Architecture

Runtime flow

Slack -> HTTP callbacks (/slack/events and /slack/interactions) OR Socket Mode
      -> command parser -> Slack thread fetch -> secret redaction
      -> OpenAI directly OR Galileo/Portkey gateway -> DraftStore
      -> Slack preview -> Approve / Edit / Cancel
      -> GitHub draft PR OR Confluence page; optional Jira issue follows a GitHub PR

The active application is Python 3.11+ and FastAPI. app.main:app exposes /health, the two Slack HTTP endpoints, and /auth/github/start and /auth/github/callback. The alternative python -m app.slack_socket_app receives commands and interactions over Slack Socket Mode. Socket Mode does not require public Slack callback endpoints; HTTP mode verifies request signatures unless explicitly disabled.

The parser accepts one to five thread links by default. Slack messages are normalized and likely Slack, GitHub, OpenAI, and AWS access-key patterns are replaced with [REDACTED] before model input. The model returns a structured draft. No destination is written until its creator approves it.

Publishing and integrations

For GitHub, authorization is evaluated against KB_ALLOWED_REPOS and the selected authorization mode. Approval creates a timestamped knowledge-assistant/…​ branch, writes one Markdown or MDX file, and opens a draft pull request. Confluence approval calls the configured MCP create_page tool with MuleSoft service credentials and the approving user’s stored PAT. Jira is compatible with GitHub publishing only and is attempted after PR creation.

State and audit

Drafts use SQLite when DRAFT_DATABASE_PATH is set; otherwise they are process-local and lost at restart. OAuth authorizations and single-use, expiring OAuth state use SQLite when AUTHORIZATION_DATABASE_PATH is set. Confluence PATs are encrypted files under CONFLUENCE_TOKEN_DIRECTORY. The Helm chart mounts a single persistent volume for both SQLite databases.

Audit records contain request/user identifiers, target repository, source URLs, action, approver, and outcome; they do not contain Slack message bodies or tokens. The current audit repository is in-memory, so audit durability is TO_BE_CONFIRMED.