Skip to content

About

Deterministic, auditable architecture risk scoring from a declared system inventory: single point of failure, excessive coupling, scalability gap. Every score traces back to a rule with a stated rationale. C#/.NET 10 HTTP service, CLI, and NuGet package.

Topics

Resources

Code of conduct

Contributing

Stars

2 stars

Watchers

1 watching

Forks

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

Β 

History

35 Commits

Folders and files

Repository files navigation

CloudSealed Predictive-ML-Core ⚑ ARCHITECTURE RISK & BLAST-RADIUS ENGINE

The ultra-fast, deterministic architecture risk scoring engine and IaC dependency analyzer for high-reliability cloud systems.

CI NuGet NuGet downloads Docker pulls License: MIT .NET MCP Ready


πŸ’‘ Why CloudSealed Predictive-ML-Core?

In modern cloud-native engineering, microservices, complex cloud architectures, and distributed systems suffer from hidden points of failure, untraceable dependency cascades, and silent architectural drift.

Traditional tools either force manual compliance questionnaires (AWS Well-Architected Tool) or rely on black-box AI models that hallucinate risk scores without auditability.

CloudSealed.ML.Core solves this problem. It automatically ingests declared infrastructure (Terraform, Kubernetes, Docker Compose, Mermaid diagrams, or JSON inventories), computes dependency blast-radii in $O(V+E)$, and scores architecture risk across 3 core dimensions with 100% deterministic, auditable rules.

                           INPUT INGESTION
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚  Terraform   β”‚   β”‚  Kubernetes  β”‚   β”‚ Docker Compose β”‚   β”‚ Mermaid DAG  β”‚
 β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
        β”‚                  β”‚                  β”‚                    β”‚
        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β–Ό
                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β”‚ CloudSealed Predictive Core β”‚
                      β”‚   - AVX2 SIMD Telemetry     β”‚
                      β”‚   - DAG Blast Radius DFS    β”‚
                      β”‚   - Risk Scoring Rules      β”‚
                      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β–Ό
                       AUDITABLE OUTPUT & REMEDIATION
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚ GitHub PR Bot  β”‚   β”‚ Interactive    β”‚   β”‚  Slack / Teams β”‚   β”‚ GenAI Code   β”‚
 β”‚   Comment      β”‚   β”‚ HTML Dashboard β”‚   β”‚ Webhook Alerts β”‚   β”‚ Remediation  β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ”₯ Key Technical Highlights

πŸš€ 1. AVX2 SIMD Zero-Allocation Telemetry Probe (ZeroAllocRiskProbe)

Designed for real-time observability pipelines. Evaluates p99 latencies, mean ratios, and performance anomalies using AVX2 SIMD vectorization over ReadOnlySpan<float>, operating with exactly 0 bytes allocated per operation.

πŸ•ΈοΈ 2. $O(V+E)$ DAG Blast-Radius Engine (DependencyGraphAnalyzer)

Zero-allocation Directed Acyclic Graph (DAG) depth-first traversal engine. Instantly calculates cascading risk factors, upstream/downstream dependency depth, and total blast radius when a specific service fails.

πŸ“„ 3. Native Infrastructure-as-Code (IaC) & Diagram Ingestion

No need to build JSON inputs manually. Parse your infrastructure directly from:

  • Terraform (.tf): Scans cloud resources, databases, and network bounds.
  • Kubernetes Manifests (.yaml): Extracts deployments, ingress, and pod dependencies.
  • Docker Compose (docker-compose.yml): Analyzes multi-container topology.
  • Architecture Diagrams (Mermaid.js): Parses text-based architecture charts directly into scoring inventories.

πŸ“Š 4. 100% Deterministic & Auditable (Zero AI Hallucinations)

Compliant with SOC 2, ISO 27001, and HIPAA audit requirements. Every single score comes with a strict mathematical breakdown: $$\text{riskScore} = \min\left(\sum \text{rulePoints}, 100\right)$$ The score and its explanation can never drift apart.

πŸ€– 5. GenAI Automated Code Remediation (GenAiRemediationEngine)

When an architectural vulnerability is flagged (e.g., Single Point of Failure or Auth Leakage), the engine automatically crafts exact prompt directives to query Claude, OpenAI, Gemini, or Ollama to output ready-to-apply C# and Terraform fix code.

