{"slug": "aura-a-self-hosted-ai-agent-with-temporal-graph-memory-written-in-go", "title": "Aura – a self-hosted AI agent with temporal graph memory, written in Go", "summary": "Aura, a self-hosted, multi-user AI agent written in Go, ships as a single binary hosting the runtime, tools, CLI, Telegram gateway and embedded web cockpit, with each user getting their own memory database, workspace and sandbox. The default stack measured 7 GB of RAM with speech-to-text and text-to-speech running on a 16 GB mini PC as of 2026-09-02, and the project's latest tagged prerelease is v1.0.2-rc1, checked on 2026-10-03, while the edge branch tracks master. Aura defaults to DeepSeek-V4 Flash via OpenRouter and also supports a ChatGPT plan, a bundled llama.cpp server running Gemma 4 12B QAT, or Ollama, with the active profile hot-reloaded from cockpit settings without a restart.", "body_md": "**A local-first, provider-neutral AI agent platform — in Go.**\n\nAn agent for ongoing work: tools, document retrieval, temporal memory, scheduled jobs, and a web cockpit on infrastructure you control.\n\n[What is Aura?](#what-is-aura) · [Features](#key-features) · [Studio](#studio) · [Compare](#how-aura-compares) · [Architecture](#architecture-one-screen) · [Quick Start](#quick-start) · [Docs](#documentation) · [Development](#development)\n\nAura is a self-hosted, multi-user AI agent. Its Go binary hosts the runtime, tools, CLI, Telegram gateway, and embedded web cockpit; each person signs in to their own identity, with their own memory database, workspace and sandbox. Docker Compose runs Postgres, ArcadeDB, Garage, embedding, ingestion, web search, voice and the bundled integrations alongside it.\n\nThe model is chosen in the cockpit settings: OpenRouter (the default route), a ChatGPT plan, the bundled local llama.cpp server, or Ollama. Local storage does not make cloud inference offline: a cloud provider receives the context sent to its model; with a local server nothing leaves the host for inference.\n\n**Hardware:** a mini PC with 16 GB of RAM is enough. The default stack measured\n7 GB with speech-to-text and text-to-speech running on a 16 GB mini PC\n(2026-09-02). No local LLM runs by default: inference goes to the provider you choose.\n\n<sub>A real run on a local stack: Aura stores the fact in its memory graph, loads the deferred\n`task` tool and schedules the reminder; a new chat then answers from memory, with\nprovenance. Model replies were written by Claude through an OpenAI-compatible endpoint;\nwaiting time is trimmed.</sub>\n\n| **Language** | Go 1.27 | \n| **Tests** | Unit, property, race, leak, mutation, live integration, and browser tests | \n| **Test coverage** | Owned-surface aggregate **≥85%** , with package policies and separate live memory/sandbox coverage authorities | \n| **CI** | build/vet/lint · CodeQL · `-race` + goleak · db/ArcadeDB/embed integration · MUSR two-identity E2E · web lint/test/mutation/Playwright · critical mutation ≥70% killed | \n| **Persistence** | Postgres (sqlc, pgx) + ArcadeDB (graph memory, full-text + LSM vector index) + Garage (S3 object store) | \n| **Models** | Default DeepSeek-V4 Flash via OpenRouter; also a ChatGPT plan, the bundled llama.cpp server (Gemma 4 12B QAT, `localllm` profile) or Ollama. The active profile (provider, model, budgets) is hot-reloaded from the cockpit settings, no restart | \n| **Distribution** | `edge` tracks master;`v1.0.2-rc1` is the latest tagged prerelease checked on 2026-10-03. See Releases for current availability | \n\n- **Streaming agent loop** with shared step/time budgets and repeated-call controls to bound work.\n- **Deferred tools and `tool_search`** — discover tools and load their schemas when needed, including tools from mounted MCP servers.