firmware rollouts |
|
||
| `iot-witness-verify` | `/iot-witness-verify <device-id>` | Verify witness chain integrity |
|
||
|
||
## Commands (25 subcommands)
|
||
|
||
```bash
|
||
# Device lifecycle
|
||
# `endpoint` defaults to http://169.254.42.1/ (the Seed link-local USB Ethernet address)
|
||
iot register [endpoint] [--token TOKEN]
|
||
iot list
|
||
iot status <device-id>
|
||
iot pair <device-id>
|
||
iot unpair <device-id>
|
||
iot remove <device-id>
|
||
|
||
# Telemetry
|
||
iot ingest <device-id>
|
||
iot baseline <device-id> [--compute]
|
||
iot anomalies <device-id>
|
||
iot query <device-id> --vector "[1,2,3]" --k 10
|
||
|
||
# Fleet management
|
||
iot fleet create --name "my-fleet"
|
||
iot fleet list
|
||
iot fleet add <fleet-id> <device-id>
|
||
iot fleet remove <fleet-id> <device-id>
|
||
iot fleet delete <fleet-id>
|
||
|
||
# Firmware rollouts
|
||
iot firmware deploy <fleet-id> --version "2.0.0"
|
||
iot firmware advance <rollout-id>
|
||
iot firmware rollback <rollout-id>
|
||
iot firmware status <rollout-id>
|
||
iot firmware list
|
||
|
||
# Mesh & witness
|
||
iot mesh <device-id>
|
||
iot witness <device-id>
|
||
iot witness verify <device-id>
|
||
iot health <device-id>
|
||
iot trust <device-id>
|
||
```
|
||
|
||
## Trust Model (5 Tiers)
|
||
|
||
| Level | Name | Score Range | Capabilities |
|
||
|-------|------|-------------|-------------|
|
||
| 0 | UNKNOWN | 0.0–0.19 | Discovery only |
|
||
| 1 | REGISTERED | 0.2–0.39 | Status, identity queries |
|
||
| 2 | PROVISIONED | 0.4–0.59 | Telemetry ingest, vector store |
|
||
| 3 | CERTIFIED | 0.6–0.79 | Mesh participation, firmware deploy |
|
||
| 4 | FLEET_TRUSTED | 0.8–1.0 | Full fleet operations, witness signing |
|
||
|
||
**Trust Score Formula:**
|
||
```
|
||
0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
|
||
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation
|
||
```
|
||
|
||
## Anomaly Detection
|
||
|
||
Z-score composite scoring: `min(1, meanZ/3)`
|
||
|
||
| Type | Detection Rule | Typical Cause |
|
||
|------|---------------|---------------|
|
||
| spike | maxZ > 5 | Sudden sensor failure |
|
||
| flatline | all zero + low Z | Sensor disconnected |
|
||
| drift | 1-2 dimensions high Z | Gradual calibration loss |
|
||
| oscillation | alternating high/low | Feedback loop |
|
||
| pattern-break | moderate Z, multiple dims | Environmental change |
|
||
| cluster-outlier | >50% dimensions high Z | Multi-sensor failure |
|
||
|
||
## Firmware Rollout State Machine
|
||
|
||
```
|
||
pending → canary → rolling → complete
|
||
↘ rolled-back ↙
|
||
```
|
||
|
||
- **canary**: Deploy to `ceil(deviceCount × canaryPercentage/100)` devices
|
||
- **rolling**: If canary anomaly score < rollback threshold, deploy to remaining
|
||
- **rolled-back**: Force rollback triggered by anomaly threshold breach
|
||
|
||
## Background Workers
|
||
|
||
| Worker | Interval | Event |
|
||
|--------|----------|-------|
|
||
| HealthProbeWorker | 30s | `iot:device-offline` |
|
||
| TelemetryIngestWorker | 60s | — |
|
||
| AnomalyScanWorker | 120s | `iot:anomaly-detected` |
|
||
| MeshSyncWorker | 120s | `iot:mesh-partition` |
|
||
| FirmwareWatchWorker | 300s | `iot:firmware-mismatch` |
|
||
| WitnessAuditWorker | 600s | `iot:witness-gap` |
|
||
|
||
## Integrations
|
||
|
||
- **AgentDB HNSW**: Telemetry vectors stored in `iot-telemetry` namespace with HNSW indexing (M=16, efConstruction=200)
|
||
- **SONA Neural**: Anomaly patterns fed to SONA for cross-device correlation and predictive maintenance
|
||
- **Cognitum SDK**: `@cognitum-one/sdk/seed` SeedClient with 12 typed endpoints
|
||
|
||
## Compatibility
|
||
|
||
- **CLI:** pinned to `@claude-flow/cli` v3.6 major+minor.
|
||
- **Hardware:** requires Cognitum Seed device. SDK: `@cognitum-one/sdk/seed`.
|
||
- **Verification:** `bash plugins/ruflo-iot-cognitum/scripts/smoke.sh` is the contract.
|
||
|
||
## Namespace coordination
|
||
|
||
This plugin owns five AgentDB namespaces, all compliant with the [ruflo-agentdb ADR-0001 §"Namespace convention"](../ruflo-agentdb/docs/adrs/0001-agentdb-optimization.md) (`<plugin-stem>-<intent>` kebab-case):
|
||
|
||
| Namespace | Purpose |
|
||
|-----------|---------|
|
||
| `iot-devices` | Device trust history per Cognitum Seed |
|
||
| `iot-telemetry` | Telemetry vectors (HNSW: M=16, efConstruction=200) |
|
||
| `iot-telemetry-anomalies` | Detected anomalies tagged by type + remedial action |
|
||
| `iot-anomalies` | Skill-level anomaly index (alias of above) |
|
||
| `iot-audit` | Witness-chain gap records |
|
||
|
||
Reserved namespaces (`pattern`, `claude-memories`, `default`) MUST NOT be shadowed.
|
||
|
||
## Trust model parallel with federation
|
||
|
||
This plugin's 5-tier device trust model (UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED) follows the same shape as the [ruflo-federation 5-tier trust model](../ruflo-federation/docs/adrs/0001-federation-contract.md) (UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED). Different surface (IoT devices vs federation peers) and distinct naming, but the score-driven progression and capability-gating principle are the same.
|
||
|
||
## Verification
|
||
|
||
```bash
|
||
bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
|
||
# Expected: "12 passed, 0 failed"
|
||
```
|
||
|
||
## Architecture Decisions
|
||
|
||
- [`ADR-0001` — ruflo-iot-cognitum plugin contract (compliant namespaces, 5-tier trust parallel, 6 background workers, smoke as contract)](./docs/adrs/0001-iot-cognitum-contract.md)
|
||
|
||
## Related Plugins
|
||
|
||
- `ruflo-agentdb` — HNSW-indexed telemetry storage backend; namespace convention owner
|
||
- `ruflo-federation` — 5-tier trust model parallel (different surface, distinct naming, same shape)
|
||
- `ruflo-intelligence` — SONA neural pattern learning
|
||
- `ruflo-observability` — Telemetry correlation and tracing
|
||
|
||
## License
|
||
|
||
MIT
|