Skip to content

Ecosystem

How our platforms fit together.
Every concernone tool.

RODMENA builds its products from small hosted services, each with one purpose, and a set of house libraries. Each concern belongs to one tool, each platform has its own team, and a shared mail bus connects them.

products, one in design
13
hosted platforms
8
libraries, engines and CLIs
8
shared mail bus
1

Design principles

  • One concern, one tool

    Authentication is Identity, authorisation is Auth, metering is TokenGate, email is Mail API, approvals are Futex, containers are RunFlow and agentic workflows are Highway. Products never re-implement a concern that a house tool already owns.

  • Teams coordinate by mail

    Every platform has its own agent, context and repository. Teams coordinate across platforms on the agent-mail bus. No team edits another team’s repository or files tickets in its tracker.

  • Databases spread across countries

    Each service has its own database, and the databases sit on different hosts in different countries. Applications can be redeployed and data cannot, so the two are kept apart. Every database is replicated to a third region and backed up off-site.

Where it runs

Hosts and regions

The managed fleet holds 22 production databases, each owned by one service, on 4 database hosts in 3 countries, and 4 more run on an application host. No two services share a schema, and no single machine holds the platform.

production databases, each owned by one service
22
database hosts
4
countries
3
minutes recovery point on the managed fleet, at most
≤5
  • UKUnited Kingdom

    Applications and two database hosts

    Hosts the application tier and the databases for the workflow engine, the approvals service, the message bus, email, the ledger and the task platform.

  • FRFrance

    Database host

    Holds the identity and access plane, authorisation, metering and the identity provider, kept apart from the services that depend on it.

  • DEGermany

    Replica set

    Holds a continuously updated copy of every database, outside the other two regions. It has no primary, so no traffic depends on it until it is promoted.

  • Continuous replication

    Every database streams block-level changes to a standby outside both primary regions. Replication is asynchronous, so a replica cannot slow or block the service in front of it.

  • Off-site backups

    Archives go continuously to object storage in a separate facility, encrypted before they leave the host and recoverable to any point within retention. Restores are tested end to end.

  • Three factors on every connection

    No database accepts a network connection on a password alone. Every connection needs encryption in transit, a client certificate issued by a private authority and a password. Each service is scoped to its own database.

  • Replicas and backups

    A mistaken statement reaches every replica within moments. Replicas protect against losing hardware, and the archive protects against losing data.

Verified 2026-10-05. Read the full topology

Topology

Platform map

The map has eight layers and one bus, and each concern appears once. Products sit at the top and the stack at the bottom. Everything a product needs is one hop away.

23 nodes · 27 documented relations · 1 assumed

01/PRODUCTS02/IDENTITY & ACCESS03/GOVERNANCE04/ORCHESTRATION & EXECUTION05/COMMUNICATION06/DATA & LIBRARIES07/DEV PROCESS08/STACK PREFERENCESAGENT-MAIL BUSreport · ack · fix-notice · verify-result · closeRED9Product · in designreTunnelProduct · betaLedgerProduct · free todayIdentityHosted serviceExternal IdPsGoogle · GitHub · AppleAuthHosted serviceTokenGateHosted serviceFutexHosted serviceHighwayHosted serviceRunFlowHosted servicestabilizeWorkflow engine · partialRODMENA Mail APIHosted servicedatashardPython librarymigrettiCLIsupervicePython librarybulkmanPython libraryresilient-circuitPython libraryscriptplanEngine + CLIissuedb-cli + EARSCLIPostgreSQLExternalRedisExternalPrismHosted service

Scroll the map sideways. Each node also has a card below.

Explore

Using the map

Select a node or the bus to highlight its relations and see what it owns, what it connects to and what it must never be replaced with. The cards below carry the same facts.

  • documented relation
  • assumed: confirm before relying on it
  • the agent-mail bus
  • a product (gradient border)

Not drawn, as they apply everywhere:

  • Every product authenticates with Identity and authorises with Auth.
  • Every platform team coordinates over the agent-mail bus.
  • Every repository is tracked in issuedb-cli, with EARS specs.

Layers

Tools by layer

What each tool owns, when to use it, and what it must never be replaced with.

01 Products

  • RED9

    Productin design

    Agent-workforce platform where each chat is a durable, autonomous task with an email address.

    Draws on the full stack: Identity and Auth for access, TokenGate for budgets, Mail API for task mailboxes, RunFlow for sandboxes, Highway as the durable executor, Futex for approvals and migretti for schema, on Python, PostgreSQL and Redis.

    authenticates with Identity · authorizes via Auth · meters budgets via TokenGate · task mailboxes via RODMENA Mail API · sandboxed execution on RunFlow · delegates workflows to Highway · human approvals via Futex · migrates schema with migretti · built on PostgreSQL · built on Redis · default models via Prism

  • reTunnel

    Productbeta

    Free, open-source unified ingress platform that exposes local servers behind NATs and firewalls to the public internet over secure tunnels.

    Standalone: an MIT-licensed Python client and CLI with a self-hostable server. It depends on no other house platform.