πŸ”Œ 6. AI-Agent First Architecture (MCP Integration)

Native integration with the Model Context Protocol (MCP). LLM Coding Agents (Claude Code, Cursor, Copilot, ChatGPT) can call cloudsealed_score_architecture_risk via cloudsealed-mcp to evaluate infrastructure safety during code generation.


⚑ Quickstart

Option 1: C# / .NET 10 Package

Install via NuGet:

dotnet add package CloudSealed.ML.Core

Analyze your infrastructure in code:

using CloudSealed.ML.Engine.Scoring;
using CloudSealed.ML.Engine.Models;

var request = new PredictArchitectureRequest
{
    CompanyName = "Acme Global",
    Systems = new List<SystemInput>
    {
        new SystemInput
        {
            Name = "checkout-api",
            Type = "API",
            Criticality = "CRITICAL",
            PublicFacing = true,
            AuthMethod = null // Single point of failure + Unauthenticated Public API risk
        },
        new SystemInput
        {
            Name = "main-db",
            Type = "DATABASE",
            Criticality = "HIGH",
            PublicFacing = false
        }
    }
};

var analyzer = new ArchitectureAnalyzer();
PredictArchitectureResponse response = analyzer.Analyze(request);

Console.WriteLine($"Overall Architecture Score: {response.OverallArchitectureScore}/100");

foreach (var prediction in response.Predictions)
{
    Console.WriteLine($"System: {prediction.SystemName}");
    Console.WriteLine($"  SPOF Risk: {prediction.RiskScores.SinglePointOfFailure}");
    Console.WriteLine($"  Coupling Risk: {prediction.RiskScores.ExcessiveCoupling}");
    Console.WriteLine($"  Scalability Gap: {prediction.RiskScores.ScalabilityGap}");
}

Option 2: Command Line (CLI) & Interactive HTML Reports

Run audit scans directly against JSON inventory files, Terraform specs, or K8s manifests:

# Human-readable CLI summary
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json

# Raw JSON output for automation
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json --json

# Generate a self-contained interactive HTML Dashboard (Offline, Zero CDN dependencies)
dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json --html audit-report.html

Option 3: GitHub Action (CI/CD Automated PR Auditing)

Automatically analyze infrastructure changes on every Pull Request and block critical architectural risk:

name: Architecture Audit CI

on:
  pull_request:
    branches: [ main ]

jobs:
  audit-architecture:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      
      - name: Run CloudSealed Architecture Risk Audit
        uses: cloudsealed/Predictive-ML-Core@main
        with:
          inventory-json: examples/inventory.json
          fail-on-severity: CRITICAL # Fails workflow if CRITICAL risk is detected

The action automatically writes interactive, formatted PR comments and updates them on subsequent pushes.


Option 4: REST API Service (Docker)

Run as an enterprise microservice:

docker run -p 8092:8092 cloudsealed/predictive-ml-core

POST /v1/predict-architecture:

curl -X POST http://localhost:8092/v1/predict-architecture \
  -H 'Content-Type: application/json' \
  -d '{
        "companyName": "Acme Enterprise",
        "systems": [
          { 
            "name": "payment-gateway", 
            "type": "API", 
            "criticality": "CRITICAL",
            "publicFacing": true, 
            "authMethod": "OAuth2" 
          }
        ]
      }'

Option 5: Slack / Teams / Webhook Alerts

Send real-time alerts to Slack or operational channels whenever a HIGH or CRITICAL architectural flaw is introduced:

dotnet run --project src/CloudSealed.ML.CLI -- examples/inventory.json --webhook-url "$SLACK_WEBHOOK_URL"

🎯 Scoring Dimensions & Auditability

CloudSealed.ML.Core evaluates infrastructure across 3 primary risk dimensions:

Risk Dimension Description Scoring Factors
singlePointOfFailure Evaluates redundancy and single-instance vulnerability. Base weight by criticality (CRITICAL=55, HIGH=35, MED=15), plus service type modifier (DATABASE +15, THIRD_PARTY +20).
excessiveCoupling Detects unauthorized exposure and dependency proliferation. Unauthenticated public endpoints (+40), third-party fan-out, and unmanaged API surfaces.
scalabilityGap Measures load limits and latency degradation. SIMD tail-latency ratio evaluation (p99 > 1000ms, p99/avg > 3x), unmonitored critical databases.

