Architecture & Production Reference

Core Architecture• 4 min read• Updated 2026-09-15

In-depth technical architecture of dewDrive. Covers 17 monorepo applications, multi-engine backup runtimes (Restic & Kopia), NATS JetStream binary IPC, YugabyteDB, and Zitadel IAM.

dewDrive is an enterprise hybrid web and desktop backup and disaster recovery platform utilizing multi-engine backup runtimes (Restic 0.19.1 & Kopia), NATS JetStream binary IPC, YugabyteDB distributed SQL with PostgREST 12, Zitadel IAM OIDC PKCE authentication, and Next.js 16 / Tauri 2.0 cockpits.


1. Monorepo Applications Matrix (17 Apps)

🖥️ Desktop Cockpits (Tauri 2.0 + React 19)

  • apps/dewdrive: Desktop Ingestion Cockpit GUI (dual-ring progress indicators, local vault configuration, system tray, hosts dewdrive-agent-watchdog).
  • apps/dewrewind (dewRewind): Standalone Disaster Recovery & Snapshot Restoration Cockpit GUI (visual card-stack file restore, point-in-time snapshot recovery).

🤖 Local Desktop Client Micro-Daemons (apps/dewdrive-agent-*)

Embedded NATS JetStream (Port 34222, fallback 4222) / WebSocket (Port 9224) with Protobuf binary serialization:

  • apps/dewdrive-agent-backup-worker: Multi-engine backup execution daemon (Restic 0.19.1 + Kopia, VSS snapshots, Protobuf progress stream on daemon.progress.events). Token refresh via universal /api/auth/token.
  • apps/dewdrive-agent-rmm: 24/7 hardware & system telemetry collector with 4-mode governor (AC Standard, Battery Eco, Spectator Turbo, Emergency Forensics). Publishes to telemetry.node.<node_id>.
  • apps/dewdrive-agent-elevated-helper (Root/SYSTEM): Privileged helper for VSS shadow copies and GPL-isolated smartctl 7.4 disk diagnostics.
  • apps/dewdrive-agent-db-writer: Dedicated single-writer SQLite persistence daemon consuming db.write.* streams to prevent SQLite concurrency lockouts.
  • apps/dewdrive-agent-updater-monitor: Process supervisor, health watchdog (heartbeat.*), and atomic binary hot-swapper (apply.update).

☁️ Cloud Microservices & APIs (apps/dewdrive-cloud-*)

  • apps/dewdrive-cloud-rmm (Port 3005): 24/7 Cloud Remote Monitoring & Management hardware telemetry ingestion (Axum + PostgreSQL).
  • apps/dewdrive-cloud-restic-vault-helper (Port 7842): Standalone Restic Secure Vault maintenance (prune, forget, check, lock monitor) & file viewer API (Axum + HTMX).
  • apps/dewdrive-cloud-restic (Port 7843): Central Cloud Restic Ingestion Control API & coordinator.
  • apps/dewdrive-cloud-kopia-vault-helper (Port 7844): Standalone Kopia Secure Vault maintenance & manifest viewer API.
  • apps/dewdrive-cloud-kopia (Port 7845): Central Cloud Kopia Ingestion Control API & coordinator.

🌐 Web Consoles & Marketing (Next.js 16 / React 19)

  • apps/web-reseller-console (Port 3000): White-label multi-tenant reseller management portal (reseller.v1.dewdrive.com).
  • apps/web-master-console (Port 3001): SaaS global infrastructure admin & dynamic reverse proxy generator (master.v1.dewdrive.com).
  • apps/web-owner-console (Port 3002): Organization tenant admin console & device management (app.v1.dewdrive.com).
  • apps/web-marketing (Port 3003): Public landing page, documentation portal & Geo-Dispersed Erasure Coding visualizer (dewdrive.com).

📱 Mobile Fleet Client

  • apps/mobile-app: Expo / React Native mobile fleet monitoring and telemetry alerting application.