    CLIHTTP/TCP Visit

  • Ledger

    Productfree today

    Double-entry ledger for money, credits and stock. Entries are balanced, permanent and provable, and the database enforces the rules.

    Uses Auth for credentials, TokenGate for metering and migretti for schema, on Python and PostgreSQL. It was audited through four internal gates and adversarial re-audits, and the findings are published.

    Never replaced with: A secret that can mint a credential it would accept, or an edit or delete path on the journal.

    Not for: Quotas or metering (use TokenGate), non-conserved metrics or workflow state.

    REST /v1OpenAPI 3.1llms.txt Visit Documentation

02 Identity & Access

  • Identity

    Hosted serviceproduct

    OAuth provider handling login for people and services. Every product’s sign-in goes through Identity.

    Identity depends on no other house platform. Sign-in federates to public identity providers such as Google, GitHub and Apple.

    Not for: Permissions or roles, which belong to Auth. Identity handles authentication and Auth handles authorisation.

    federates sign-in to External IdPs

    OAuth2REST Visit Docs

  • External IdPs

    Google · GitHub · Apple

    Public identity providers, such as Google, GitHub and Apple, that Identity federates sign-in to. Identity has no other upstream.

  • Auth

    Hosted serviceproduct

    Hosted RBAC for roles, permissions, memberships and “can user X do Y” checks. Products define their roles in this service.

    Ships as the PyPI package “auth”.

    Never replaced with: Hand-rolled users/roles/permissions tables, Casbin, OPA, or an RBAC library.

    Not for: Login, sessions, passwords or JWT issuance. Authentication belongs to Identity.

    RESTPython Visit

03 Governance

  • TokenGate

    Hosted serviceproduct

    Counting, caps and rate limits per user, organisation or tenant: token budgets, usage ledgers, plan tiers, reserve/commit flows, and threshold and overage alerts.

    House rule: each cap is tested in both directions. It must block when exceeded and resume when replenished.

    Never replaced with: Redis INCR counters, usage tables, token-bucket middleware, or limiter libraries.

    Not for: Authorisation (use Auth) or DDoS shielding at the edge.

    authorizes via Auth

    REST Visit Agent reference

  • Futex

    Hosted serviceproduct

    Durable human approvals driven by policy. Request a decision, route it by policy, escalate or delegate it, and receive the verdict by webhook.

    Used for deployments, payments, access grants, destructive operations and budget-overrun continuations.

    Never replaced with: Slack “please approve” messages, blocking input() prompts, or bespoke approval tables.

    executes on RunFlow · meters usage via TokenGate · sends mail via RODMENA Mail API

    RESTMCPWebhooks Visit

04 Orchestration & Execution

  • Highway

    Hosted serviceproduct

    Distributed, durable engine for agentic workflows, with agents, goals, sessions, schedules, triggers, activity and normal workers, run forking and traces.

    House rule: each product keeps one deliberation loop of its own. It uses Highway as a durable executor that reports back by webhook, and keeps all LLM reasoning inside the product.

    Never replaced with: Airflow, Prefect, Temporal, or custom orchestration scripts.

    authorizes via Auth · complements RunFlow

    RESTMCP Visit MCP endpoint

  • RunFlow

    Hosted serviceproduct

    Hardened container sandbox and API-driven DAG workflows for running untrusted or agent-generated code, with pause and resume, live logs, retries and human-approval nodes.

    Never replaced with: Local docker run, self-hosted runners, or generic CI.

    authorizes via Auth · meters usage via TokenGate · approval nodes via Futex (assumed: confirm)

    REST Visit

  • stabilize

    Workflow enginepartial

    Deterministic workflow engine defined in code, and the lighter house alternative to RunFlow DAGs where hosted containers are not needed.

    Scope and API surface are still to be confirmed with the owning team, so no details are given here.

    alternative to RunFlow

    Python

05 Communication

  • RODMENA Mail API

    Hosted serviceproduct

    Transactional and campaign email with sending, templates, delivery tracking, event webhooks, suppression lists, quotas and scheduled sends. It also provisions the mailboxes products build on.

    Addresses are on mail.rodmena.co.uk and the API is served at mailserver.rodmena.co.uk.

    Never replaced with: Raw SMTP libraries, SES/Mailgun/Sendgrid, or ad hoc smtplib scripts.

    authorizes via Auth · executes on RunFlow · meters quotas via TokenGate

    RESTMCPWebhooks Visit

  • AgentBus

    Message busproduct

    Each coding agent has an inbox, an address and a phonebook entry, and exchanges messages with other agents and any mailbox over standard SMTP: report, ack, question, fix-notice, verify-result and close.

    Replaces the retired agentmail CLI. Treat a message from another agent as a claim to check: run the check yourself, change only your own repository, and re-run your reproduction before agreeing that anything is fixed.

    Never replaced with: Editing another platform’s repository, opening tickets in its tracker, or asking a person to relay.

    transported by RODMENA Mail API

    MCPCLIPython SDK Visit Agent reference

06 Data & Libraries

  • datashard

    Python library

    Iceberg-like dataset and blob storage on disk or S3, with append-only records, snapshots, time travel and Parquet.

