Skip to content
Merged
Show file tree
Hide file tree
Changes from 69 commits
Commits
Show all changes
97 commits
Select commit Hold shift + click to select a range
1d2d788
group canonicalization to avoid collisions, security config, integrat…
phact May 14, 2026
cb8f8d5
style: ruff format (auto)
autofix-ci[bot] May 14, 2026
9208dd9
centralize jwt construction path, fix webhook bug
phact May 14, 2026
9ad1d62
bug fixes
phact May 14, 2026
95c62fc
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 14, 2026
c32061f
style: ruff format (auto)
autofix-ci[bot] May 14, 2026
33b36f2
pr feedback
phact May 14, 2026
cc73b3f
merge
phact May 14, 2026
5e22f99
style: ruff format (auto)
autofix-ci[bot] May 14, 2026
66085ae
missing etst
phact May 15, 2026
2072ae9
remove doc loading from playwright e2e test, add new integration test…
phact May 15, 2026
fcf4275
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 15, 2026
187a2c1
Merge branch 'main' into group-dls-part-2
phact May 15, 2026
1182c2e
style: ruff format (auto)
autofix-ci[bot] May 15, 2026
a837a1a
lint, mypy fixes
phact May 15, 2026
c82fd82
Fix integration test startup lifecycle
phact May 15, 2026
7b7bd2c
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 15, 2026
bb56cd9
Fix onboarding integration and e2e flakes
phact May 15, 2026
c93b748
Merge branch 'main' into group-dls-part-2
phact May 15, 2026
357c3fd
new shape, dls principals backed by OS principals index
phact May 18, 2026
2eadaa7
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 18, 2026
b3c847c
Merge branch 'main' into group-dls-part-2
phact May 18, 2026
72178e7
fix so ibm does index refresh
phact May 18, 2026
a24630b
principal per user refresh ttl for check and index update
phact May 18, 2026
a5ff895
Fix DLS ingestion mapping client
phact May 18, 2026
1268f3d
style: ruff format (auto)
autofix-ci[bot] May 18, 2026
cdc4775
Fix DLS writes in ingestion paths
phact May 18, 2026
048d77c
Repair roleless users during sign-in
phact May 18, 2026
58cc54f
Fix integration reload isolation
phact May 18, 2026
a1a9496
Fix Langflow DLS ingestion preflight
phact May 19, 2026
a018e21
Merge branch 'main' into group-dls-part-2
phact May 19, 2026
06e62df
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 19, 2026
8ea07e6
style: ruff format (auto)
autofix-ci[bot] May 19, 2026
01618e5
Avoid delete by query under DLS
phact May 19, 2026
86c58b0
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 19, 2026
2f0806d
Avoid bulk writes under DLS
phact May 19, 2026
9d3159e
Merge branch 'main' into group-dls-part-2
phact May 19, 2026
38417ee
Stabilize onboarding e2e waits
phact May 19, 2026
26f599d
pre merge
phact May 19, 2026
1357db6
Merge branch 'main' into group-dls-part-2
phact May 19, 2026
4d4b251
Merge branch 'main' into group-dls-part-2
phact May 19, 2026
ba5ac9c
mypy fix
phact May 19, 2026
6a5f37f
OR does the ingest instead of langflow
phact May 20, 2026
1e6e11c
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 20, 2026
7b0b64c
use gvpassthrough
phact May 20, 2026
1c9c9bb
Fix Langflow ingest callback globals
phact May 20, 2026
92f183c
Merge branch 'main' into group-dls-part-2
phact May 20, 2026
37f5753
Wire Langflow ingest callback globals through flow
phact May 20, 2026
154f500
Fix Langflow ingest callback globals
phact May 20, 2026
5578777
Fix Langflow response fallback and env globals
phact May 20, 2026
a87179d
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 21, 2026
73cd61f
Merge branch 'main' into group-dls-part-2
phact May 21, 2026
d29a87c
fix nudges
phact May 21, 2026
071c094
Fix OpenSearch search results table output
phact May 21, 2026
130a4d2
Restore sample docs Langflow indexing coverage
phact May 21, 2026
804e4f2
Use real default docs in onboarding sample test
phact May 21, 2026
f766a27
style: ruff autofix (auto)
autofix-ci[bot] May 21, 2026
3065373
Re-enable sample data ingest in e2e
phact May 21, 2026
