Quivr V2 turns a document stream into search and alerts
Quivr V2 accepts articles and documents, stores their canonical bytes, and builds a search projection around them. Saved queries can turn new matches into signed webhook deliveries. The core also exposes polling, resumable server-sent events, a command-line search client, and MCP tools that let an agent search a corpus while retaining Record, Version, Part, and excerpt offsets for citations. The API is v0, and the README says it may change without notice.
The interesting choice is durability before indexing. PostgreSQL 17 records the catalog, receipts, and changes, while S3-compatible storage holds canonical bytes and artifacts. Weaviate is a rebuildable lexical and vector projection rather than the final authority. Every accepted write has an idempotency key, and a correction creates a new immutable Version. A search result is rehydrated from canonical storage and checked for access again before Quivr returns it.
The 5-service runtime is the real installation
Our checkout was only 21 MB, but a working local stack spans PostgreSQL, S3-compatible SeaweedFS, Temporal, Weaviate, and a TEI embedding service. The quickstart says its first run downloads pinned images plus roughly 1 GB for the multilingual E5 model. It also asks for Go 1.27.1, Docker Compose v2, Python with venv, Node.js 22 or newer, and jq. That is platform work, not a single-binary trial.
The quivr binary does combine API, worker, and migration commands. make dev starts dependencies and generates throwaway local keys, while make verify creates an isolated stack and writes a report naming failed steps and pinned versions. Our source scan found 9 CI workflow files and a tests directory, but no Dockerfile. Release images are documented on GHCR, so deployment users should follow those published-image instructions rather than expect a root Dockerfile.
What happened when we ran it
Our run installed commit 85a8a74 in 22 seconds and added 168 Go packages. The build completed in 80 seconds. Tests finished in 34 seconds with 86 passed and 0 failed out of 86. Our method used a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, Go 1.24, and no secrets. The successful result covers repository mechanics, not the Docker Compose journey or search quality.
The repository itself is substantial: 2,154 files, about 237,105 lines of source, and 21 MB checked out. Those figures help explain the 80-second build even though the Go dependency step was quick. We did not start PostgreSQL, Temporal, Weaviate, SeaweedFS, or TEI, and we did not ingest a corpus. No latency, throughput, alert accuracy, or ranking claim can be drawn from this run.
Evaluation status outweighs the green 86-test result
The README labels Quivr V2 an evaluation-stage project and says not to run it in production. That warning carries more weight than a clean 86-test sandbox run. The public API remains v0, and the latest GitHub release returned by the API is core-0.0.33, published on February 4, 2025. It predates the current V2 status text and cannot serve as proof that this architecture has a stable production release.
The tracked limits make the warning concrete. Full make verify, retrieval measurement, and evaluation run only on Linux AMD64. Linux ARM64 and Intel Macs are not claimed. The acceptance suite is order-sensitive and load-sensitive. Search currently duplicates each enriched segment as lexical and enriched objects, making the lexical index about twice as large and slightly changing BM25 term weighting until enrichment catches up.
Plugin contracts are stronger than arbitrary extension points
Quivr defines connector, normalizer, enrichment, retrieval, subscription, and delivery behavior through versioned plugin contracts. The repository includes Go and Python SDKs, a contract runner, scaffolding, and first-party plugins for feeds, X lists, PDF text, alerts, ingestion, and retrieval. Plugin calls can use 60-second HS256 tokens bound to the operation and request body. Operators can register and switch compatible plugin versions without restarting the engine.
That structure does not make every format automatic. The bundled PDF plugin extracts text one page at a time but has no OCR, so scanned pages remain blank with warnings. Described alerts need a TypeSafe key and send article text outside the deployment. A local vector-based meaning check avoids that external classifier, but it is a different matching mode. Connector credentials also require a configured encryption key or deposits fail with a 503 response.
October activity is current, but readiness remains explicit
GitHub showed 39,578 stars and 11 open issues and pull requests on October 6, 2026. The API list split that queue into 9 issues and 2 pull requests, and the repository was pushed the same day. Some open reports refer to the older Python application rather than the V2 Go architecture, so the combined count should not be read as 9 confirmed V2 defects. The current pull requests and same-day push do show active work.
Quivr is a credible codebase for evaluating a durable monitoring engine because our 86 tests passed and its documentation lists specific limits instead of hiding them. The production answer is still no, in the maintainers' own words. Use the evaluation period to prove one corpus, one connector, and one alert path on Linux AMD64 before you accept the cost of the full 5-service stack.