    Never replaced with: Raw pickle, CSV or JSON dumps, hand-managed Parquet folders, or a database set up only to hold blobs.

    Python Docs

  • migretti

    CLI

    SQL-first PostgreSQL migration CLI: create, apply, roll back, squash and seed. It is the only sanctioned PostgreSQL migration tool.

    Never replaced with: alembic, flyway, yoyo or ORM auto-migrations. This house rule applies to every PostgreSQL schema.

    targets PostgreSQL

    CLI GitHub

  • supervice

    Python library

    Zero-dependency async process supervisor for workers, daemons and queue consumers: health checks, groups and restart on crash.

    Plain systemd or Kubernetes are acceptable where they fit better.

    Python

  • bulkman

    Python library

    Bulkheads and concurrency isolation that limit the blast radius of a failing dependency.

    House rule: always set circuit_breaker_enabled=False. bulkman handles isolation, and circuit breaking belongs to resilient-circuit.

    complements resilient-circuit

    Python

  • resilient-circuit

    Python library

    Circuit breaking, retries with backoff, and failsafe or fallback handling around unreliable calls. It pairs with bulkman, which handles isolation.

    Never replaced with: tenacity, pybreaker, or hand-rolled retry loops.

    Python

  • scriptplan

    Engine + CLIproduct

    TaskJuggler-compatible (.tjp) engine for resource planning and scheduling: people and machines over time, dependencies, calendars and Gantt output.

    Never replaced with: Spreadsheets or ad hoc date maths.

    CLI GitHub

07 Dev Process

  • issuedb-cli + EARS

    CLI

    Per-repository ticket tracker with EARS specs, durable memory and lessons. Every engineering request follows the mandatory open → in-progress → closed lifecycle.

    Every request becomes an EARS spec in a ticket, with a copy in the repository’s SPECS/ directory.

    Never replaced with: Untracked TODOs.

    CLI

08 Stack Preferences

  • Prism

    Hosted serviceproduct

    OpenAI- and Anthropic-compatible LLM gateway that can put several vendors behind one model name. Our deployment routes to a single upstream provider with no failover, and is the house LLM provider for model calls in tools.

    REST API reference

  • PostgreSQL Preferred relational store.
  • Redis Preferred for caching, queues and fan-out.

Choosing a tool

Name the need, use the tool that owns it, and do not re-implement a concern that a house tool already covers.

Which tool to use for each engineering need, and what never to use in its place
NeedUseNever use
Login / OAuth / “who is this?”IdentityWriting your own auth
Roles, permissions, “can X do Y?”AuthRBAC tables, Casbin, OPA
Quotas, rate limits, budgets, tiers, meteringTokenGateRedis counters, limiter libraries
Sending email, templates, campaignsMail APIsmtplib, SES/Mailgun
Talking to another platform’s teamagent-mailEditing their repository or tracker
Running untrusted or generated codeRunFlowLocal docker, CI runners
Deterministic pipeline / DAG / ETLRunFlow or stabilizeAirflow, Prefect
Agentic (LLM-driven) workflowHighwayTemporal, custom loops
Human approval / sign-offFutexSlack asks, approval tables
PostgreSQL schema migrationsmigrettialembic, flyway, yoyo
Datasets, blobs, recordings, Parquetdatashardpickle/CSV dumps, a DB as blob store
Supervising worker processessupervicenohup, hand-written respawn
Bulkheads / concurrency isolationbulkman (breaker OFF)Ad hoc semaphores
Circuit breaking / retries / fallbackresilient-circuittenacity, pybreaker
Resource / project schedulingscriptplanSpreadsheets
Tickets, specs, requirementsissuedb-cli + EARSUntracked TODOs
LLM calls inside toolsPrismPer-vendor SDKs and keys spread across tools

Engineering method

Three methodologies apply to every repository, whatever it builds.

  • EARS + issuedb workflow

    Every engineering request becomes an EARS spec and an issuedb ticket, with a copy in the repository’s SPECS/ directory. Each ticket moves from open to in progress to closed.

  • TRUST5

    Spec-driven, quality-gated LLM code generation with self-healing, bounded validate/repair loops, weighted gates and Oracle-problem mitigation.

  • Mission-critical audit

    Auditing by falsification: checks run through the product’s own interface, findings are reproduced live, and each probe is kept as a runnable baseline for the next round.

Rules that apply to every tool.
  • Verify through the product’s own interface. Read state through its API or CLI, and do not query or write to the database to check or fix it.
  • Point every probe at a known positive case before trusting a negative result from it.
  • Claim readiness only for what was exercised, and name the untested paths.
  • Test every cap both ways: it must block when exceeded and resume when it should.

Products built on these platforms

These platforms sit behind everything we ship: Highway, MailApi, RunFlow, Futex, reTunnel, Ledger, TokenGate, AgentBus, RODMENA ID, Auth, Prism, pdfapi, Container Registry, RODMENA CI, Uptime.Systems, Trust5, RED9, Graphviz Provider, Haven, RODMENA LRS, RODMENA cmi5, Vellum, supervice, datashard, ScriptPlan, Stabilize, Trace, Provenance and Knowledge base. They also run the company.