// dark open-source factory · ai governance layer
DARK FACTORY MCP GOVERNED LIGHTS-OUT OPS
Governance Controls
Topology = Governance
Draw links → tools generated
auto-enforced
Credential Scoping
AI never sees raw passwords
{variable} resolved
Write-Access Gating
Per-service boolean flags
read-only default
Tool Boundaries
Typed params, no kubectl
scoped per link
Multi-Stack Isolation
Per-stack MCP + credentials
is_external boundary
Security Model
SOPS Encrypted Secrets
cloud.env → K8s Secret
APISIX Gateway Auth
key-auth + TLS termination
MCP Bearer Token
Authorization: Bearer <key>
Audit Trail
JSON-RPC method + params + ts
AI Governance Flow
AI Capabilities
Q
Topology Query 7 tools
M
Prometheus 7 tools
G
Grafana 6 tools
L
Loki Logs 5 tools
D
Databases 15+ tools
A
ArgoCD 6 tools
P
AI Playbooks 6 prompts
query_topology run_test prom_query loki_query ch_query cnpg_query
Metadata Feed
{namespace} {password} {database} {host} {port}
Stack Awareness
T
Components + Links
S
Sub-components
A
Attributes + Config
X
Cross-stack Boundaries