Codebase map
The runtime is one Python package, interlock, with the services as entry points (python -m interlock.gateway, .admin, .worker). Database migrations are in migrations/, the Helm chart and deployment scripts in deploy/, tests in tests/, and this site in docs-site/.
| Package | What it holds |
|---|---|
interlock.admin |
The admin console and its JSON API: sources, connectors, roles, identities, policies, approvals and audit. |
interlock.audit |
The audit log writer (batching, retry, disk spool) and usage aggregation. |
interlock.cache |
Response caching: in-process and Redis tiers, cache keys, per-source strategies and invalidation. |
interlock.catalog |
The source catalog: what each registered source contains, structurally. |
interlock.connections |
Connectors, pooled connections, circuit breakers, source configuration and the role vocabulary. |
interlock.core |
Governance decisions: authentication, source roles, policy, SQL governance, write classification, approvals and rate limits. |
interlock.db |
Database connection utilities for InterLock. |
interlock.discovery |
Discovery: search across indexed content, categories and entities. |
interlock.gateway |
The gateway: the PostgreSQL wire, HTTP proxy and MCP front doors, and the governance pipeline they share. |
interlock.metadata |
The in-memory registry of enabled data sources, reloaded when configuration changes. |
interlock.notifications |
Outbound notifications for write approvals. |
interlock.observability |
OpenTelemetry tracing and metrics. |
interlock.pipeline |
Response processing: PII scanning and redaction. |
interlock.secrets |
Resolution of secret references: env://, file://, vault:// and aws-sm://. |
interlock.security |
API-key hashing, outbound egress checks and the repository secret scanner. |
interlock.utils |
Small shared helpers. |
interlock.worker |
The background worker: ingestion jobs, catalog scans and scheduled refreshes. |