Architecture & Production Reference
Core Architecture• 4 min read• Updated 2026-09-15
In-depth technical architecture of dewDrive. Covers 17 monorepo applications, multi-engine backup runtimes (Restic & Kopia), NATS JetStream binary IPC, YugabyteDB, and Zitadel IAM.
dewDrive is an enterprise hybrid web and desktop backup and disaster recovery platform utilizing multi-engine backup runtimes (Restic 0.19.1 & Kopia), NATS JetStream binary IPC, YugabyteDB distributed SQL with PostgREST 12, Zitadel IAM OIDC PKCE authentication, and Next.js 16 / Tauri 2.0 cockpits.
1. Monorepo Applications Matrix (17 Apps)
🖥️ Desktop Cockpits (Tauri 2.0 + React 19)
apps/dewdrive: Desktop Ingestion Cockpit GUI (dual-ring progress indicators, local vault configuration, system tray, hostsdewdrive-agent-watchdog).apps/dewrewind(dewRewind): Standalone Disaster Recovery & Snapshot Restoration Cockpit GUI (visual card-stack file restore, point-in-time snapshot recovery).
🤖 Local Desktop Client Micro-Daemons (apps/dewdrive-agent-*)
Embedded NATS JetStream (Port 34222, fallback 4222) / WebSocket (Port 9224) with Protobuf binary serialization:
apps/dewdrive-agent-backup-worker: Multi-engine backup execution daemon (Restic 0.19.1 + Kopia, VSS snapshots, Protobuf progress stream ondaemon.progress.events). Token refresh via universal/api/auth/token.apps/dewdrive-agent-rmm: 24/7 hardware & system telemetry collector with 4-mode governor (AC Standard, Battery Eco, Spectator Turbo, Emergency Forensics). Publishes totelemetry.node.<node_id>.apps/dewdrive-agent-elevated-helper(Root/SYSTEM): Privileged helper for VSS shadow copies and GPL-isolatedsmartctl7.4 disk diagnostics.apps/dewdrive-agent-db-writer: Dedicated single-writer SQLite persistence daemon consumingdb.write.*streams to prevent SQLite concurrency lockouts.apps/dewdrive-agent-updater-monitor: Process supervisor, health watchdog (heartbeat.*), and atomic binary hot-swapper (apply.update).
☁️ Cloud Microservices & APIs (apps/dewdrive-cloud-*)
apps/dewdrive-cloud-rmm(Port3005): 24/7 Cloud Remote Monitoring & Management hardware telemetry ingestion (Axum + PostgreSQL).apps/dewdrive-cloud-restic-vault-helper(Port7842): Standalone Restic Secure Vault maintenance (prune, forget, check, lock monitor) & file viewer API (Axum + HTMX).apps/dewdrive-cloud-restic(Port7843): Central Cloud Restic Ingestion Control API & coordinator.apps/dewdrive-cloud-kopia-vault-helper(Port7844): Standalone Kopia Secure Vault maintenance & manifest viewer API.apps/dewdrive-cloud-kopia(Port7845): Central Cloud Kopia Ingestion Control API & coordinator.
🌐 Web Consoles & Marketing (Next.js 16 / React 19)
apps/web-reseller-console(Port3000): White-label multi-tenant reseller management portal (reseller.v1.dewdrive.com).apps/web-master-console(Port3001): SaaS global infrastructure admin & dynamic reverse proxy generator (master.v1.dewdrive.com).apps/web-owner-console(Port3002): Organization tenant admin console & device management (app.v1.dewdrive.com).apps/web-marketing(Port3003): Public landing page, documentation portal & Geo-Dispersed Erasure Coding visualizer (dewdrive.com).
📱 Mobile Fleet Client
apps/mobile-app: Expo / React Native mobile fleet monitoring and telemetry alerting application.
2. Shared Libraries (libs/ — Pure Logic, Zero UI per Rule 2)
libs/dewdrive-core: Shared Rust engine logic, SQLite database partitioning, token auth, AES-256-CBC crypto, power detection, path sanitization, URI helpers.libs/core-proto: Canonical Protobuf schemas (telemetry.proto,backup_progress.proto,control_commands.proto) with dualprost(Rust) and@bufbuild/protobuf(TS) bindings.libs/restic-executor: Async subprocess executor (tokio::process::Command), speed collector, local S3 TCP tunnel proxy.libs/restic-parser: Rust JSON streaming stdout/stderr parser &ts-rsexported models.libs/kopia-executor: Async subprocess executor for Kopia CLI binaries and cache directory resolution.libs/core/: Foundation TypeScript packages (@dewdrive/core-types,@dewdrive/core-supabase,@dewdrive/core-api,@dewdrive/core-control-plane,@dewdrive/core-backup-engines,@dewdrive/core-constants).libs/features/: Domain TypeScript packages (@dewdrive/feature-auth,@dewdrive/feature-nodes,@dewdrive/feature-s3-storage,@dewdrive/feature-reseller-branding,@dewdrive/feature-payment-gateways,@dewdrive/feature-referral-tree,@dewdrive/feature-master-infrastructure,@dewdrive/feature-agent-settings).
3. Production Infrastructure Topology
The production stack is deployed across dedicated Proxmox VE virtual machines:
[ Public WAN 59.93.37.40 ]
│
┌─────┴──────────────────────────────────────────────────────────────────┐
│ Edge Nginx Reverse Proxy (SSL Termination, CORS, Buffers, 410 Guard) │
└─────┬──────────────────────────────────────────────────────────┬───────┘
│ (Internal Subnets: 10.40.10.0/24 & 10.40.11.0/24) │
▼ ▼
┌───────────────────────────┐ ┌──────────────────────────┐
│ VM 8050: dewdrive-ingress │ │ VM 8054: dewdrive-db-api │
│ ├─ Caddy (Port 80/443) │ │ ├─ PostgREST 12 (:3000) │
│ │ └─ Static /downloads │ │ └─ Zitadel IAM (:8080) │
│ └─ HAProxy (5432-5433) │ └─────────────┬────────────┘
└───────────────────────────┘ │
▼
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ YugabyteDB 2.20 Distributed SQL Cluster (Multi-Master / Multi-TServer) │
│ ├─ Masters: VM 8061 (01), VM 8062 (02), VM 8063 (03), VM 8064 (04) │
│ └─ TServers: VM 8065 (01), VM 8066 (02), VM 8067 (03), VM 8068 (04) │
└─────────────────────────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────────────────────┐
│ Web Application Tier (Next.js 16 Production Services) │
│ ├─ VM 8058: Master Console (Port 3001) & Web Marketing (Port 3003) │
│ ├─ VM 8059: Owner Customer Cockpit (Port 3002) │
│ └─ VM 8060: Reseller Partner Portal (Port 3000) │
└─────────────────────────────────────────────────────────────────────────────────────┘
4. Modern IAM & Authentication Strategy
- Pure Zitadel IAM with OIDC PKCE: All console logins use modern cyber-dark hero cards redirecting to Zitadel (
https://auth.v1.dewdrive.com). All legacy GoTrue email/password forms are permanently decommissioned. - Dynamic Just-In-Time (JIT) Provisioning:
resolveOrProvisionDatabaseUser()issues a short-lived 60s service-role JWT signed withPGRST_JWT_SECRETto querydewdrive_usersandtenant_membershipsin YugabyteDB. Fresh registrations in Zitadel automatically have an organization tenant, user record, and default membership provisioned on the fly. - Universal Desktop Token Endpoint:
POST /api/auth/tokenon web consoles refreshes tokens with Zitadel, resolves the database identity, and mints an HS256 PostgREST token for desktop daemons. - Hybrid Desktop Session Model: Sibling apps
dewdriveanddewrewindstore separate sets of SQLite session keys (session_tokenvsdewrewind_session_token) to prevent concurrent GoTrue/Zitadel refresh token revocation, with boot inheritance and refresh healing.
Tags:#architecture#tauri#restic#kopia#nats#yugabytedb#zitadel