NuFiDocs

Components

Every piece of NuFi, what it does, and where it runs.

NuFi is one product made of several services. Most people only ever see the app and the console. Admins also see the admin panel and, on the compose stack, the trace viewer and the dashboards. Everything else runs behind the gateway.

What members see

SurfaceHosted atWhat it is for
The NuFi appchat.nufi.meconversations, files, agents, teams
NuFi Consoleconsole.nufi.meself-service gateway keys and your own usage
Agentsagents.nufi.methe door to the two agent products
NuFi Studiostudio.nufi.meflows on a canvas, published as endpoints
NuFi Worksworks.nufi.mea team of agents with goals, approvals and a budget

Sign in once. The console reads the app's session, and the agent products accept an identity the console issues. Studio and Works is the member's view.

What admins see

SurfaceHosted atWhat it is for
NuFi Admin Paneladmin.app.nufi.mesettings, users, roles, groups, per-role overrides, the audit log
Langfuselangfuse.codechi.me on NuFi's stack; host port 3000 on yoursevery request as a trace: user, model, tokens, cost
Grafanagrafana.codechi.me; host port 3030request rate, errors, latency, guardrail decisions
The gateway's admin UIapi.codechi.me/ui; host port 4000models, keys, spend, signed in with the master key
Prometheus, Alertmanagerhost ports 9090 and 9093, over SSHraw metrics and firing alerts

Administer walks through the day-to-day tasks on each.

Behind the scenes

ServiceWhat it doesWhere it runs
The NuFi appthe conversation UI and API; owns accounts, conversations, agents, filesRailway (hosted), the compose stack (self-hosted)
NuFi Consolekeys, usage, the identity issuer, the chooserboth
NuFi Admin Panelthe admin UI, against the app's admin APIRailway; its own image anywhere
NuFi AI GatewayLiteLLM with NuFi's guardrails: routing, keys, budgets, the five controls, traces, metricsthe compose stack
Presidio analyzer and anonymizerpersonal-data detection for the guardrailsthe compose stack, next to the gateway
nufi-scannerthe prompt-injection classifier the guardrails callthe compose stack, next to the gateway
Langfusetrace store: web, worker, ClickHouse, MinIOthe compose stack
Prometheus, Grafana, Alertmanagermetrics, dashboards, alert routing; two exporters for Postgres and Redisthe compose stack
Postgresgateway keys, budgets and spend; Langfuse metadatathe compose stack; Railway for Studio and Works
MongoDBthe app's databoth
Redisthe gateway's cache and rate-limit countersthe compose stack
RAG service and pgvectorfile uploads for the app, on RailwayRailway
NuFi Studiothe flow canvas and its runtime; Langflow, vendoredRailway; its own image anywhere
NuFi Worksthe agent-team server and UI; Paperclip, vendoredRailway; its own image anywhere

Alerts are routed to Slack once an operator adds a webhook; until then critical alerts have a receiver and nowhere to go. The image names, ports and rebuild rules are in Docker Compose and Ports.

The code

All of it is one repository, dudaji-vn/nufi-app: apps/chat (the app), apps/console, apps/admin-panel, apps/nufi-agent (Studio), apps/agents (Works), apps/docs (this manual), deploy/platform (the compose stack) and deploy/railway (the app on its own, and the Railway wrapper). Calling NuFi from your own code needs none of it; a key from the console is enough. Changing NuFi starts at Develop.