Metadata-Version: 2.4
Name: reliamesh-server
Version: 0.2.0
Summary: Privacy-first reliability infrastructure for AI agents
Author: Prefiler Labs Private Limited
License-Expression: Apache-2.0
Project-URL: Homepage, https://reliamesh.com
Project-URL: Repository, https://github.com/PrefilerLabs/reliamesh
Project-URL: Issues, https://github.com/PrefilerLabs/reliamesh/issues
Project-URL: Documentation, https://github.com/PrefilerLabs/reliamesh#readme
Requires-Python: >=3.12
Description-Content-Type: text/markdown
License-File: LICENSE
License-File: NOTICE
Requires-Dist: fastapi<1,>=0.115
Requires-Dist: uvicorn<1,>=0.34
Requires-Dist: pydantic<3,>=2.10
Provides-Extra: gcp
Requires-Dist: google-cloud-firestore<3,>=2.20; extra == "gcp"
Provides-Extra: attest
Requires-Dist: cryptography<51,>=50.0.1; extra == "attest"
Provides-Extra: dev
Requires-Dist: pytest<10,>=8; extra == "dev"
Requires-Dist: httpx<1,>=0.28; extra == "dev"
Requires-Dist: ruff<1,>=0.11; extra == "dev"
Requires-Dist: pip-audit<3,>=2.9; extra == "dev"
Requires-Dist: pip-licenses<6,>=5; extra == "dev"
Requires-Dist: build<2,>=1.2; extra == "dev"
Dynamic: license-file

# ReliaMesh

**Open-source reliability infrastructure for AI agents.**

ReliaMesh ingests structured outcomes, detects reliability deterioration, and
tracks recovery without collecting prompts, model responses, or tool content.
An API returning HTTP 200 does not establish that an agent completed its task.

Copyright 2026 **Prefiler Labs Private Limited**. [Apache-2.0](https://github.com/PrefilerLabs/reliamesh/blob/main/LICENSE).

Canonical repository: [PrefilerLabs/reliamesh](https://github.com/PrefilerLabs/reliamesh).

[Technical dossier and verification](docs/grant-readiness.md) ·
[Solana evidence and current limits](docs/evidence/solana-devnet/README.md)

Managed endpoint: [api.reliamesh.com](https://api.reliamesh.com). Access is provisioned
by the operator; self-hosting needs no managed account.

## What works in 0.2.0

- A versioned, strict reliability-event contract and a Python SDK with no runtime
  dependencies. Explicit outcomes, failure taxonomy, counters, elapsed time,
  opaque version labels, and a whitelist OpenTelemetry attribute adapter.
- Authenticated tenant ingestion with scoped keys, rotation/revocation, bounded
  payloads, per-tenant quotas, duplicate detection, and tenant deletion.
- Deterministic detection of high failure rates, changes in failure rate,
  latency, token consumption, and retries; version-associated observations,
  failure fingerprints, and incident opening/recovery.
- SQLite self-hosting and a Firestore storage adapter for Cloud Run. No outbound
  telemetry from a SQLite self-hosted service.
- An optional, operator-triggered Solana Devnet report commitment and verifier,
  plus a read-only Solana RPC agent example. The API and SDK do not require a
  blockchain connection. [Attestation specification](docs/solana-attestation.md)
  and [agent example](docs/solana-agent-example.md).

This is an early release with bounded tenant-local analysis. It does not establish
root cause, infer correctness from model text, or claim calibrated false-positive
rates. Cross-organization network intelligence is disabled; there are no verified
cohort or adoption claims. See [detection behavior](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/detection.md) and
[operating limits](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/architecture.md).

## Run locally

Python 3.12 or later is required. Create and activate a virtual environment using
your platform's standard commands. For a published release, install from PyPI:

```sh
python -m pip install reliamesh-server==0.2.0 reliamesh-sdk==0.2.0
```

For development, install from the source checkout instead:

```sh
python -m pip install -e . -e ./sdk/python
```

Then provision a local tenant and start the service:

```sh
reliamesh tenant create example --output .local/example.json
reliamesh serve
```

The server listens on `http://127.0.0.1:8080`. SQLite stores data at
`.local/reliamesh.db`. Tenant creation writes credentials to the requested file;
keep it private and outside version control. No cloud account is needed.
The provisioning key has ingest/read/manage scopes; create a key limited to
`ingest` for application deployments.