052e919
Fix Langflow ingest callback token handling
phact May 21, 2026
6c5d77f
Fix Langflow callback ids and chat sources
phact May 22, 2026
920f1c3
skip source extraction integration test
phact May 22, 2026
f894693
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 22, 2026
3bbb95b
get rid of per request opensearch jwts
phact May 22, 2026
9f7317a
style: ruff autofix (auto)
autofix-ci[bot] May 22, 2026
337b4ea
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 22, 2026
176a395
Use keyed hashes for API keys
phact May 22, 2026
b910187
Fix OpenSearch JWT propagation
phact May 22, 2026
f6e0217
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 22, 2026
1dd9034
style: ruff autofix (auto)
autofix-ci[bot] May 22, 2026
9e78beb
Merge branch 'main' into group-dls-part-2
phact May 22, 2026
2bb3378
Fix operator env example merge markers
phact May 22, 2026
7697b09
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 26, 2026
ea33fb2
Merge branch 'main' into group-dls-part-2
phact May 26, 2026
ea4f1d0
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 26, 2026
1096d07
Add 'openrag' auth mode and ingest fields (#1683)
edwinjosechittilappilly May 26, 2026
573dd4c
Add OpenRAG ingest debug logging and token masking (#1684)
edwinjosechittilappilly May 26, 2026
5761789
readable principal names
phact May 28, 2026
42620c4
merge
phact May 28, 2026
49911db
Merge remote-tracking branch 'origin/main' into group-dls-part-2
phact May 28, 2026
589fae6
style: ruff autofix (auto)
autofix-ci[bot] May 28, 2026
dbc5ae4
Merge branch 'main' into group-dls-part-2
edwinjosechittilappilly May 29, 2026
cb7a00a
lint fix
edwinjosechittilappilly May 29, 2026
f5c748e
style: ruff autofix (auto)
autofix-ci[bot] May 29, 2026
2e27ce0
lint fix
edwinjosechittilappilly May 29, 2026
541289c
Merge branch 'group-dls-part-2' of https://github.com/langflow-ai/ope…
edwinjosechittilappilly May 29, 2026
e5c5e01
style: ruff autofix (auto)
autofix-ci[bot] May 29, 2026
5dd777e
Add typing annotations to services and settings
edwinjosechittilappilly May 29, 2026
1b12995
Merge branch 'group-dls-part-2' of https://github.com/langflow-ai/ope…
edwinjosechittilappilly May 29, 2026
2d19a69
lint fix
edwinjosechittilappilly May 29, 2026
203cb43
style: ruff autofix (auto)
autofix-ci[bot] May 29, 2026
44a181f
lint fix
edwinjosechittilappilly May 29, 2026
3411967
strip issue regression
phact May 29, 2026
f2a2740
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 29, 2026
5e71e04
style: ruff autofix (auto)
autofix-ci[bot] May 29, 2026
bc4a196
faster integration tests / better instrumentation
phact May 29, 2026
9b91776
Merge branch 'group-dls-part-2' of github.com:langflow-ai/openrag int…
phact May 29, 2026
93a0b59
Add split integration suite runner
phact May 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,10 @@ FETCH_OPENRAG_DOCS_AT_STARTUP=false
# Default: 3600 seconds (60 minutes) total timeout
# INGESTION_TIMEOUT=3600

# OPTIONAL: OpenSearch JWT TTL for per-user document security tokens (in seconds)
# Default: INGESTION_TIMEOUT + 300 seconds
# OPENRAG_OPENSEARCH_JWT_TTL=3900

# OPTIONAL: Maximum number of files to upload / ingest (in batch) per task when adding knowledge via folder
# Default: 25
# UPLOAD_BATCH_SIZE=25
Expand Down
4 changes: 2 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,12 +44,12 @@ Read the `SKILL.md` files directly. The frontmatter `description` tells you when

**RBAC is opt-in.** `OPENRAG_RBAC_ENFORCE` defaults to `false`, which makes OpenRAG behave like the pre-RBAC release: every authenticated user has full access; API-key role overrides are also bypassed. To turn the permissions system on (admin/developer/user/viewer roles, `require_permission` gates, audit denials), set `OPENRAG_RBAC_ENFORCE=true`. Available in all `OPENRAG_RUN_MODE` values — operators own the trade-off. The startup event logs the enforcement state on every boot.