\n- **Adaptive reasoning router** — selects reasoning effort using the configured classifier and the active model's supported capabilities.\n- **Full host terminal + filesystem tools** — real operating power, with destructive-command approval gates and secret redaction.\n- **Graph-native memory** — facts, sources and validity windows in ArcadeDB; temporal paths return supporting evidence. Postgres-authoritative conversations have a derived recall projection and managed context compaction.\n- **Document retrieval** — indexed passages with source hashes and citations, plus access to the original file for calculations and whole-file tasks.\n- **Self-extension** — author and run skills, use bundled memory/PIM/WhatsApp integrations, and connect additional MCP servers.\n- **Scheduler and self wake-ups** — one`task` tool (`at | every | cron` ) for reminders and`agent_job` runs, with job policy, operator controls and outcomes delivered to the owning conversation.\n- **Per-identity sandbox** — a full-capability box per operator (opt-in`sandbox` profile; gVisor`runsc` on native Linux), with deliverables handed back over the channel (`send_file` ), never as a path.\n- **Multi-user** — Authula sign-in (password, plus a TOTP step for accounts enrolled in it), one isolated ArcadeDB database per identity enforced by the server, capability grants, and an admin audit view.\n- **Multi-channel** — CLI REPL, Telegram (voice/photo/docs/HITL), and a web cockpit over AG-UI/SSE with mid-turn steering, approvals, voice input/output, and live settings.\n- **Studio** — image and video generation, photo and video editing, and a multi-track video editor, all in the cockpit ([details](#studio) ).\n- **Bundled integrations** — calendar/e-mail (PIM MCP, OAuth providers), WhatsApp (unofficial client), web search through a bundled SearXNG, snapshot share links to a conversation, and Cloudflare remote access.\n\nThe cockpit's creative workspace, per identity.\n\n- \n**Generate images and video** from a prompt over OpenRouter's media models. The model\npicker shows each model's price (per image, per second or per million output tokens)\nand the estimated cost before you press Generate. Options cover resolution, aspect\nratio, seed, and duration and sound for video; advanced inputs take a start frame, an\nend frame and reference images from your library. Every generation lands in a\nsearchable history you can reuse or download. Generation needs the OpenRouter route.\n- \n**Edit photos and clips** in the browser: a photo editor (Filerobot) and a quick video\neditor (trim, crop, rotate, audio) for any image or clip in a chat or in the Garage\nlibrary.\n- \n**Multi-track video editor** :\n  - a video lane plus overlay lanes for titles and images, with transitions between clips;\n  - per-clip transform (fill, fit, crop, flip, rotate), adjustments (opacity, brightness, contrast, saturation, hue, blur), animations and speed;\n  - audio lanes for an uploaded sound, a recorded voice, a text read aloud, or the sound extracted from a clip, with noise reduction, fades and automatic ducking under speech;\n  - undo and redo, saved projects, a mobile layout, and an export rendered in the browser (video, or the audio alone as WAV).\n A generated video opens in the editor with one click.\n\nChecked on 2026-10-03 against each project's own documentation. Open WebUI and LibreChat are mature, much larger projects; this table shows where Aura differs, not that it is ahead.