ai: migrate LLM backbone from Kimi CLI to Codex CLI
Retires the Moonshot/Kimi subscription in favour of the already-paid ChatGPT plan. Both CLI wrappers now run `codex exec`; the kimi-agent container is gone. adolf-llm + hindsight-llm: - runKimi -> runCodex (`codex exec --json --skip-git-repo-check`), resume via `codex exec resume <thread_id>`. - MCP moves from a per-session .mcp.json (a workaround for Kimi having no --mcp-config-file flag) to a $CODEX_HOME/config.toml generated once at startup from shared-mcp.json. Field translation is load-bearing: bearerTokenEnvVar -> bearer_token_env_var, enabledTools -> enabled_tools. - approval_policy="never" + sandbox_mode required, or unattended turns block on an approval prompt nobody can answer. kimi-agent removed. It was the ONLY large-tier deployment behind LiteLLM, so deleting it outright would have silently degraded every large-tier request to the local 4B model via the existing fallbacks. tier-large, the auto_router complex-reasoning route and their fallbacks now point at the codex-backed adolf-llm wrapper (model_name: codex-agent). Three environment blockers fixed along the way: - OpenAI geo-blocks this host (403 unsupported_country_region_territory). Both containers now egress via the host xray proxy, with NO_PROXY keeping MCP and *.alogins.net traffic off the tunnel. - node:22-slim ships no system CA store; the Rust codex binary validates TLS against it, so every HTTPS call failed with a generic transport error while Node's own fetch worked. ca-certificates added to both images. - `codex exec resume` rejects -C/--cd (plain `codex exec` accepts it), which broke follow-up turns while first turns succeeded. Known regression: Kimi's managed-usage API has no Codex equivalent, so the /usage route returns 501 and there is no quota probe for the codex model. The two quota plugins degrade quietly to no output. Also: stop tracking cognee.env (live LLM + JWT secrets) and gitignore it. The secrets remain in earlier history and should be rotated. Verified live: plain turn, SSE streaming, session resume, MCP tool call, bearer-token MCP call, and completions through both LiteLLM routes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Y5QPagv4iun1ghpwM96Ff
This commit is contained in:
62
ai/cognee-llm/README.md
Normal file
62
ai/cognee-llm/README.md
Normal file
@@ -0,0 +1,62 @@
|
||||
# cognee-llm (:8011)
|
||||
|
||||
> ⚠️ **SUPERSEDED — Adolf's memory is migrating Cognee → Hindsight (2026-07-13).**
|
||||
> Hindsight runs its LLM on LiteLLM `:4000` / Ollama, so this bespoke Kimi-CLI
|
||||
> wrapper is being **retired**, not ported (SPIKE gate 5 already concluded the
|
||||
> extraction workload shouldn't sit on the Kimi seat). This service is decommissioned
|
||||
> in migration task **H4**. Plan: `agap_git/adolf/HINDSIGHT-MIGRATION.md`. The doc
|
||||
> below describes the outgoing Cognee stack, kept until H4 lands.
|
||||
|
||||
OpenAI-compatible wrapper around the Kimi Code CLI (`@moonshot-ai/kimi-code`, home
|
||||
`/root/.kimi-code`), built for Cognee's batch/structured LLM calls. **Opposite policy to
|
||||
`kimi-agent`**:
|
||||
|
||||
- **Stateless one-shot** — fresh temp dir under `/workspace/<uuid>` per request, `kimi -p
|
||||
<prompt> --output-format stream-json`, **no `-r`/`-S` resume**, dir removed after every call
|
||||
(success or failure).
|
||||
- **Non-streaming** — always returns a full `chat.completion` body, even if the caller sets
|
||||
`stream: true`.
|
||||
- **No media, no MCP** — text-only prompt built from `messages`; no image persistence, no
|
||||
`.mcp.json`.
|
||||
- **Structured/low-temperature intent via prompt, not a sampling param** — the CLI has no raw
|
||||
temperature knob (it's an agent loop, not a completions API), so determinism/JSON-only output
|
||||
is enforced with an instruction preamble prepended to the caller's system prompt.
|
||||
- **Bounded concurrency** — `MAX_CONCURRENCY = 3` in `server.js`, queued beyond that.
|
||||
|
||||
Endpoints: `GET /v1/models` (model id `cognee-llm`), `POST /v1/chat/completions`.
|
||||
|
||||
Own disposable in-container `/workspace` (no host bind mount — nothing here is meant to
|
||||
survive a request, let alone a container restart) + own `cognee-llm-home` volume
|
||||
(`/root/.kimi-code`), same Kimi subscription as `kimi-agent`/`adolf-llm`, separate volume so
|
||||
each wrapper's CLI state stays isolated.
|
||||
|
||||
## This IS Cognee's LLM backbone
|
||||
|
||||
By design, Cognee's LLM runs on the flat Kimi subscription through this wrapper — the whole
|
||||
reason it exists — mirroring how `adolf-llm` backs the assistant. P4 wires cognee's
|
||||
`LLM_ENDPOINT` → `http://cognee-llm:8011`, `LLM_MODEL` → `openai/cognee-llm`.
|
||||
|
||||
**Accepted tradeoff (SPIKE-FINDINGS gate 5).** The CLI's JSON output is clean/schema-conformant,
|
||||
but it's slower than a raw API: ~5s fixed per-invocation floor + ~22-24s for a realistic
|
||||
structured-extraction call, and every call is agentic. Cognify issues one call per
|
||||
chunk/entity-extraction step, so large batches serialize into minutes. To protect the
|
||||
single-seat subscription, `MAX_CONCURRENCY = 3` bounds concurrent spawns.
|
||||
|
||||
**Documented fallback (not the default):** if cognify throughput ever becomes a real problem,
|
||||
route cognee's LLM to a LiteLLM model instead (`ARCHITECTURE.md` §3.3) — see the commented block
|
||||
in `cognee/cognee.env`. Embeddings already run on LiteLLM's `nomic-embed` regardless (embeddings
|
||||
can't go through the agentic CLI).
|
||||
|
||||
## Smoke test
|
||||
|
||||
```bash
|
||||
cd /home/alvis/agap_git/ai
|
||||
docker build -t cognee-llm:local ./cognee-llm
|
||||
docker run --rm -d --name cognee-llm-smoke -p 18011:8011 cognee-llm:local
|
||||
curl -s http://localhost:18011/v1/models
|
||||
docker rm -f cognee-llm-smoke
|
||||
```
|
||||
|
||||
A full `/v1/chat/completions` round-trip needs a `kimi login`-authed
|
||||
`/root/.kimi-code` volume (shared Kimi subscription) — not present in a bare smoke container,
|
||||
so that step is deferred to integration/P4 wiring.
|
||||
Reference in New Issue
Block a user