**Dev-local with backend on host.** When you run `make dev-local-cpu` (or `dev-local`) and then `make backend` on the host, OpenSearch needs to resolve `openrag-backend` to the host machine so it can fetch JWKS for OIDC validation. The base `docker-compose.yml` does NOT add this alias — it would break CI, where the backend is a docker-compose service. To enable the host-backend mode, layer the override file:
**Dev-local with backend on host.** When you run `make dev-local-cpu` (or `dev-local`) and then `make backend` on the host, OpenSearch needs to resolve `openrag-backend` to the host machine so it can fetch JWKS for OIDC validation. Langflow also needs that name for backend ingest callbacks. The base `docker-compose.yml` does NOT add this alias — it would break CI, where the backend is a docker-compose service. To enable the host-backend mode, layer the override file:

```bash
docker compose -f docker-compose.yml -f docker-compose.host-backend.yml up -d opensearch dashboards langflow
make backend # in another terminal
make frontend # in another terminal
```

The override only adds `extra_hosts: openrag-backend:host-gateway` to the OpenSearch service. Without it, OIDC works because docker DNS routes `openrag-backend` to the in-compose backend container.
The override only adds `extra_hosts: openrag-backend:host-gateway` to the OpenSearch and Langflow services. Without it, OIDC and ingest callbacks work because docker DNS routes `openrag-backend` to the in-compose backend container.
2 changes: 2 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -871,6 +871,7 @@ test-ci: ensure-langflow-data ensure-backend-volumes ## Start infra, run integra
GOOGLE_OAUTH_CLIENT_ID="" \
GOOGLE_OAUTH_CLIENT_SECRET="" \
OPENSEARCH_HOST=localhost OPENSEARCH_PORT=9200 \
LANGFLOW_OPENSEARCH_HOST=opensearch LANGFLOW_OPENSEARCH_PORT=9200 \
OPENSEARCH_USERNAME=admin OPENSEARCH_PASSWORD=$${OPENSEARCH_PASSWORD} \
DISABLE_STARTUP_INGEST=$${DISABLE_STARTUP_INGEST:-true} \
uv run pytest tests/integration/core -vv -s -o log_cli=true --log-cli-level=DEBUG; \
Expand Down Expand Up @@ -995,6 +996,7 @@ test-ci-local: ensure-langflow-data ensure-backend-volumes ## Same as test-ci bu
GOOGLE_OAUTH_CLIENT_ID="" \
GOOGLE_OAUTH_CLIENT_SECRET="" \
OPENSEARCH_HOST=localhost OPENSEARCH_PORT=9200 \
LANGFLOW_OPENSEARCH_HOST=opensearch LANGFLOW_OPENSEARCH_PORT=9200 \
OPENSEARCH_USERNAME=admin OPENSEARCH_PASSWORD=$${OPENSEARCH_PASSWORD} \
DISABLE_STARTUP_INGEST=$${DISABLE_STARTUP_INGEST:-true} \
uv run pytest tests/integration/core -vv -s -o log_cli=true --log-cli-level=DEBUG; \
Expand Down