\n\n|  | Aura | Open WebUI | LibreChat | \n|---|---|---|---|\n| **Backend** | Go, one binary + Compose appliance | Python | Node.js | \n| **License** | MIT | Open WebUI License (BSD-3 up to v0.6.5; branding must stay above 50 users) | MIT | \n| **Long-term memory** | Temporal knowledge graph: facts with sources and validity windows, one ArcadeDB database per identity | Facts and notes the model can search and update | Memory with per-agent partitions | \n| **Scheduled work** | `task` tool (`at` ,`every` ,`cron` ) running full agent jobs | Scheduled prompts | Scheduled Chats (beta) | \n| **Tool approval (HITL)** | Yes | Not documented | Yes (v0.8.8) | \n| **Messaging channels** | Telegram, WhatsApp, e-mail/calendar | Not documented | Not documented | \n| **Video** | Generation plus a multi-track editor | Voice and video calls | Not documented | \n| **Single sign-on** | No: email/password (TOTP for enrolled accounts) | SSO/OIDC, LDAP, SCIM | OAuth2, SAML, LDAP | \n| **Community** | Small, one maintainer | Very large | Large | \n\nChoose Open WebUI or LibreChat for a polished multi-model chat front end with SSO and a large ecosystem. Choose Aura for a long-running personal agent that remembers over time, works on a schedule and reaches you on Telegram or WhatsApp.\n\n```\nTransport & UX     cmd/aura (CLI) · channels (+telegram) · agui (SSE) · webui (embedded SPA) · webauth (Authula) · setup · askuser\nAgent runtime      agent (LlmAgent, Budget, Events, hooks, workflow Seq/Par/Loop) · runner · swarm · steer\nTools & MCP        agent/tools (registry, deferred, tool_search, fs/shell/web/skill) · agent/mcptools · mcp (+manager) · mcpoauth · sandbox\nIntelligence       llm (+openai_compat) · chatgptplan · semindex (embed-index core) · reasoningtrace · scoring · multimodal · mediagen\nCapabilities       web · skills · cron · onboarding · documents · share · retention\nPersistence        db (Postgres+sqlc) · arcadedb (memory + retrieval) · conversations · identity · objectstore · secret · settings\nObservability      obs · agent/panicobs · reasoningtrace · toolinvocations · cachemetrics\n```\n\n| Doc | For | \n|---|---|\n| [docs/ARCHITECTURE.md](https://github.com/chetto1983/Aura/blob/master/docs/ARCHITECTURE.md) | How the system is built — layers, turn lifecycle, invariants | \n| [docs/TECHNICAL_OVERVIEW.md](https://github.com/chetto1983/Aura/blob/master/docs/TECHNICAL_OVERVIEW.md) | CTO / due-diligence overview — problem, differentiators, maturity | \n| [docs/CAPABILITIES.md](https://github.com/chetto1983/Aura/blob/master/docs/CAPABILITIES.md) | Capability matrix — shipped / in-progress / roadmap | \n| [docs/release-readiness.md](https://github.com/chetto1983/Aura/blob/master/docs/release-readiness.md) | How a release is cut — the twelve-report exact-SHA gate, rollback rule, operational checks | \n| [docs/BACKUP-RESTORE.md](https://github.com/chetto1983/Aura/blob/master/docs/BACKUP-RESTORE.md) | Backup schedules, recovery procedures, live validation and scope | \n| [CLAUDE.md](https://github.com/chetto1983/Aura/blob/master/CLAUDE.md) ·[prd.md](https://github.com/chetto1983/Aura/blob/master/prd.md) | Engineering guidance · product requirements (source of truth) | \n\nAura is a self-hosted agent runtime packaged as a Docker Compose appliance. The\ndefault stack brings up Aura (with its migration one-shot), Postgres, ArcadeDB and its\nMCP, Garage, the local embedding sidecar, document ingestion, SearXNG, speech-to-text\nand text-to-speech, the PIM and WhatsApp MCP sidecars, the Cloudflare tunnel\nsupervisor (idle until enabled), and Caddy in front of the Authula sign-in. Compose\nprofiles add the rest: `localllm` (a llama.cpp server with Gemma 4 12B QAT), `ocr`,\n`observability` (Prometheus, Tempo, Grafana) and `sandbox` (the Docker socket proxy\nfor per-identity boxes).\n\n**Releases.