Docker alternative:

```sh
docker compose up --build -d --wait
docker compose exec api reliamesh tenant create example --output /data/example.json
docker compose cp api:/data/example.json .local/example.json
```

Create `.local` before copying the credentials. The API binds only to loopback,
uses a persistent volume and runs as an unprivileged user. Install the local SDK
to run the example against this service. Back up the volume before upgrades.

In a second terminal in the same environment, run the example from a source
checkout or the server source archive:

```sh
python examples/synthetic_regression.py --endpoint http://127.0.0.1:8080 --credentials .local/example.json
```

The example sends 50 successful baseline observations, induces 50 malformed-output
failures, checks that a regression incident actually opens, then sends 100 healthy
observations and verifies recovery. Every observation and incident is labeled
synthetic. It uses a new deployment ID per run; use a disposable tenant because
each tenant supports 16 active streams. This is a functional exercise, not
evidence about any real provider or customer.

## Integrate

```python
import os
from reliamesh_sdk import Client, event

client = Client(
    endpoint=os.environ["RELIAMESH_ENDPOINT"],
    api_key=os.environ["RELIAMESH_API_KEY"],
)
client.emit(event(
    deployment_id="prod-eu1", agent_id="order-agent",
    operation="validation", outcome="failure", failure_type="malformed_output",
    model="model-alias", prompt_version="release-7", latency_ms=210,
))
client.flush()
```

`emit` only queues an event. `flush` is synchronous, bounded best-effort delivery;
run it on a worker in async or latency-sensitive applications. Watch
`client.counters` for drops. The SDK never chooses a cloud endpoint or exports
silently. Use opaque identifiers; schema validation cannot detect secrets hidden
inside otherwise valid labels. [SDK usage and delivery contract](https://github.com/PrefilerLabs/reliamesh/blob/main/sdk/python/README.md).

## Inspect and operate

Authenticated `GET /v1/summary` returns window statistics and version metadata;
`GET /v1/incidents` returns incident history. The SDK exposes both methods.
`/openapi.json` describes the HTTP API. `/health` is public liveness;
authenticated `/ready` checks storage availability.

For self-hosting, serve behind HTTPS before allowing remote clients. Application
configuration is explicit: `RM_STORE=sqlite` or `firestore`, `RM_SQLITE_PATH`, and
`RM_DAILY_EVENTS` (default 10,000 per tenant per UTC day). Cloud storage is restricted
to `RM_GCP_PROJECT=reliamesh`. Remote tenant provisioning is disabled unless an
operator sets `RM_ADMIN_HASH`. The local CLI can provision tenants without a remote
admin endpoint.

For SQLite, run `reliamesh purge` on a schedule to physically remove expired operational state.
Reads suppress expired observations after seven days. Active tenant credentials
persist until revoked or deleted. Backups require a separate operator retention
policy. Firestore requires its TTL policy for unattended physical cleanup;
see [storage operations](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/storage.md) and [privacy and retention](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/privacy.md).

`reliamesh backup --output .local/backup.db` uses SQLite's consistent backup API
and refuses to overwrite an existing file. Backups contain private tenant data
and key digests. To verify a restore, stop the destination service, place the backup
at a new private path, set `RM_SQLITE_PATH` to that path, start the service, and
compare authenticated summaries before routing traffic. Review deleted tenants
and revoked keys before any production restore.

## Documentation and development

- [Architecture and limits](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/architecture.md)
- [Managed deployment](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/deployment.md), [operations](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/operations.md), and [cost controls](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/cost-controls.md)
- [Protocol](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/protocol.md) and [detection](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/detection.md)
- [Privacy](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/privacy.md) and [threat model](https://github.com/PrefilerLabs/reliamesh/blob/main/docs/threat-model.md)
- [Security reporting](https://github.com/PrefilerLabs/reliamesh/blob/main/SECURITY.md), [contributing](https://github.com/PrefilerLabs/reliamesh/blob/main/CONTRIBUTING.md), and [changelog](https://github.com/PrefilerLabs/reliamesh/blob/main/CHANGELOG.md)

```sh
python -m pip install -e ".[dev]" -e ./sdk/python
python -m pytest
python -m ruff check .
```

No payments, blockchain, generative-model dependency, or proprietary hosted
dependency is required for the core reliability path.
