Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

NexusAgent 架构设计文档

基于技术调研论的最终技术选型与各层设计


1. 系统架构总览

┌────────────────────────────────────────────────────────────────────────┐
│ 接入层 (Clients) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ WebChat │ │ QQ │ │ 飞书 │ │ REST API │ │
│ │ (Vue3) │ │(OneBot) │ │ SDK │ │ (第三方) │ │
│ └──────────┘ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Spring Cloud Gateway (Port 8080) │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ JWT 认证 │ │ Tenant ID │ │ 限流 │ │
│ │ (Auth) │ │ 注入 │ │(Sentinel)│ │
│ └──────────┘ └──────────┘ └──────────┘ │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Java 微服务层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ Auth │ │ Tenant │ │Session │ │Knowledge│ │ MCP │ │
│ │ 认证服务│ │租户服务│ │会话服务│ │知识库服务│ │ Manager │ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
│ │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Nexus Platform (WebChat + QQ) │ │
│ │ ┌────────────────┐ ┌────────────────┐ │ │
│ │ │ WebSocket Handler│ │ QQ Adapter │ │ │
│ │ │ (流式直连) │ │ (MQ 异步) │ │ │
│ │ └────────────────┘ └────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ │
│ Nacos (服务注册与配置) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ Python AI 服务层 │
│ ┌──────────────────────────────────────────────────────────────┐ │
│ │ Agent Engine (LangGraph) │ │
│ │ ┌────────────┐ ┌────────────┐ ┌────────────────────┐ │ │
│ │ │ ToolManager│ │LoopController│ │ Followup Queue │ │ │
│ │ │ (工具管理) │ │ (最大30次) │ │ (消息注入) │ │ │
│ │ └────────────┘ └────────────┘ └────────────────────┘ │ │
│ └──────────────────────────────────────────────────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ LLM Proxy │ │Tool Registry│ │ Memory │ │ RAG │ │
│ │ (LLM调用)│ │ (工具执行) │ │ (会话记忆)│ │ (知识检索)│ │
│ └───────────┘ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Nacos (服务注册) │
└────────────────────────────────────────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ 基础设层 │
│ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │ MySQL 8│ │ Redis │ │ Milvus │ │RabbitMQ│ │ MinIO │ │
│ │(租户数据)│ │(缓存/会话)│ │(向量库)│ │(消息队列)│ │(文件存储)│ │
│ └────────┘ └────────┘ └────────┘ └────────┘ └────────┘ │
└────────────────────────────────────────────────────────────────────────┘

2. 核心模块设计

2.1 Agent Engine

Agent Engine 是系统的核心 AI 引擎,基于 LangGraph 实现。

2.1.1 工具系统

工具来源

来源说明权限控制
内置工具 (BUILTIN)calculator, web_search, sandbox_execute所有用户可见
MCP Server (MCP)用户配置的外部 MCP Server按 Agent 绑定
自定义工具 (CUSTOM)租户自定义工具按角色权限

MCP Server 配置格式

// SSE 模式
{
"transport": "sse",
"url": "https://mcp.example.com/sse",
"headers": {"Authorization": "Bearer xxx"},
"timeout": 30
}
// Streamable HTTP 模式
{
"transport": "streamable_http",
"url": "https://mcp.example.com/mcp",
"headers": {"Authorization": "Bearer xxx"}
}

2.1.2 Agent Loop 控制

  • 最大循环次数:30 次
  • 强制输出:到达上限后强制得到最终输出
  • 强制输出 Prompt
你已达到最大工具调用次数(30次)。
请基于之前的分析和工具调用结果,直接回答用户的问题。
不要调用任何新工具,给出最终答案。

2.1.3 Followup 队列

用户可以在 Agent 执行过程中注入新消息:

  • 消息存储在 Redis 队列中
  • 每次工具调用后检查队列
  • 注入消息附加在 tool message 后面
  • 按顺序排队,统一注入到 prompt