** `ghcr.io/chetto1983/aura:<tag>` and the binary archives are published by\nthe `Release` workflow on a `v*` tag, and only after the exact-SHA *Production\nReadiness* check passed for that commit ([docs/release-readiness.md](https://github.com/chetto1983/Aura/blob/master/docs/release-readiness.md)).\nCheck the\n[Releases page](https://github.com/chetto1983/Aura/releases) for the current tag\n(`v1.0.2-rc1` is the latest) and use it as `vX.Y.Z` below. Independently of\nreleases, every master push publishes the moving `ghcr.io/chetto1983/aura:edge`\nimage (plus an immutable `master-<sha>` tag) — the continuous-delivery channel a\ndefault install tracks.\n\nThe interactive installer supports local installation or a Linux target over SSH:\n\n```\nnpx create-aura-appliance\nnpx create-aura-appliance --mode remote\n```\n\nIt requires Node.js **22.13 or newer** on the workstation. The target needs at least\n**4 CPU cores, 14 GiB usable RAM, and 20 GiB free disk**; documents, models and backup\nretention need additional capacity. The installer detects the embedding backend on the\ntarget: CUDA for an NVIDIA GPU Docker can drive, otherwise Vulkan for an Intel or AMD GPU\nexposing `/dev/dri`, otherwise CPU. See the [installer guide](https://github.com/chetto1983/Aura/blob/master/packages/create-aura/README.md)\nfor supported targets and prerequisites. The npm installer carries its own payload.\n\nThe source-hosted installer remains available:\n\nInstall Docker, then run the installer. One command on a machine with Node 18+\n(`npx` fetches the repo and runs `scripts/install.sh`):\n\n```\nsudo npx github:chetto1983/Aura -- --appliance\n```\n\nor the curl equivalent of the same script — use `master` to track the edge\nchannel, or a release tag `vX.Y.Z` to pin:\n\n```\ncurl -fsSL https://raw.githubusercontent.com/chetto1983/Aura/master/scripts/install.sh | sudo bash -s -- --appliance\n```\n\nThe installer checks hardware, creates `.env` with generated `POSTGRES_PASSWORD`,\nthe three `ARCADEDB_*` secrets, and `AURA_ACCESS_TOKEN`, downloads the Compose/Caddy assets, and\nstarts the stack. Re-running it keeps an existing `.env` intact. A master/edge\ninstall points `.env` at the `:edge` moving tags, and `--appliance` also enables\nthe `aura-image-update` systemd timer: from then on the machine re-pulls aura and\nits MCP sidecars from GHCR on its own, migrations and Compose payload included, with\nno operator involved. Without `--appliance` (no systemd units, no timer), the stack still\nstarts; updates stay manual.\n\nThe default stack also starts the Cloudflare supervisor healthy-idle. Enable it after setup in\n**Settings > Remote access**; the installer requires no Cloudflare credential. Existing edge\nappliances receive the sidecar through the payload updater without replacing database volumes.\nSee [Cloudflare Remote Access](https://github.com/chetto1983/Aura/blob/master/docs/cloudflare-remote-access.md) for registered-domain prerequisites,\nAccess OTP, organization WARP, token refresh and safe disable/delete.\n\nAdd `--gvisor` on native Linux Docker hosts that should run Aura under `runsc`.\nDocker Desktop is intentionally not supported for that isolation tier.\n\nUse Docker Desktop and the shipped Compose files. From PowerShell in the Aura checkout or release directory:\n\n```\nfunction New-Hex { -join ((1..32) | ForEach-Object { '{0:x2}' -f (Get-Random -Maximum 256) }) }\n@\"\nPOSTGRES_PASSWORD=$(New-Hex)\nPOSTGRES_USER=aura\nPOSTGRES_DB=aura\nARCADEDB_PASSWORD=$(New-Hex)\nARCADEDB_APP_PASSWORD=$(New-Hex)\nAURA_ARCADEDB_TENANT_SECRET=$(New-Hex)\nAURA_IMAGE=ghcr.io/chetto1983/aura:vX.Y.Z\nAURA_ACCESS_TOKEN=$(New-Hex)\nAURA_AUTHULA_SECRET=$(New-Hex)\nSEARXNG_SECRET=$(New-Hex)\nAURA_OBJECTSTORE_ACCESS_KEY=GK$((New-Hex).Substring(0,24))\nAURA_OBJECTSTORE_SECRET_KEY=$(New-Hex)\nGARAGE_RPC_SECRET=$(New-Hex)\nAURA_GARAGE_ADMIN_TOKEN=$(New-Hex)\nAURA_BACKUP_DIR=./backups\nAURA_EMBED_REVISION=0f741b5a6585bd53aeb15cd1372c56f2a0f65e12\nAURA_EMBED_FINGERPRINT=b5ce9d77a3fc4b3b39ccb5643c36777911cc4eb46a66962eadfa3f5f60490d63\nAURA_EMBED_NGL=99\n\"@ | Set-Content -Path .env -Encoding ascii\n\ndocker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi\ndocker compose up -d\n```\n\nThis `.env` targets an NVIDIA GPU: the embedding sidecar reserves one, so fix\nDocker/NVIDIA before starting Aura if the `nvidia-smi` container check fails. Without\nan NVIDIA GPU, run embeddings on the CPU instead: set `AURA_EMBED_NGL=0` and\n`COMPOSE_FILE=compose.yaml;compose.cpu.yaml` (`;` is Compose's path separator on\nWindows), which drops the GPU reservation and selects the CPU build of the pinned\nllama.cpp server.\n\nThe model route, the OpenRouter key and the Telegram bot token are not `.env`\nsettings: choose them in the first-run web setup, and Aura keeps them in\n`aura.settings`. For local development images, replace `AURA_IMAGE` with\n`aura:local` after building the image.\n\nPostgres 18 is the default Compose image for new installs. When upgrading an\nexisting Aura deployment from Postgres 17, migrate the data with `pg_dump` /\n`pg_restore` or `pg_upgrade`; a Postgres 18 container cannot reuse a Postgres 17\ndata volume directly.\n\nAura listens on loopback; Caddy serves the cockpit on HTTPS at `https://<host>`, behind\nthe Authula sign-in. On a fresh install the sign-in page offers **Create first user**:\nthat account is the operator, and after signing in the cockpit's first-run setup\nfinishes the configuration. The Telegram bot is connected through the setup wizard,\ngated by the access token the installer prints:\n\n```\nhttps://<host>/setup/?token=<AURA_ACCESS_TOKEN>\n```\n\nCaddy uses `tls internal`. Browsers on other LAN machines will warn until they\ntrust the local CA root from the `caddy-data` volume:\n\n```\ndocker compose exec caddy cat /data/caddy/pki/authorities/local/root.crt > aura-caddy-root.crt\n```\n\nTrust on the Ubuntu server does not make remote browsers trust that CA. Cloudflare named-tunnel hostnames use the public edge certificate; direct port 443 bypasses Cloudflare Access and retains Authula. Quick Tunnels are temporary testing only and cannot validate Aura chat because they do not support SSE.\n\nAn edge appliance installed with `--appliance` updates itself: the\n`aura-image-update.timer` (5-minute cadence, flock-guarded) pulls the moving\ntags and recreates only what changed, running migrations first. The aura image\nalso carries the installation payload — the Compose files, the updater and its\nunits, the sidecar configuration — and each tick installs whatever differs from\n`/opt/aura` (backing up what it replaces under `backups/payload-*`) and brings\nthe whole stack up on it. A version pin changed in `compose.yaml` therefore\nreaches every appliance on its own. `sha256sum -c payload_manifest.txt` inside\n`/opt/aura` shows whether a host matches its payload. Watch it with\n`journalctl -u aura-image-update.service -f`.\n\nManual update (pinned installs, or no systemd). Volumes persist, and the\n`aura-migrate` one-shot runs the Postgres migrations before the Aura service\nstarts (ArcadeDB needs none — the MCP creates each identity's database on first\nuse):\n\n```\ndocker compose pull\ndocker compose up -d\n```\n\nScheduled backups run inside the socketless Aura box. Postgres is dumped over the\nCompose network with `pg_dump` into `AURA_BACKUP_DIR`:\n\n```\n./backups/postgres-YYYYMMDDTHHMMSSZ.dump\n```\n\n**Memory is backed up automatically.