Skip to main content

citadeldb-haystack

A Haystack DocumentStore backed by Citadel. Encrypted at rest, embedded in your process, and deletes that destroy the key, not just the row.

Passes deepset's own DocumentStoreBaseTests conformance suite.

pip install citadeldb-haystack
from haystack import Document
from haystack.components.embedders import SentenceTransformersTextEmbedder
from haystack.utils import Secret
from citadeldb_haystack import CitadelDocumentStore

embedder = SentenceTransformersTextEmbedder()
store = CitadelDocumentStore(
    "corpus.cdl",
    Secret.from_env_var("CITADEL_KEY"),
    embedder=embedder,
    dim=768,
    embedding_similarity_function="cosine",
)
# CITADEL_KEY must be set: an env-var secret is what lets a pipeline serialize.

store.write_documents([Document(id="d1", content="...", meta={"chapter": "intro"})])
store.filter_documents({"field": "meta.chapter", "operator": "==", "value": "intro"})

dim defaults to 768 and must match your embedding model. embedding_similarity_function is "cosine" or "dot_product" and is persisted with the store. It defaults to Haystack's "dot_product"; choose "cosine" explicitly when that is what produced the supplied vectors. Embedders exposing model_id, model, or model_name record that identity automatically, in that order. For a custom component without any of those attributes, pass a stable model_id= explicitly; Citadel refuses to guess from the Python class name.

The passphrase never lands in a pipeline file

The passphrase is a Haystack Secret. Pipelines are serialized to disk, and a literal token refuses to serialize, so a passphrase cannot be written into a pipeline by accident:

CitadelDocumentStore(
    "literal.cdl", "literal-passphrase", embedder=embedder, dim=768
).to_dict()
# ValueError: Cannot serialize token-based secret.

CitadelDocumentStore(
    "corpus.cdl", Secret.from_env_var("CITADEL_KEY"), embedder=embedder, dim=768
).to_dict()
# {... "key": {"type": "env_var", "env_vars": ["CITADEL_KEY"], ...}}

Use Secret.from_env_var for any store that goes into a saved pipeline.

Deletes destroy the key

Every document is sealed under its own key. Deleting destroys that key and then removes the row, so any ciphertext surviving elsewhere stays unreadable.

store.delete_documents(["d1"])
store.delete_all()  # returns the number erased

DuplicatePolicy.NONE falls back to FAIL, as InMemoryDocumentStore does, so an accidental re-write is reported rather than silently replacing a document whose key would then be destroyed.

Retrieval

query_embedding = [0.0] * 768  # from your Haystack text embedder, `dim` wide

store.embedding_retrieval(
    query_embedding,
    top_k=5,
    filters={"field": "meta.chapter", "operator": "==", "value": "intro"},
    scale_score=False,
    return_embedding=False,
)

Filtering uses Haystack's own evaluator, so the whole filter language, date comparisons included, matches InMemoryDocumentStore operator for operator. top_k is top_k: a filter matching only distant documents still returns them, however many others outrank them.

A top-level AND of string equality conditions is pushed into the scan, including nested paths like meta.person.name. Everything else is evaluated afterwards, so the two agree: nothing is pushed under OR or NOT, and numbers are not pushed either, because == here is Python's (1 == 1.0) where the stored comparison is JSON-type exact.

Notes

The store requires a Haystack text embedder. Documents that arrive without a vector are embedded with it, while vectors already supplied by the pipeline are stored as-is. Pass the same model to the pipeline and store so both paths remain in one vector space. The store warms the embedder lazily before its first model call and serializes it, so pipeline round-trips retain the model instead of reopening with a hidden fallback.

Citadel is embedded and one process owns the file. A path already open on this thread, under the same passphrase, is shared, so this can sit on the same database as another Citadel adapter; construct them on the same thread.

License

Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

citadeldb_haystack-2.1.0.tar.gz (14.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

citadeldb_haystack-2.1.0-py3-none-any.whl (9.2 kB view details)

Uploaded Python 3

File details

Details for the file citadeldb_haystack-2.1.0.tar.gz.

File metadata

  • Download URL: citadeldb_haystack-2.1.0.tar.gz
  • Upload date:
  • Size: 14.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for citadeldb_haystack-2.1.0.tar.gz
Algorithm Hash digest
SHA256 23450d2e05f98b6be6574a10bee81e2d79b96fdba9271d115d127894b375156d
MD5 e1971638c7446f6f8fb54cb9ea3a7cf7
BLAKE2b-256 143111e9e6293cac6821e1849134e96286dd37efbc2d0fd968bc2ba582e51404

See more details on using hashes here.

Provenance

The following attestation bundles were made for citadeldb_haystack-2.1.0.tar.gz:

Publisher: release-haystack.yml on yp3y5akh0v/citadel

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file citadeldb_haystack-2.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for citadeldb_haystack-2.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a319fe232842dd56ed1d7c1d284aa02af8c66c843d4c54b1f7705772b28386af
MD5 4a8f978d66c18fa12ff63767586ade27
BLAKE2b-256 af28d2e87a3716aa3ab3c9f4093d588d54b40134fcae0e3b4f88c393e82f9988

See more details on using hashes here.

Provenance

The following attestation bundles were made for citadeldb_haystack-2.1.0-py3-none-any.whl:

Publisher: release-haystack.yml on yp3y5akh0v/citadel

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

2.4.0

2 files

2.3.0

2 files

2.2.0

2 files

This release

2.1.0 This release

2 files

2.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page