2.1.4 会话控制

功能说明
停止流式/非流式都能中途停止
中断机制Redis flag + NodeInterrupt

2.2 MCP Manager

MCP Server 管理服务(Java):

功能说明
CRUDMCP Server 创建/更新/删除
绑定将 MCP Server 绑定到 Agent
测试连接验证 MCP Server 可用性
限制每租户最多 100 个 MCP Server

2.3 权限系统

两次鉴权

  1. Agent 端:快速过滤,减少 LLM token 消耗
  2. 微服务端:安全兜底,防止绕过

权限模型

  • 角色级别权限(role_tool_permission)
  • Agent-MCP 绑定(agent_mcp_binding)

2.4 审计日志

所有租户相关操作都记录审计日志:

  • 用户操作(创建/更新/删除)
  • MCP Server 操作
  • 工具执行记录

3. 数据流设计

3.1 WebChat 流式链路(直接 HTTP)

WebSocket → WebChatWebSocketHandler → AgentService → HTTP SSE → agent-engine
↓ 逐 token 推送
WebSocket 客户端

3.2 QQ Bot 非流式链路(MQ 异步)

QQ 消息 → platform → MQ inbound 队列
↓
agent-engine 消费 → 非流式调用 → MQ outbound 队列
↓
platform 消费 → QQ API

3.3 工具调用链路

Agent (LLM 返回 tool_call)
↓
ToolManager.check_permission() → 第一次鉴权
↓
Tool-Registry / MCP Executor → 第二次鉴权
↓
执行工具 + 记录审计日志

4. 数据库设计

4.1 新增表

表名说明
mcp_serverMCP Server 配置
agent_mcp_bindingAgent-MCP 绑定
role_tool_permission角色-工具权限
audit_log审计日志
tool_execution_log工具调用记录
mcp_execution_logMCP 调用记录

4.2 Schema

详见 sql/V2__mcp_tools_audit.sql


5. API 设计

5.1 MCP Server

接口方法说明
/api/mcp/serversGET列表
/api/mcp/serversPOST创建
/api/mcp/servers/{id}PUT更新
/api/mcp/servers/{id}DELETE删除
/api/mcp/servers/{id}/testPOST测试连接

5.2 Agent-MCP 绑定

接口方法说明
/api/agent/{id}/mcpGET获取绑定列表
/api/agent/{id}/mcp/bindPOST绑定
/api/agent/{id}/mcp/{mcpId}DELETE解绑

5.3 角色权限

接口方法说明
/api/role/{id}/toolsGET获取权限
/api/role/{id}/toolsPOST设置权限

6. Nacos 服务注册

所有 Python 服务都通过 Nacos 进行服务发现:

服务服务名端口
nexus-agent-enginenexus-agent-engine8001
nexus-llm-proxynexus-llm-proxy8010
nexus-tool-registrynexus-tool-registry8011
nexus-memory-servicenexus-memory-service8012
nexus-rag-servicenexus-rag-service8013
nexus-sandbox-servicenexus-sandbox-service8020

7. 启动命令

# 启动所有服务
docker compose up -d
# 单独启动 Python 服务cd python-services/agent-engine
pip install -r requirements.txt
python main.py

8. 环境变量

8.1 Python 服务

变量说明默认值
NACOS_ENABLED启用 Nacosfalse
NACOS_SERVERNacos 地址127.0.0.1:8848
NACOS_SERVICE_NAME服务名-
REDIS_HOSTRedis 地址127.0.0.1
MYSQL_HOSTMySQL 地址127.0.0.1

8.2 MCP Server

配置项说明
transportsse / streamable_http
urlMCP Server 地址
headers认证头
timeout超时秒数

9. 待实现功能

  • MCP Server 实际连接测试
  • MCP 工具列表获取
  • 工具执行频率限制
  • Rerank 优化
  • 多模态支持

About

NexusAgent - 企业私有化部署的 Agent 平台

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages