Catalog and Infrastructure Graph

A live inventory of everything your organization runs and how it connects, plus a versioned graph of a project's code and infrastructure that build pipelines can query.

Praxis gives you two ways to see your infrastructure, and they share only a word. Catalog is a live inventory of what your organization runs right now: an agent inspects your Kubernetes clusters, cloud accounts, and Facets environments, then maps every service, database, cache, and queue, along with the dependencies that connect them. Infrastructure Graph is different. It is a versioned bundle of one project's code and infrastructure that you publish and query from a build pipeline.

What Catalog shows

Catalog lives at /knowledge/catalog. The map is searchable, can be filtered by type, source, and namespace, and can be shown grouped or as a flat list. Every entry is one running thing: a service, database, cache, queue, ingress, storage, scheduled job, or function. Catalog keeps one map per organization, so production and staging appear together, each entry labeled with its environment.

Opening an entry shows what it is, how critical it is and what happens if it fails, and its dependencies split into what it depends on and what depends on it. Each entry carries a source, which is the system it was seen in or "Inferred" when the agent deduced it, and a confidence level. High confidence means the agent saw the entry directly in a live scan; low confidence means it was inferred. Where an entry has a known owning repository, Catalog links it, both the application repository and the infrastructure-as-code repository. Catalog does not read your source code.

The agent builds the map from three kinds of source. In Kubernetes it walks namespaces and reads workload configuration, inferring connections from environment variables such as a DATABASE_URL. In cloud accounts on AWS, GCP, and Azure it reads the managed resources each one runs. From your Facets environments it tags each entry with its Facets identity: project, intent, and flavor.


Turning on scanning

📘

Catalog scanning is off by default. Connecting a Kubernetes cluster, cloud account, or Facets environment only makes it available to scan. Nothing runs until you turn a target on.

Open Scan Targets under Catalog. Praxis auto-discovers your connected clusters, cloud accounts, and Facets environments and lists each one as a target, switched off. Enable a target and choose how often it scans, from every 12 hours up to every 7 days, then set the time of day and timezone. Use Scan Now to run one scan immediately. A target that fails several times in a row pauses itself until you re-enable it.

Every scan is run by an agent, so you can see exactly what it did. Scan History lists each scan with its result counts, cost, and duration, and lets you open the scan's chat. From an entry's own page you can refine what the agent found: edit its details, add a missing connection, link its repositories, or rescan just that entry.

🚧

Deleting an entry removes its connections with it, and Delete All clears the whole map for your organization. Neither can be undone, though the next scan re-discovers whatever is still running.


How Catalog powers incident response

Catalog's main use today is spotting cascading failures during incident response. When Incident Responder investigates an alert and Catalog covers the affected service, it walks the dependency map to nearby services and checks which of them also have open incidents. That turns one root cause spreading through connected services, a database outage taking four services down with it, into a single picture instead of four separate investigations. Without Catalog, Incident Responder still investigates, one incident at a time.


Infrastructure Graph

Infrastructure Graph captures how one project fits together as a portable, versioned bundle. It lives at /knowledge/ig, where the product lists published bundles as ig Catalogs. Each bundle is built from members of two kinds. A code member is a project's source repository, pinned to one exact commit. An infra member is the project's Facets infrastructure graph, which has no repository of its own. Pinning every code member to a commit is the point: a bundle describes one precise version of a project, not whatever sits on a branch today.

A small manifest travels with each bundle and declares which members belong to it. Opening a bundle shows four tabs: Graph, the members and how they connect; Members, each member's kind, git URL, and commit; Manifest, the pushed manifest, read-only; and Assemblies, the history of assemble runs, newest first.


Publishing and querying a graph

You build and publish a bundle from the command line, not in the browser, using the praxis ig commands. You author the manifest in your repository and push it with praxis ig manifest push. Your build pipeline generates each code member's graph and publishes it with praxis ig publish. Praxis reassembles the bundle after each publish, so it always reflects the members pushed so far. praxis ig list shows your bundles, and praxis ig sync downloads an assembled one.

A bundle has two audiences. A person browses it in the product with their signed-in session. A build pipeline runs unattended and authenticates with a Praxis API key, mainly to run the reverse lookup praxis ig claims --git <repo-url>. Given a repository, it answers which published bundles embed it, so a pipeline can tell whether the change it is about to build belongs to one, and which.

The infra member has no repository, so Praxis rebuilds it server-side using your Facets credentials. It refreshes on a periodic schedule and on demand, and you can connect a Facets deploy webhook so that each deployment refreshes it. Detailed questions about a single relationship in the graph are answered by a Praxis agent with the bundle loaded, rather than drawn in the browser, because a full member graph is large.


How Catalog and Infrastructure Graph differ and relate

CatalogInfrastructure Graph
What it isA live map of everything your organization runs nowA versioned bundle of one project's code and infrastructure
How it stays currentAn agent scans your live systems on a scheduleYou publish it from CI, each code member pinned to a commit
Where it lives/knowledge/catalog/knowledge/ig
Who uses itIncident Responder and people investigating incidentsBuild pipelines and developers

Reach for Catalog when you want the live operational picture, including incident investigation. Reach for Infrastructure Graph when a build pipeline needs to know whether a change belongs to a published, versioned bundle. They hold different data, with different producers and consumers, in separate homes in the product.


Read-only by design

Neither feature changes your infrastructure. Catalog only ever reads: it inspects your clusters, cloud accounts, and Facets environments to build the map, and writes only to the map itself, never to the systems it scans. It cannot restart, modify, or delete anything you run. Infrastructure Graph is the same, because building, publishing, assembling, and querying a bundle only read and record. Both are scoped to your organization. For the shared execution, credential, and permission model these run under, see How Praxis works.