Third-party components¶
What the server and the GPU machines run besides Fadenstack's own code, and whose terms apply. This page is a reference for licence and compliance reviews.
Fadenstack's own code, configuration and deployment files are under the Apache License 2.0: the server's
services, the faden command-line tool, the node agent and the runtime helper. That licence does not change the
terms of the components below. Each release publishes SPDX software bills of materials (SBOMs) for its
artifacts; they list the packages found in them. An SBOM is an inventory, not a grant of rights: the licence files
and notices inside each image are what count.
On the server¶
faden deploy pulls Fadenstack's own images and these third-party images, each under its own terms:
| Component | What it does here |
|---|---|
| nginx | The front door: HTTPS, the console, /api, /v1 |
| PostgreSQL with pgvector | All relational data, and vectors for document search |
| Redis | Leases, rate limits, cache |
| RabbitMQ | Messages between the services |
| ClickHouse | The trace store behind Langfuse |
| MinIO | File storage behind Langfuse |
| Langfuse (web and worker) | Request traces, when tracing is switched on (it is off by default) |
| Prometheus | Metrics |
| Loki | Logs |
| Grafana | Dashboards |
| Grafana Alloy | Collects the server's container logs |
Inside Fadenstack's own images:
| Image | Third-party content | Terms |
|---|---|---|
| All service images | Python packages from the services' lock files, the Python base image, operating-system packages | Each keeps its own licence; the image's SBOM lists them |
| Console (frontend) | npm packages (React, React Router, MUI and others); the Sora font | Each npm package keeps its own licence; Sora is under the SIL Open Font License 1.1 |
| Console API, gateway, PII | Swagger UI and ReDoc, for the API documentation pages | Swagger UI: Apache License 2.0. ReDoc: MIT. Their licence and notice files ship next to them |
The faden tool carries the deployment files and its Python dependencies, which keep their own licences. The
images those files name are downloaded separately and keep their own terms.
On the GPU machines¶
| Artifact | Built on | Terms |
|---|---|---|
| Runtime image for NVIDIA DGX Spark | NVIDIA's vLLM container from the NVIDIA NGC catalog (nvcr.io/nvidia/vllm), with CUDA and other NVIDIA components, plus Ray and added Python packages |
The base image is under the NVIDIA Deep Learning Container License, which sets conditions on distributing derived containers and restricts stand-alone redistribution. Ray and vLLM are Apache-2.0, but that does not make the whole image Apache-2.0 |
| Runtime image for x86_64 machines | A slim Python base image, operating-system packages, Ray and vLLM from PyPI, and the Python and CUDA packages they pull in | Each component keeps its own licence, including NVIDIA packages that are not open source. The image's SBOM is the inventory |
| Model-TLS proxy | nginx | nginx's licence |
| The models | Whatever you deploy from Hugging Face or import | Each model's own licence, which the administrator accepts on Hugging Face for gated models |
The machines get these images from the server. If you redistribute a runtime image outside your organisation, check the exact terms of its base image first.