DL
Daniel LeoneActive
SWE & ML Systems
Backend & Agentic Infrastructure•Live in Production

Inventory Audit API & MCP Server

A production-grade inventory auditing and variance tracking engine built with FastAPI, SQLAlchemy 2, Alembic, and PostgreSQL 16. Designed with pure functional domain logic, fail-closed security, and native Model Context Protocol (MCP) tooling for AI pair programmers.

⚡ Live Swagger API Docs
MCP Server:mcp.leonegroupholdings.com/mcp
GitHub Repository

🌐 Production Deployment Topology

Zero Downtime Keepalive Active
EDGE INGRESS & PROXY
Cloudflare Proxy & DNS

Enforces HTTPS, TLS 1.3, DDoS protection, and forwards real visitor IPs via CF-Connecting-IP for precision rate-limiting.

APPLICATION RUNTIME
Railway Container Services

Hosts two distinct containerized services: the primary REST API service and the read-only HTTP MCP JSON-RPC service.

MANAGED PERSISTENCE
Supabase PostgreSQL 16

Managed database with connection pooling, automated Alembic migrations, and Row Level Security enabled across all tables.

Key Architectural Pillars

01. Pure Functional Rule Engine

Deterministic Discrepancy Auditing

All warehouse inventory decision logic lives in decide_audit(), a pure, side-effect-free function with zero database dependencies. If a cycle count discrepancy occurs while an inbound purchase shipment is in transit, the system holds the audit rather than prematurely declaring lost stock.

02. Cumulative Variance Reporting

SQL Window Functions

Warehouse managers track stock drift over time using optimized SQL window queries (SUM(variance_quantity) OVER (PARTITION BY item_id ORDER BY created_at)). Enables real-time shrink detection and bin reconciliation.

03. Fail-Closed Security & Hardening

Token Buckets & Row Level Security

Write operations require API key authentication that fails closed. Unauthenticated requests are throttled at exactly 120 allowed / 80 blocked per burst. All database tables enforce PostgreSQL Row Level Security (RLS) to prevent unauthorized Data API exposure.

04. Agentic Tooling

Model Context Protocol (MCP)

Exposes structured read-only tools (list_open_audits, get_variance_report, explain_audit) to AI coding agents (Claude Code, Antigravity) via a lightweight client over HTTP.

Quality Assurance & Test Verification
ComponentSpecificationMeasured ResultVerification
Unit & Integration TestsPytest against isolated PostgreSQL DB159 passing testsPassed
Code Coverage FloorCI fails below 95% coverage99.82% coverageEnforced in CI
Rate-Limiting Verification120 requests/min token bucket120 allowed / 80 blockedLive Measured
Database Row Level SecurityRLS enabled on all public tablesAll 6 tables trueSQL Confirmed