Skip to main content

citadeldb-haystack

A Haystack DocumentStore backed by Citadel. Encrypted at rest, embedded in your process, and deletes that destroy the key, not just the row.

pip install citadeldb-haystack sentence-transformers

Requires citadeldb>=2.2,<3 and haystack-ai>=2.9,<4. Set CITADEL_KEY before running the example. The embedding model downloads on first use and runs locally.

from haystack import Document
from haystack.components.embedders import SentenceTransformersTextEmbedder
from haystack.utils import Secret
from citadeldb_haystack import CitadelDocumentStore

embedder = SentenceTransformersTextEmbedder(model="sentence-transformers/all-mpnet-base-v2")
store = CitadelDocumentStore(
    "corpus.cdl",
    Secret.from_env_var("CITADEL_KEY"),
    embedder=embedder,
    dim=768,
    embedding_similarity_function="cosine",
)
store.write_documents([
    Document(id="d1", content="The deployment failed because the disk was full.",
             meta={"chapter": "intro"}),
])
store.filter_documents({"field": "meta.chapter", "operator": "==", "value": "intro"})

dim defaults to 768 and must match your embedding model. embedding_similarity_function is "cosine" or "dot_product" and is persisted with the store. It defaults to Haystack's "dot_product"; choose "cosine" explicitly when that is what produced the supplied vectors. Embedders exposing model_id, model, or model_name record that identity automatically, in that order. For a custom component without any of those attributes, pass a stable model_id= explicitly; Citadel refuses to guess from the Python class name.

Pipeline serialization

Use a Haystack environment-variable Secret for pipeline serialization. Literal passphrases cannot be serialized:

CitadelDocumentStore(
    "literal.cdl", "literal-passphrase", embedder=embedder, dim=768
).to_dict()
# ValueError: Cannot serialize token-based secret.

CitadelDocumentStore(
    "corpus.cdl", Secret.from_env_var("CITADEL_KEY"), embedder=embedder, dim=768,
    embedding_similarity_function="cosine",
).to_dict()
# {... "key": {"type": "env_var", "env_vars": ["CITADEL_KEY"], ...}}

Use Secret.from_env_var for any store that goes into a saved pipeline.

Deletes destroy the key

Every document is sealed under its own key. Deleting destroys that key and removes the row. Pre-erasure backups or snapshots containing keys, and exported plaintext, are outside that erasure.

store.delete_documents(["d1"])
store.delete_all()  # returns the number erased

DuplicatePolicy.NONE is treated as FAIL: duplicate ids are rejected.

Retrieval

embedder.warm_up()
query_embedding = embedder.run(text="Why did the release break?")["embedding"]

store.embedding_retrieval(
    query_embedding,
    top_k=5,
    filters={"field": "meta.chapter", "operator": "==", "value": "intro"},
    scale_score=False,
    return_embedding=False,
)

Filters use Haystack's evaluator. Top-level AND string equalities, including nested paths such as meta.person.name, are passed to Citadel as payload filters. Other predicates filter ranked candidates; the search window expands until top_k matches survive or the region is exhausted.

Notes

The store requires a Haystack text embedder. Documents that arrive without a vector are embedded with it, while vectors already supplied by the pipeline are stored as-is. Pass the same model to the pipeline and store so both paths remain in one vector space. The store warms the embedder lazily before its first model call and includes its configuration in pipeline serialization.

Citadel is embedded and one process owns the file. A path already open on this thread, under the same passphrase, is shared, so this can sit on the same database as another Citadel adapter; construct them on the same thread.

License

Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

citadeldb_haystack-2.3.0.tar.gz (14.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

citadeldb_haystack-2.3.0-py3-none-any.whl (9.2 kB view details)

Uploaded Python 3

File details

Details for the file citadeldb_haystack-2.3.0.tar.gz.

File metadata

  • Download URL: citadeldb_haystack-2.3.0.tar.gz
  • Upload date:
  • Size: 14.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for citadeldb_haystack-2.3.0.tar.gz
Algorithm Hash digest
SHA256 38b882c7bb0ee15c72090f6aede505be028ed681a1dda94f12a02ceb858dcb09
MD5 c5e80ef784a95d71f5c79bc745809d38
BLAKE2b-256 0a2780e37f345a511f47bcd9922ff437bb284b5ede44ff617a26b7e2d3eb2d11

See more details on using hashes here.

Provenance

The following attestation bundles were made for citadeldb_haystack-2.3.0.tar.gz:

Publisher: release-haystack.yml on yp3y5akh0v/citadel

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file citadeldb_haystack-2.3.0-py3-none-any.whl.

File metadata

File hashes

Hashes for citadeldb_haystack-2.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c776ed9e2d70a31f814c4e6a8d37df44816f9ae29e7ee63125ed0c6c8215db6c
MD5 9f3353a81faf9cba8f55aed5689baf5b
BLAKE2b-256 dd0d2906b55cc9eefd3739f912c7f2e06a7adbcc50ca65440d9772698ff47c85

See more details on using hashes here.

Provenance

The following attestation bundles were made for citadeldb_haystack-2.3.0-py3-none-any.whl:

Publisher: release-haystack.yml on yp3y5akh0v/citadel

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

2.4.0

2 files

This release

2.3.0 This release

2 files

2.2.0

2 files

2.1.0

2 files

2.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page