Skip to main content

Knowledge Bases architecture

This page describes how CAIPE ingests, authorizes, searches, and serves organizational knowledge. For implementation details and environment variables, see RAG codebase architecture.

Component architecture​

Core components​

ComponentDefault portResponsibility
CAIPE UI and BFF3000Data source management, collections, search, graph exploration, and authenticated API proxying
RAG server9446Ingestion, hybrid search, graph operations, REST APIs, and MCP tools
Ontology Agent8098Optional background discovery and validation of entity relationships
IngestorsVariesRetrieve data from external systems and submit normalized content or entities

OIDC establishes the caller's identity. OpenFGA relationships decide which knowledge-base actions and resources that identity may use. The RAG server checks data source access even when a request has already passed through the UI BFF.

Document ingestion​

  1. An ingestor retrieves source content and associates every item with a data source ID.
  2. The RAG server normalizes and chunks the text while preserving useful metadata.
  3. An embedding provider creates dense semantic vectors.
  4. Milvus produces and indexes BM25 sparse vectors for keyword matching.
  5. Milvus stores both representations for filtered hybrid retrieval.

Data source IDs are part of the security boundary. Reloading a data source replaces its indexed content and removes stale pages while preserving its ownership and search access.

Structured-entity ingestion​

Structured ingestors can submit entities and relationships instead of document pages. The server splits nested structures into connected entities, makes their properties searchable, and stores their relationships in Neo4j when Graph RAG is enabled.

The Ontology Agent examines entity types and properties, finds candidate relationships, evaluates them, and writes accepted relationships to the ontology graph.

Authorized query flow​

For a direct search, the requested scope may include every data source the caller can search. For an agent request, CAIPE intersects that access with the data sources and collections selected for the agent. Both paths fail closed when authorization cannot be verified.

Hybrid retrieval​

A query produces a dense vector and a sparse keyword representation. Milvus runs both searches within the authorized data source filter, then CAIPE combines the result scores with configurable weights.

StrategySemantic weightKeyword weightUseful for
Balanced50%50%General-purpose retrieval
Semantic90%10%Concepts and paraphrased language
Keyword10%90%Exact identifiers and terms

These values describe the standard presets. Deployments can tune the weights for their content and evaluation results.

Storage and supporting services​

ServicePurpose
MilvusDense HNSW and sparse BM25 indexes
Neo4jOptional data and ontology graphs
RedisData source metadata, ingestion jobs, and ontology state
Object storageMilvus object persistence
etcdMilvus metadata coordination

Embedding providers​

The embedding factory supports provider configurations for:

  • Azure OpenAI
  • OpenAI
  • AWS Bedrock
  • Cohere
  • Hugging Face
  • LiteLLM
  • Ollama

Use deployment-owned secrets for credentials. Do not place provider keys in reusable source configuration or documentation examples.

Port reference​

PortServiceProtocol
3000CAIPE UIHTTP
9446RAG REST API and MCP serverHTTP / Streamable HTTP
8098Ontology AgentHTTP
7687Neo4jBolt
7474Neo4j BrowserHTTP
19530MilvusgRPC
6379RedisTCP

Neo4j and the Ontology Agent are required only for the Graph RAG profile.

Further reading​