The ultra-fast, deterministic architecture risk scoring engine and IaC dependency analyzer for high-reliability cloud systems.
In modern cloud-native engineering, microservices, complex cloud architectures, and distributed systems suffer from hidden points of failure, untraceable dependency cascades, and silent architectural drift.
Traditional tools either force manual compliance questionnaires (AWS Well-Architected Tool) or rely on black-box AI models that hallucinate risk scores without auditability.
CloudSealed.ML.Core solves this problem. It automatically ingests declared infrastructure (Terraform, Kubernetes, Docker Compose, Mermaid diagrams, or JSON inventories), computes dependency blast-radii in
INPUT INGESTION
ββββββββββββββββ ββββββββββββββββ ββββββββββββββββββ ββββββββββββββββ
β Terraform β β Kubernetes β β Docker Compose β β Mermaid DAG β
ββββββββ¬ββββββββ ββββββββ¬ββββββββ ββββββββ¬ββββββββββ ββββββββ¬ββββββββ
β β β β
ββββββββββββββββββββ΄ββββββββββ¬βββββββββ΄βββββββββββββββββββββ
βΌ
βββββββββββββββββββββββββββββββ
β CloudSealed Predictive Core β
β - AVX2 SIMD Telemetry β
β - DAG Blast Radius DFS β
β - Risk Scoring Rules β
ββββββββββββββββ¬βββββββββββββββ
βΌ
AUDITABLE OUTPUT & REMEDIATION
ββββββββββββββββββ ββββββββββββββββββ ββββββββββββββββββ ββββββββββββββββ
β GitHub PR Bot β β Interactive β β Slack / Teams β β GenAI Code β
β Comment β β HTML Dashboard β β Webhook Alerts β β Remediation β
ββββββββββββββββββ ββββββββββββββββββ ββββββββββββββββββ ββββββββββββββββ
Designed for real-time observability pipelines. Evaluates p99 latencies, mean ratios, and performance anomalies using AVX2 SIMD vectorization over ReadOnlySpan<float>, operating with exactly 0 bytes allocated per operation.
Zero-allocation Directed Acyclic Graph (DAG) depth-first traversal engine. Instantly calculates cascading risk factors, upstream/downstream dependency depth, and total blast radius when a specific service fails.
No need to build JSON inputs manually. Parse your infrastructure directly from:
- Terraform (
.tf): Scans cloud resources, databases, and network bounds. - Kubernetes Manifests (
.yaml): Extracts deployments, ingress, and pod dependencies. - Docker Compose (
docker-compose.yml): Analyzes multi-container topology. - Architecture Diagrams (
Mermaid.js): Parses text-based architecture charts directly into scoring inventories.
Compliant with SOC 2, ISO 27001, and HIPAA audit requirements. Every single score comes with a strict mathematical breakdown:
When an architectural vulnerability is flagged (e.g., Single Point of Failure or Auth Leakage), the engine automatically crafts exact prompt directives to query Claude, OpenAI, Gemini, or Ollama to output ready-to-apply C# and Terraform fix code.
Native integration with the Model Context Protocol (MCP). LLM Coding Agents (Claude Code, Cursor, Copilot, ChatGPT) can call cloudsealed_score_architecture_risk via cloudsealed-mcp to evaluate infrastructure safety during code generation.
Install via NuGet:
dotnet add package CloudSealed.ML.CoreAnalyze your infrastructure in code:
using CloudSealed.ML.Engine.Scoring;
using CloudSealed.ML.Engine.Models;
var request = new PredictArchitectureRequest
{
CompanyName = "Acme Global",
Systems = new List<SystemInput>
{
new SystemInput
{
Name = "checkout-api",
Type = "API",
Criticality = "CRITICAL",
PublicFacing = true,
AuthMethod = null // Single point of failure + Unauthenticated Public API risk
},
new SystemInput
{
Name = "main-db",
Type = "DATABASE",
Criticality = "HIGH",
PublicFacing = false
}
}
};
var analyzer = new ArchitectureAnalyzer();
PredictArchitectureResponse response = analyzer.Analyze(request);
Console.WriteLine($"Overall Architecture Score: {response.OverallArchitectureScore}/100");
foreach (var prediction in response.Predictions)
{
Console.WriteLine($"System: {prediction.SystemName}");
Console.WriteLine($" SPOF Risk: {prediction.RiskScores.SinglePointOfFailure}");
Console.WriteLine($" Coupling Risk: {prediction.RiskScores.ExcessiveCoupling}");
Console.WriteLine($" Scalability Gap: {prediction.RiskScores.ScalabilityGap}");
}Run audit scans directly against JSON inventory files, Terraform specs, or K8s manifests:
# Human-readable CLI summary
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json
# Raw JSON output for automation
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json --json
# Generate a self-contained interactive HTML Dashboard (Offline, Zero CDN dependencies)
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json --html audit-report.htmlAutomatically analyze infrastructure changes on every Pull Request and block critical architectural risk:
name: Architecture Audit CI
on:
pull_request:
branches: [ main ]
jobs:
audit-architecture:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run CloudSealed Architecture Risk Audit
uses: cloudsealed/Predictive-ML-Core@main
with:
inventory-json: examples/inventory.json
fail-on-severity: CRITICAL # Fails workflow if CRITICAL risk is detectedThe action automatically writes interactive, formatted PR comments and updates them on subsequent pushes.