Every Score is Fully Provenanced

{
  "singlePointOfFailure": 60,
  "scoreBreakdown": {
    "singlePointOfFailure": [
      { 
        "rule": "criticality=CRITICAL", 
        "points": 55, 
        "rationale": "CRITICAL system without declared redundancy poses high business continuity risk." 
      },
      { 
        "rule": "type=API", 
        "points": 5, 
        "rationale": "API surface adds base protocol overhead and exposure point." 
      }
    ]
  }
}

πŸ“Š Feature Comparison Matrix

Feature CloudSealed Predictive-ML-Core Backstage CAST Highlight AWS Well-Architected Tool
Input Mode Terraform, K8s, Compose, Mermaid, JSON Custom Plugins & Yaml Codebase Scanner Manual Web Questionnaire
Auditability 100% Deterministic Rule Breakdown N/A (Catalog) Proprietary SaaS Manual Form Answers
Latency Engine Zero-Allocation AVX2 SIMD None None None
Blast Radius $O(V+E)$ DAG Engine Manual Graph View Portfolio Scan Static Documentation
AI Remediation GenAI Patch Generation None None None
Execution C# Lib, Native CLI, Docker, GitHub Action, MCP Self-Hosted Portal SaaS AWS Console
Cost / License 100% Free & Open Source (MIT) Open Source Commercial SaaS Free (AWS Native)

πŸ› οΈ Custom Rules & Extension

Want to add custom FinOps policies or internal compliance rules? The engine is built to be hackable.

  1. Fork this repository.
  2. Open src/CloudSealed.ML.Engine/Scoring/RiskRules.cs.
  3. Add your custom risk weight constants and rationales.
  4. Run dotnet test to ensure rule-breakdown invariants are preserved!

πŸ‘₯ Community & Contributing

We welcome pull requests, new IaC parsers, and custom risk rule additions!


FAQ

What is CloudSealed.ML.Core for? Deterministic, auditable architecture risk scoring and SLA breach forecasting from OS telemetry. Zero-allocation inference and SIMD-accelerated feature extraction for .NET services that need ML inline without GC pressure.

How is it different from ML.NET alone? ML.NET gives you the primitives. CloudSealed.ML.Core adds: zero-allocation inference path (ReadOnlySpan<float> throughout), deterministic scoring (same inputs β†’ same outputs), and prebuilt pipelines for risk/SLA use cases. Use raw ML.NET for generic models; use this for latency-sensitive services.

Does it support .NET Framework? No. .NET 6+ only β€” depends on Span<T> and modern SIMD intrinsics.

What does "zero-allocation inference" mean in practice? The hot path allocates nothing on the managed heap. No boxing, no LINQ, no new. Critical when running under GC pressure with strict p99 targets.

How do I integrate it into an ASP.NET Core service?

services.AddSingleton<RiskScorer>(sp =>
    RiskScorer.Load("models/arch-risk-v3.cml"));

app.MapGet("/score", (RiskScorer scorer, SystemInventory inv) =>
    scorer.Score(inv.AsSpan()));

Scorer is thread-safe β€” register as singleton.

<script type="application/ld+json"> { "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is CloudSealed.ML.Core for?", "acceptedAnswer": { "@type": "Answer", "text": "Deterministic, auditable architecture risk scoring and SLA breach forecasting from OS telemetry. Zero-allocation inference and SIMD-accelerated feature extraction for .NET services." } }, { "@type": "Question", "name": "How is CloudSealed.ML.Core different from ML.NET alone?", "acceptedAnswer": { "@type": "Answer", "text": "An opinionated layer on top of ML.NET adding zero-allocation inference, SIMD feature extraction via ReadOnlySpan, deterministic scoring, and prebuilt risk/SLA pipelines." } }, { "@type": "Question", "name": "Does CloudSealed.ML.Core support .NET Framework?", "acceptedAnswer": { "@type": "Answer", "text": "No. .NET 6+ only due to Span and modern SIMD intrinsics." } }, { "@type": "Question", "name": "What does zero-allocation inference mean?", "acceptedAnswer": { "@type": "Answer", "text": "The hot path from input to prediction allocates zero objects on the managed heap β€” no boxing, no LINQ, no new. Designed for services under GC pressure with strict p99 latency targets." } } ] } </script>

πŸ“œ License

This project is licensed under the MIT License.

About

Deterministic, auditable architecture risk scoring from a declared system inventory: single point of failure, excessive coupling, scalability gap. Every score traces back to a rule with a stated rationale. C#/.NET 10 HTTP service, CLI, and NuGet package.

Topics

Resources

Code of conduct

Contributing

Stars

2 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages