Plataforma soberana de democracia participativa (PINDORAMA) — participação sem consequência é teatro. Rust + ActivityPub + 70k mandatos reais. https://democracia.social.br
  • Rust 63.5%
  • Svelte 19.3%
  • PLpgSQL 6.8%
  • TypeScript 3.8%
  • Astro 3.4%
  • Other 3.2%
Find a file
Marcos 9953268606
Some checks failed
ci / fmt (push) Successful in 6s
ci / clippy (push) Successful in 3m33s
ci / boundaries (push) Successful in 11s
ci / test (push) Failing after 4s
ci / coverage (push) Failing after 4s
security / deny (push) Successful in 6s
security / audit (push) Successful in 8s
security / secrets (push) Successful in 8s
deploy: v0.82.1 — LGPD registry + credential erasure (#16)
2026-08-06 17:27:09 -03:00
.config ops(smtp): document sovereign relay (mail.autonomia.lat) + fix SMTP_URL → SMTP_HOST/… drift 2026-07-06 04:30:15 +00:00
.forgejo/workflows [SEC] storage: drop the cleartext CPF and voter registration (#15, contract) 2026-08-06 16:54:23 -03:00
.github/workflows [SEC] storage: drop the cleartext CPF and voter registration (#15, contract) 2026-08-06 16:54:23 -03:00
.sqlx [SEC] storage: protect identifiers at rest — encryption + a blind index (#15, phase 1) 2026-08-06 03:49:20 -03:00
brand feat(auth+federation): sovereign CPF+e-mail/senha auth (ADR-0008) and the ActivityPub federation foundation 2026-06-25 22:18:49 -03:00
crates [SEC] lgpd: erase the credential material that survived a deletion request (#16) 2026-08-06 17:23:49 -03:00
deploy deploy: v0.82.1 — LGPD registry + credential erasure (#16) 2026-08-06 17:27:09 -03:00
docs [SEC] federation: require HTTP-Signature verification on the Group/forum inbox (0.71.0) 2026-08-05 15:43:27 -03:00
migrations [SEC] storage: drop the cleartext CPF and voter registration (#15, contract) 2026-08-06 16:54:23 -03:00
scripts [SEC] db: give the federation/notes tables an org_id (#14, phase 1) 2026-08-06 00:50:53 -03:00
tests/e2e feat(consequence): SLA por gabinete — a cobrança vale pra todos os destinatários (0538) 2026-07-25 18:28:49 +00:00
web [ADD] link preview cards: a pasted YouTube link now shows its thumbnail (0680) 2026-08-05 22:56:07 -03:00
.dockerignore deploy: v0.67.0 rollout — manifest pin, ownership migration, lean docker context 2026-08-05 13:34:40 -03:00
.editorconfig chore: bootstrap sovereign participatory democracy platform (PINDORAMA) 2026-06-25 17:19:50 -03:00
.gitignore chore: remove arquivos de tooling interno e menções a fornecedores no texto de transparência 2026-08-05 12:26:36 -03:00
.gitleaks.toml ci: green the GitHub gate — sqlx offline cache regen, FK allowlist backfill, gitleaks policy 2026-08-05 12:48:00 -03:00
Cargo.lock [SEC] introduce a hardened outbound HTTP client (SSRF guard) (#9) 2026-08-05 21:36:39 -03:00
Cargo.toml [SEC] introduce a hardened outbound HTTP client (SSRF guard) (#9) 2026-08-05 21:36:39 -03:00
CHANGELOG.md [SEC] federation: require HTTP-Signature verification on the Group/forum inbox (0.71.0) 2026-08-05 15:43:27 -03:00
clippy.toml chore: bootstrap sovereign participatory democracy platform (PINDORAMA) 2026-06-25 17:19:50 -03:00
codecov.yml feat(agora): GitHub org split, mandatory GitOps, CI + coverage gates, Helm agora-core, dev compose 2026-08-05 12:39:39 -03:00
CONTRIBUTING.md [DOC] contributing: OCA tag convention for issues/commits/PRs + definition of done (full test pyramid) 2026-08-05 14:25:51 -03:00
deny.toml feat(federation): ator de instância + fetch assinado — busca federada em instâncias AUTHORIZED_FETCH (0539) 2026-07-25 20:32:34 +00:00
docker-compose.dev.yml feat(agora): GitHub org split, mandatory GitOps, CI + coverage gates, Helm agora-core, dev compose 2026-08-05 12:39:39 -03:00
LICENSE chore: bootstrap sovereign participatory democracy platform (PINDORAMA) 2026-06-25 17:19:50 -03:00
LICENSE-SOCIAL-CONTRACT.md chore: bootstrap sovereign participatory democracy platform (PINDORAMA) 2026-06-25 17:19:50 -03:00
PLAN.md docs(adr): ADR-0010 — civic-social platform; PLAN.md §3 scoped reversal 2026-06-26 13:23:16 +00:00
README.md feat(agora): GitHub org split, mandatory GitOps, CI + coverage gates, Helm agora-core, dev compose 2026-08-05 12:39:39 -03:00
rust-toolchain.toml chore: bootstrap sovereign participatory democracy platform (PINDORAMA) 2026-06-25 17:19:50 -03:00
rustfmt.toml chore: bootstrap sovereign participatory democracy platform (PINDORAMA) 2026-06-25 17:19:50 -03:00
SECURITY.md feat(0.28.1-contato): public contact form — no e-mail addresses exposed on the site 2026-07-10 20:32:38 +00:00

AGORA

Democratic infrastructure framework — deliberation, decision, and consequence, natively federated on the Fediverse. Stewardship: PopSolutions Software & Comunicação LTDA, a cooperatively managed company · License: AGPL-3.0-or-later (+ Social Contract)

CI Security codecov

AGORA is the framework: a country-agnostic, Rust-based engine for participatory democracy. Installations localize it. The reference installation is PINDORAMA (https://democracia.social.br), running AGORA with the Brazilian localization module agora-fed/l10n-brazil — ~70,000 real mandates (federal, state, municipal) indexed from official open data, each with a public accountability scorecard.

Thesis: Participation without consequence is theater. AGORA converts citizen demand into visible, time-bound, public accountability an elected official cannot silently ignore.

Framework AGORA — this repository (agora-fed/core), API and code 100% English
Localization l10n_<cc> modules — identity documents, territory, voter registry (ADR-0015); Brazil: l10n-brazil
Installation A deployment of core + one l10n module + a locale. PINDORAMA = core + l10n-brazil + pt-BR

The engineering north star is PLAN.md. The Fediverse strategy (where AGORA is heading as a federated network) is docs/FEDIVERSE-STRATEGY.md.


The core loop

propose ─▶ cluster (consensus) ─▶ vote ─▶ threshold ─▶ notify official ─▶ SLA clock ─▶ answered / public silence ─▶ scorecard
                                                                                              │
                                                                                              └─▶ auto-federated ActivityPub Note

Four subsystems make this not "Decidim in Rust" — they are the point:

Subsystem What it does
consensus Embeds proposals (pgvector), merges duplicates into one real signal
consequence Starts a public SLA clock; records answered / acted / ignored (write-once)
mandates Indexes officials & candidates (official open data) and onboards them via public e-mail
scorecard Permanent public record: promises vs delivery, answered vs ignored

On top of the loop, AGORA is a full ActivityPub citizen network: Mastodon-compatible client API (existing apps like Tusky/Elk/Ivory log in via OAuth), S2S federation with HTTP signatures, notes/polls/media/hashtags, feeds, forum Group actors (FEP-1b12), and an admin console with Mastodon-grade moderation (reports queue, domain blocks, invites, webhooks).

Architecture at a glance

  • Language: Rust (Axum + Tokio), Cargo workspace of ~23 tiered crates — the crate boundary is the ownership boundary; cross-crate effects flow only through the durable event log (events_log, Postgres) or the gateway (see PLAN.md §6).
  • DB: PostgreSQL + pgvector, accessed via sqlx (compile-checked where cached, runtime-checked at the gateway surface — no ORM, auditability is a requirement).
  • Auth: sovereign e-mail + password (Argon2id); per-country identity documents come from the active l10n module (ADR-0008, ADR-0015); optional national OIDC; session cookie + Mastodon OAuth bearer.
  • Front-end: Astro SSG + Svelte islands (web/), served by the gateway at the same origin (ADR-0009); PWA with Web Push (RFC 8291).
  • Federation: ActivityPub S2S + Mastodon client API (ADR-0005, ADR-0010).
  • Deploy: GitOps-only (docs/GITOPS.md) — Helm chart deploy/helm/agora-core, images from deploy/docker/, k3s IPv6-first reference environment (ADR-0002). Runbooks: docs/ops/.
  • Reliability/audit: CI on GitHub Actions + a self-hosted Forgejo runner — see docs/CICD.md.

Repository layout

See docs/PROJECT-STRUCTURE.md for the full annotated tree.

crates/
├── core/  db/  api-contract/        # Tier 0 — frozen contracts (single owner)
├── app/                             # shared AppState (ports: db, clock, storage)
├── platform/                        # Tier 1 — auth, notify, events, consensus,
│                                    #          moderation, admin, l10n-br*
├── gateway/                         # Tier 1 — the ONE public HTTP surface + worker
├── spaces/                          # Tier 2 — processes, assemblies, initiatives,
│                                    #          consultations, mandates (+ parties)
├── components/                      # Tier 2 — proposals, votes, comments, forums,
│                                    #          meetings, budgets, surveys,
│                                    #          accountability, consequence, scorecard
└── clients/                         # Tier 3 — federation SDK (ActivityPub)
web/                                 # Astro + Svelte front-end (SSG → gateway image)
migrations/                          # append-only SQL (GitOps applies them)
deploy/                              # docker/ k8s/ helm/ gitops/
docs/                                # architecture, ADRs, ops runbooks, wiki
scripts/                             # CI guards + data seeds
tests/                               # cross-crate integration harness

* platform/l10n-br is being extracted to agora-fed/l10n-brazil — the first standalone localization module.

Quickstart

Fast lane (Docker, nothing on the host)

docker compose -f docker-compose.dev.yml up --build
# gateway on http://localhost:8080 — API under /api/v1, web bundle at /

Developer lane (cargo on the host, DB in Docker)

docker compose -f docker-compose.dev.yml up -d db
export DATABASE_URL=postgres://dsoc:dsoc@localhost:55432/agora_dev
cargo sqlx migrate run --source migrations

# Guards the CI enforces (run before pushing):
cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
./scripts/check-crate-boundaries.sh && ./scripts/check-migration-numbers.sh \
  && ./scripts/check-fk-targets.sh && ./scripts/check-lints-optin.sh

cargo test --workspace --all-features

# Front-end:
cd web && npm install && npm test && npm run build

IPv6-first: every example binds to [::1]. IPv4 is an explicit fallback only.

Production

Production is GitOps-only: a release tag builds ghcr.io/agora-fed/core:<tag>, and a commit bumping image.tag in the installation values file is the deploy. No manual helm/kubectl — ever. Read docs/GITOPS.md.

Documentation

Language policy

All code, comments, identifiers, commits, and documentation in this repository are English (ADR-0013). Portuguese (or any other language) lives only in:

  1. localization modules (l10n-brazil carries pt-BR),
  2. installation-facing UI copy resolved per locale.

Contributing

See CONTRIBUTING.md. Conventional Commits; main is protected and every change lands through CI.

The agora-fed organization

  • agora-fed/core — this framework
  • agora-fed/l10n-brazil — Brazilian localization (CPF, voter registry, IBGE)
  • future: per-module plugin repositories (agora-module-*) once the module ABI stabilizes (see docs/FEDIVERSE-STRATEGY.md, wave 2)