2. Shared Libraries (libs/ — Pure Logic, Zero UI per Rule 2)

  • libs/dewdrive-core: Shared Rust engine logic, SQLite database partitioning, token auth, AES-256-CBC crypto, power detection, path sanitization, URI helpers.
  • libs/core-proto: Canonical Protobuf schemas (telemetry.proto, backup_progress.proto, control_commands.proto) with dual prost (Rust) and @bufbuild/protobuf (TS) bindings.
  • libs/restic-executor: Async subprocess executor (tokio::process::Command), speed collector, local S3 TCP tunnel proxy.
  • libs/restic-parser: Rust JSON streaming stdout/stderr parser & ts-rs exported models.
  • libs/kopia-executor: Async subprocess executor for Kopia CLI binaries and cache directory resolution.
  • libs/core/: Foundation TypeScript packages (@dewdrive/core-types, @dewdrive/core-supabase, @dewdrive/core-api, @dewdrive/core-control-plane, @dewdrive/core-backup-engines, @dewdrive/core-constants).
  • libs/features/: Domain TypeScript packages (@dewdrive/feature-auth, @dewdrive/feature-nodes, @dewdrive/feature-s3-storage, @dewdrive/feature-reseller-branding, @dewdrive/feature-payment-gateways, @dewdrive/feature-referral-tree, @dewdrive/feature-master-infrastructure, @dewdrive/feature-agent-settings).

3. Production Infrastructure Topology

The production stack is deployed across dedicated Proxmox VE virtual machines:

[ Public WAN 59.93.37.40 ]
           │
     ┌─────┴──────────────────────────────────────────────────────────────────┐
     │ Edge Nginx Reverse Proxy (SSL Termination, CORS, Buffers, 410 Guard)   │
     └─────┬──────────────────────────────────────────────────────────┬───────┘
           │ (Internal Subnets: 10.40.10.0/24 & 10.40.11.0/24)        │
           ▼                                                          ▼
┌───────────────────────────┐                              ┌──────────────────────────┐
│ VM 8050: dewdrive-ingress │                              │ VM 8054: dewdrive-db-api │
│ ├─ Caddy (Port 80/443)    │                              │ ├─ PostgREST 12 (:3000)  │
│ │  └─ Static /downloads   │                              │ └─ Zitadel IAM (:8080)   │
│ └─ HAProxy (5432-5433)    │                              └─────────────┬────────────┘
└───────────────────────────┘                                            │
                                                                         ▼
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ YugabyteDB 2.20 Distributed SQL Cluster (Multi-Master / Multi-TServer)               │
│ ├─ Masters:  VM 8061 (01), VM 8062 (02), VM 8063 (03), VM 8064 (04)                 │
│ └─ TServers: VM 8065 (01), VM 8066 (02), VM 8067 (03), VM 8068 (04)                 │
└─────────────────────────────────────────────────────────────────────────────────────┘
           │
           ▼
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ Web Application Tier (Next.js 16 Production Services)                               │
│ ├─ VM 8058: Master Console (Port 3001) & Web Marketing (Port 3003)                  │
│ ├─ VM 8059: Owner Customer Cockpit (Port 3002)                                      │
│ └─ VM 8060: Reseller Partner Portal (Port 3000)                                     │
└─────────────────────────────────────────────────────────────────────────────────────┘

4. Modern IAM & Authentication Strategy

  • Pure Zitadel IAM with OIDC PKCE: All console logins use modern cyber-dark hero cards redirecting to Zitadel (https://auth.v1.dewdrive.com). All legacy GoTrue email/password forms are permanently decommissioned.
  • Dynamic Just-In-Time (JIT) Provisioning: resolveOrProvisionDatabaseUser() issues a short-lived 60s service-role JWT signed with PGRST_JWT_SECRET to query dewdrive_users and tenant_memberships in YugabyteDB. Fresh registrations in Zitadel automatically have an organization tenant, user record, and default membership provisioned on the fly.
  • Universal Desktop Token Endpoint: POST /api/auth/token on web consoles refreshes tokens with Zitadel, resolves the database identity, and mints an HS256 PostgREST token for desktop daemons.
  • Hybrid Desktop Session Model: Sibling apps dewdrive and dewrewind store separate sets of SQLite session keys (session_token vs dewrewind_session_token) to prevent concurrent GoTrue/Zitadel refresh token revocation, with boot inheritance and refresh healing.
Tags:#architecture#tauri#restic#kopia#nats#yugabytedb#zitadel