Run as an enterprise microservice:
docker run -p 8092:8092 cloudsealed/predictive-ml-corePOST /v1/predict-architecture:
curl -X POST http://localhost:8092/v1/predict-architecture \
-H 'Content-Type: application/json' \
-d '{
"companyName": "Acme Enterprise",
"systems": [
{
"name": "payment-gateway",
"type": "API",
"criticality": "CRITICAL",
"publicFacing": true,
"authMethod": "OAuth2"
}
]
}'Send real-time alerts to Slack or operational channels whenever a HIGH or CRITICAL architectural flaw is introduced:
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json --webhook-url "$SLACK_WEBHOOK_URL"CloudSealed.ML.Core evaluates infrastructure across 3 primary risk dimensions:
| Risk Dimension | Description | Scoring Factors |
|---|---|---|
singlePointOfFailure |
Evaluates redundancy and single-instance vulnerability. | Base weight by criticality (CRITICAL=55, HIGH=35, MED=15), plus service type modifier (DATABASE +15, THIRD_PARTY +20). |
excessiveCoupling |
Detects unauthorized exposure and dependency proliferation. | Unauthenticated public endpoints (+40), third-party fan-out, and unmanaged API surfaces. |
scalabilityGap |
Measures load limits and latency degradation. | SIMD tail-latency ratio evaluation (p99 > 1000ms, p99/avg > 3x), unmonitored critical databases. |
{
"singlePointOfFailure": 60,
"scoreBreakdown": {
"singlePointOfFailure": [
{
"rule": "criticality=CRITICAL",
"points": 55,
"rationale": "CRITICAL system without declared redundancy poses high business continuity risk."
},
{
"rule": "type=API",
"points": 5,
"rationale": "API surface adds base protocol overhead and exposure point."
}
]
}
}| Feature | CloudSealed Predictive-ML-Core | Backstage | CAST Highlight | AWS Well-Architected Tool |
|---|---|---|---|---|
| Input Mode | Terraform, K8s, Compose, Mermaid, JSON | Custom Plugins & Yaml | Codebase Scanner | Manual Web Questionnaire |
| Auditability | 100% Deterministic Rule Breakdown | N/A (Catalog) | Proprietary SaaS | Manual Form Answers |
| Latency Engine | Zero-Allocation AVX2 SIMD | None | None | None |
| Blast Radius |
|
Manual Graph View | Portfolio Scan | Static Documentation |
| AI Remediation | GenAI Patch Generation | None | None | None |
| Execution | C# Lib, Native CLI, Docker, GitHub Action, MCP | Self-Hosted Portal | SaaS | AWS Console |
| Cost / License | 100% Free & Open Source (MIT) | Open Source | Commercial SaaS | Free (AWS Native) |
Want to add custom FinOps policies or internal compliance rules? The engine is built to be hackable.
- Fork this repository.
- Open
src/CloudSealed.ML.Engine/Scoring/RiskRules.cs. - Add your custom risk weight constants and rationales.
- Run
dotnet testto ensure rule-breakdown invariants are preserved!
We welcome pull requests, new IaC parsers, and custom risk rule additions!
- Check out our open issues: GitHub Issues
- Read our CONTRIBUTING.md and ARCHITECTURE.md guides.
What is CloudSealed.ML.Core for? Deterministic, auditable architecture risk scoring and SLA breach forecasting from OS telemetry. Zero-allocation inference and SIMD-accelerated feature extraction for .NET services that need ML inline without GC pressure.
How is it different from ML.NET alone?
ML.NET gives you the primitives. CloudSealed.ML.Core adds: zero-allocation inference path (ReadOnlySpan<float> throughout), deterministic scoring (same inputs β same outputs), and prebuilt pipelines for risk/SLA use cases. Use raw ML.NET for generic models; use this for latency-sensitive services.
Does it support .NET Framework?
No. .NET 6+ only β depends on Span<T> and modern SIMD intrinsics.
What does "zero-allocation inference" mean in practice?
The hot path allocates nothing on the managed heap. No boxing, no LINQ, no new. Critical when running under GC pressure with strict p99 targets.
How do I integrate it into an ASP.NET Core service?
services.AddSingleton<RiskScorer>(sp =>
RiskScorer.Load("models/arch-risk-v3.cml"));
app.MapGet("/score", (RiskScorer scorer, SystemInventory inv) =>
scorer.Score(inv.AsSpan()));Scorer is thread-safe β register as singleton.
<script type="application/ld+json"> { "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is CloudSealed.ML.Core for?", "acceptedAnswer": { "@type": "Answer", "text": "Deterministic, auditable architecture risk scoring and SLA breach forecasting from OS telemetry. Zero-allocation inference and SIMD-accelerated feature extraction for .NET services." } }, { "@type": "Question", "name": "How is CloudSealed.ML.Core different from ML.NET alone?", "acceptedAnswer": { "@type": "Answer", "text": "An opinionated layer on top of ML.NET adding zero-allocation inference, SIMD feature extraction via ReadOnlySpan, deterministic scoring, and prebuilt risk/SLA pipelines." } }, { "@type": "Question", "name": "Does CloudSealed.ML.Core support .NET Framework?", "acceptedAnswer": { "@type": "Answer", "text": "No. .NET 6+ only due to Span and modern SIMD intrinsics." } }, { "@type": "Question", "name": "What does zero-allocation inference mean?", "acceptedAnswer": { "@type": "Answer", "text": "The hot path from input to prediction allocates zero objects on the managed heap β no boxing, no LINQ, no new. Designed for services under GC pressure with strict p99 latency targets." } } ] } </script>This project is licensed under the MIT License.