Install & build

Roteiro is a Rust workspace (MSRV 1.96). Install the lean default build from crates.io, or build from source with the feature tiers you want.

# Lean default build — pure Rust, no network call of its own,
# and `roteiro model pull` included (--locked uses the published lockfile)
cargo install roteiro --locked

# Pin a specific release
cargo install roteiro@1.1.0 --locked

# Pick the capabilities you want
cargo install roteiro --features "inference,mcp" --locked

# Everything on — MCP, serving, local models, PDF/OCR/vision.
# Needs a C/C++ toolchain (the inference-local-models/serve/image-vision features build llama.cpp).
cargo install roteiro --all-features --locked

# …or build from source
git clone https://github.com/OffeneDatenmodellierung/Roteiro
cd Roteiro
cargo build --release --all-features

Feature tiers

FeatureAdds
(default)Graph build, query, check, render, the roteiro model registry, and roteiro security ingest|list|prefetch|status|run — smallest binary, no C++/cmake toolchain, and no network call unless you consent to a pull or a prefetch --allow-download.
inferenceroteiro infer / duplicates with a pure-Rust hashing embedder. Still fully offline; no download.
models (default)The roteiro model registry: list and consent-gated pull of local models. On by default — pull is the prerequisite for working offline, so a stock install has it.
inference-local-modelsRun pulled GGUF embedding & generative models via the shared llama.cpp engine.
pdf-text · image-ocr · image-visionIngest text from PDFs, OCR text from images, and describe images with a local vision model.
exec-subprocess (default)Runs an analyzer (semgrep, osv-scanner, cargo audit) as a child process on this host. You install the analyzer; Roteiro never does. security run is sandboxed by default, so a build without exec-boxlite refuses and tells you how to get one; --allow-unsandboxed is how you choose this host instead, and it records isolation=none. Use --no-default-features --features execution for a build that provisions and ingests but cannot execute.
exec-boxliteThe same analyzers inside a digest-pinned OCI image in a microVM — read-only worktree, no egress. Needs protoc and a provisioned runtime; see the README.
serveAn OpenAI-compatible /v1 model endpoint over your installed models (llama.cpp).
remoteThe one feature that can send your repository's content off this machine — roteiro remote status|dry-run|call|log against a hosted model, plus spec draft --allow-remote and serve --allow-remote (Ask), which take the same gate (ADR-0019). Off by default and staying off. Compiling it does not enable it: a run needs your ~/.roteiro/config.toml and the invocation, and a committed roteiro.toml may deny it but never grant it. Read the note on the home page before turning it on.
mcpThe MCP graph server, exposing the graph to AI agents (stdio or HTTP).
--all-featuresEvery capability above at once — the largest build. Requires a C/C++ toolchain because the serving and vision features compile llama.cpp. This includes remote, so such a build can call a hosted model once you grant it in your user config and per run; it still cannot without both.