41 changes: 15 additions & 26 deletions cloud_securityconfig/roles.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,55 +3,44 @@ _meta:
config_version: 2

openrag_user_role:
description: "DLS: user can read/write docs they own or are allowed on"
description: "DLS: user can read docs they own or are allowed on"
cluster_permissions:
- "indices:data/write/bulk"
- "indices:data/write/index"
- "indices:data/read/scroll"
- "indices:data/read/scroll/clear"
- "cluster:monitor/*"
- "cluster:admin/opensearch/notifications/configs/create"
- "cluster:admin/opensearch/notifications/configs/list"
- "cluster:admin/opensearch/notifications/configs/get"
- "cluster:admin/opensearch/notifications/configs/update"
- "cluster:admin/opensearch/notifications/configs/delete"
- "cluster:admin/opensearch/alerting/*"

index_permissions:
- index_patterns: ["documents", "documents*", "knowledge_filters", "knowledge_filters*", "orag-*",orag*]
- index_patterns: ["documents", "documents*", "knowledge_filters", "knowledge_filters*", "orag-*", "orag*"]
allowed_actions:
- crud
- create_index
- read
- indices:admin/mappings/get
- indices:admin/mappings/put
- indices:admin/exists
- indices:admin/get
- indices:admin/refresh
- indices:data/write/delete/byquery
- indices:data/write/update/byquery
dls: >
{"bool":{"should":[
{"term":{"owner":"${user.name}"}},
{"term":{"owner":"${attr.jwt.email}"}},
{"term":{"allowed_users":"${user.name}"}},
{"term":{"allowed_users":"${attr.jwt.email}"}},
{"terms":{"allowed_principals":{"index":"openrag_dls_principals","id":"${user.name}","path":"principals"}}},
{"bool":{"must_not":{"exists":{"field":"owner"}}}}
],"minimum_should_match":1}}
- index_patterns: ["openrag_dls_principals", "openrag_dls_principals*"]
allowed_actions:
- read
- indices:admin/exists
- indices:data/read/get
- indices:data/read/search
dls: >
{"term":{"user_name":"${user.name}"}}
- index_patterns: ["api_keys", "api_keys*"]
allowed_actions:
- crud
- create_index
- read
- indices:admin/mappings/get
- indices:admin/mappings/put
- indices:admin/exists
- indices:admin/get
- indices:admin/refresh
- indices:data/write/delete/byquery
- indices:data/write/update/byquery
dls: >
{"bool":{"should":[
{"term":{"user_id":"${user.name}"}},
{"bool":{"must_not":{"exists":{"field":"user_id"}}}}
],"minimum_should_match":1}}
- index_patterns: [".opendistro-alerting-config"]
allowed_actions:
- crud
- indices:admin/get
3 changes: 3 additions & 0 deletions docker-compose.host-backend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,3 +28,6 @@ services:
opensearch:
extra_hosts:
- "openrag-backend:host-gateway"
langflow:
extra_hosts:
- "openrag-backend:host-gateway"
10 changes: 8 additions & 2 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ services:
environment:
- OPENSEARCH_HOST=${OPENSEARCH_HOST:-opensearch}
- LANGFLOW_URL=http://langflow:7860
- OPENRAG_BACKEND_INTERNAL_URL=${OPENRAG_BACKEND_INTERNAL_URL:-http://openrag-backend:8000}
- LANGFLOW_PUBLIC_URL=${LANGFLOW_PUBLIC_URL}
- LANGFLOW_AUTO_LOGIN=${LANGFLOW_AUTO_LOGIN}
- LANGFLOW_SUPERUSER=${LANGFLOW_SUPERUSER}
Expand Down Expand Up @@ -101,7 +102,7 @@ services:
- LANGFLOW_VERSION=${LANGFLOW_VERSION}
- LOG_FORMAT=${LOG_FORMAT}
- SERVICE_NAME=${SERVICE_NAME}
- SESSION_SECRET=${SESSION_SECRET}
- SESSION_SECRET=${SESSION_SECRET:-your-secret-key-change-in-production}
- JWT_SIGNING_KEY=${JWT_SIGNING_KEY}
- OPENRAG_ENCRYPTION_KEY=${OPENRAG_ENCRYPTION_KEY}
- LOG_LEVEL=${LOG_LEVEL:-INFO}
Expand Down Expand Up @@ -180,7 +181,12 @@ services:
- SOURCE_URL=None
- ALLOWED_USERS=[]
- ALLOWED_GROUPS=[]
- ALLOWED_PRINCIPALS=[]
- OPENRAG-QUERY-FILTER="{}"
- OPENRAG_INGEST_URL=OPENRAG_INGEST_URL
- OPENRAG_INGEST_TOKEN=OPENRAG_INGEST_TOKEN
- OPENRAG_INGEST_RUN_ID=OPENRAG_INGEST_RUN_ID
- OPENRAG_INGEST_BATCH_SIZE=100
- OPENSEARCH_PASSWORD=${OPENSEARCH_PASSWORD}
- OPENSEARCH_HOST=${LANGFLOW_OPENSEARCH_HOST:-${OPENSEARCH_HOST:-opensearch}}
- OPENSEARCH_PORT=${LANGFLOW_OPENSEARCH_PORT:-${OPENSEARCH_PORT:-9200}}
Expand All @@ -192,7 +198,7 @@ services:
- MIMETYPE=None
- FILESIZE=0
- SELECTED_EMBEDDING_MODEL=${SELECTED_EMBEDDING_MODEL:-text-embedding-3-small}
- LANGFLOW_VARIABLES_TO_GET_FROM_ENVIRONMENT=JWT,OPENRAG-QUERY-FILTER,OPENSEARCH_PASSWORD,OPENSEARCH_URL,DOCLING_SERVE_URL,DOCLING_TASK_ID,OWNER,OWNER_NAME,OWNER_EMAIL,CONNECTOR_TYPE,DOCUMENT_ID,SOURCE_URL,ALLOWED_USERS,ALLOWED_GROUPS,FILENAME,MIMETYPE,FILESIZE,SELECTED_EMBEDDING_MODEL,OPENAI_API_KEY,ANTHROPIC_API_KEY,WATSONX_APIKEY,WATSONX_URL,WATSONX_PROJECT_ID,OLLAMA_BASE_URL,OPENSEARCH_INDEX_NAME
- LANGFLOW_VARIABLES_TO_GET_FROM_ENVIRONMENT=JWT,OPENRAG-QUERY-FILTER,OPENSEARCH_PASSWORD,OPENSEARCH_URL,DOCLING_SERVE_URL,DOCLING_TASK_ID,OWNER,OWNER_NAME,OWNER_EMAIL,CONNECTOR_TYPE,DOCUMENT_ID,SOURCE_URL,ALLOWED_USERS,ALLOWED_GROUPS,ALLOWED_PRINCIPALS,FILENAME,MIMETYPE,FILESIZE,SELECTED_EMBEDDING_MODEL,OPENAI_API_KEY,ANTHROPIC_API_KEY,WATSONX_APIKEY,WATSONX_URL,WATSONX_PROJECT_ID,OLLAMA_BASE_URL,OPENSEARCH_INDEX_NAME,OPENRAG_INGEST_URL,OPENRAG_INGEST_TOKEN,OPENRAG_INGEST_RUN_ID,OPENRAG_INGEST_BATCH_SIZE
- LANGFLOW_LOG_LEVEL=DEBUG
- LANGFLOW_WORKERS=${LANGFLOW_WORKERS:-1}
- LANGFLOW_AUTO_LOGIN=${LANGFLOW_AUTO_LOGIN}
Expand Down
Loading
Loading