** ArcadeDB loads\n[`docker/arcadedb/backup.json`](https://github.com/chetto1983/Aura/blob/master/docker/arcadedb/backup.json) and backs up every\ndatabase every 60 minutes, including newly-created identity databases. Archives\nlive in the separate `aura-arcadedb-backups` volume. The configuration sets\n`maxFiles=60` and tiered hourly/daily/weekly/monthly retention of 24/7/4/6.\n\nThe database and backup volumes are separate, but both are on the same host by default. Preserve off-host copies and the deployment configuration separately. Garage objects, workspaces, and other runtime files need their own backup policy.\n\nRun the restore drill against the current Compose stack:\n\n```\nset -a\n. ./.env\nset +a\nscripts/restore_drill.sh\n```\n\nThe drill tests four planes: Postgres, conversation sidecars, Garage and an\nArcadeDB database shaped like a tenant. It verifies restored checksums and cleans\nup its disposable resources. All four passed on 2026-09-07. A separate restore\nof an existing scheduled operator-memory archive recovered 93 entities, 75 facts\nand 40 mentions, including a historical fact. This is a dated recovery check,\nnot a complete host-loss rehearsal or an RPO/RTO guarantee. See\n[Backup and restore](https://github.com/chetto1983/Aura/blob/master/docs/BACKUP-RESTORE.md) for scope and evidence.\n\nManual restore commands:\n\n```\ndocker compose exec -T -e PGPASSWORD=\"$POSTGRES_PASSWORD\" postgres \\\n  pg_restore -U \"${POSTGRES_USER:-aura}\" -d \"${POSTGRES_DB:-aura}\" \\\n  --clean --if-exists --no-owner --no-acl /backups/postgres-YYYYMMDDTHHMMSSZ.dump\n```\n\nTake a fresh backup before restoring over a live database.\n\nThe `whatsapp` service is part of the default stack, mounted through Aura's MCP catalog.\nIt uses an unofficial whatsmeow-based client, so it carries WhatsApp Terms of Service and account-ban risk. First pairing is headless:\n\n```\ndocker compose logs -f whatsapp\n```\n\nScan the QR code shown in the logs. Aura boot never depends on this service.\n\nThe host needs no Python MCP runtime at all: memory is served by Aura's own ArcadeDB MCP, a Go binary in the image. Old host-level Python installs and the earlier WSL WhatsApp MCP install can be removed after migrating to the Compose appliance.\n\n```\naura serve                    run the long-lived agent runtime (channels, cockpit, scheduler)\naura shell | chat <sub>       interactive REPL / chat conversations against the agent loop\naura doctor | config <sub>    environment diagnostics / effective configuration\naura agent dry-run            drive a mock LoopAgent through the Budget tree\naura tools                    print the tool manifest\naura task <sub>               operator parity with the model-facing `task` tool:\n                              schedule | list | cancel | run_now | approve | runs | doctor\naura mcp <sub>                managed MCP servers: install | add | list | doctor | tools | enable | disable | remove\naura memory <sub>             ArcadeDB memory administration\naura identity <sub>           identities, capability grants, operator break-glass recovery\naura gateway grants <sub>     AG-UI gateway approval grants\naura paused-states <sub>      HITL pauses\naura skills <sub> | pack <sub> skill lifecycle · packs: list | show | install | trust\naura retention <plan|apply>   retention sweep\naura db <sub>                 Postgres lifecycle: migrate | ping | status | reset\naura objectstore <sub>        Garage object-store administration\naura web <doctor|tool ...>    web tools (search/fetch) from the CLI\naura docs <sub>               document ingestion\naura version                  build metadata\n```\n\nFor source builds, install Go from [`go.mod`](https://github.com/chetto1983/Aura/blob/master/go.mod), Docker, and a POSIX shell.\nLinux is the supported source-build and quality-gate runtime. On Windows, use WSL;\nthe native Windows Go binary is not a release target because Windows ACLs are not\nrepresented by POSIX `FileMode` bits. Docker Desktop remains supported for running\nthe shipped Linux Compose appliance.\n\n```\ngit clone https://github.com/chetto1983/Aura.git\ncd Aura\ncp .env.example .env\nmake tools\nlefthook install\nmake db-migrate memory-up\ngo run ./cmd/aura version\ngo run ./cmd/aura agent dry-run --request-id auto\n```\n\nTo run a local source build instead of a published image, build\nthe image and point `.env` at it (the image builds\n`web/` in its own stage; the committed `internal/webui/dist` only feeds a host `go build`\nand is refreshed from that stage, never from a host `vite build`):\n\n```\ndocker build -f docker/aura/Dockerfile -t aura:local .\n# then in .env:  AURA_IMAGE=aura:local\n```\n\nQuality gates:\n\n```\nmake quality\nmake db-migrate memory-up\nmake quality-full\n```\n\n| Target | Does | \n|---|---|\n| `make tools` | install the quality toolchain | \n| `make lint` /`make vet` | lint and `go vet` | \n| `make vuln` | `govulncheck` supply-chain scan | \n| `make test-race` | `go test -race ./...` | \n| `make coverage` | owned-surface coverage floor | \n| `make restore-drill` | four-plane restore drill (Postgres, sidecars, Garage, ArcadeDB) | \n\n```\ncmd/aura/                CLI entry and subcommands\ncmd/arcadedb-mcp/        Aura's own ArcadeDB memory MCP server\ncmd/aura-*/              sidecar binaries (Cloudflare and ingest supervisors, media index, file cards)\ninternal/                the runtime, one package per concern (see Architecture)\nweb/                     React cockpit, embedded into the binary from internal/webui/dist\nservices/ingest/         document ingestion sidecar\npackages/create-aura/    the npx installer (create-aura-appliance)\ndocker/ deploy/ caddy/   image builds, systemd units and the updater, Caddy front door\nscripts/                 install, smoke, restore drill, coverage, file-size cap\ndocs/                    architecture, capabilities, release and backup guides\n.planning/               GSD planning artifacts\n```\n\nAura is PRD-first. Persistence is Postgres plus an ArcadeDB graph, with graph access\nthrough MCP for model-facing tools. The default packaged deployment keeps Aura\nsocketless: no Docker socket is mounted into the Aura container. The opt-in `sandbox`\nprofile reaches Docker only through a socket proxy that allows the box lifecycle verbs.\n\nSee [`CONTRIBUTING.md`](https://github.com/chetto1983/Aura/blob/master/CONTRIBUTING.md). Report vulnerabilities privately per\n[`SECURITY.md`](https://github.com/chetto1983/Aura/blob/master/SECURITY.md), never in a public issue.\n\n[MIT](https://github.com/chetto1983/Aura/blob/master/LICENSE) Copyright 2026 Davide Marchetto.", "url": "https://wpnews.pro/news/aura-a-self-hosted-ai-agent-with-temporal-graph-memory-written-in-go", "canonical_source": "https://github.com/chetto1983/Aura", "published_at": "2026-10-04 08:42:20+00:00", "updated_at": "2026-10-04 09:11:58.710690+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "ai-products", "agent-protocols", "artificial-intelligence"], "entities": ["Aura", "Go", "OpenRouter", "DeepSeek-V4 Flash", "llama.cpp", "Gemma 4 12B QAT", "Ollama", "ArcadeDB"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/aura-a-self-hosted-ai-agent-with-temporal-graph-memory-written-in-go", "markdown": "https://wpnews.pro/news/aura-a-self-hosted-ai-agent-with-temporal-graph-memory-written-in-go.md", "text": "https://wpnews.pro/news/aura-a-self-hosted-ai-agent-with-temporal-graph-memory-written-in-go.txt", "jsonld": "https://wpnews.pro/news/aura-a-self-hosted-ai-agent-with-temporal-graph-memory-written-in-go.jsonld"}}