Skip to main content

Context

This C1 System Context documents AeroSim's deployed and integrated structure as an authenticated browser flight-simulation system for pilots and learners. It is implementation evidence, not approval of the Proposed Features, requirements, ADR-0001, or ADR-0002.

loading...

People and external systems​

ElementRelationship with AeroSim
Pilot or learnerOpens AeroSim over HTTPS, configures a flight, flies the aircraft, observes flight state, and completes, aborts, retries, or restarts a session
KeycloakProvides the only sign-in path through OpenID Connect and OAuth 2.0; AeroSim stores no password or local credential
GiteaHosts source and review evidence and runs governed build workflows
HarborStores immutable Web and API container images over OCI/HTTPS
Gondor platformOsgiliath terminates public TLS and reverse-proxies HTTP to Kubernetes Ingress; Kubernetes provides runtime, GitOps selection, networking, and workload-secret integration
Project PagesPublishes the generated Documentation Site to readers over HTTPS

System boundary​

AeroSim owns the Web Application, API Service, Pilot Data Store, and Documentation Site. Keycloak, Gitea, Harbor, Osgiliath, Kubernetes Ingress, Kubernetes, and GitOps are external platform systems.

Flight rendering, deterministic physics, and the governed Release 1 aircraft/world/condition catalogues execute from the browser bundle. The API owns authenticated pilot data and exposes an authenticated Socket.IO surface whose production command forwarder is not configured; that surface is not part of the active Release 1 flight path. PostgreSQL owns durable pilot identity linkage, supported preferences, progress, outcomes, and attempt metadata.

Trust and protocol boundaries​

  • Browser traffic uses HTTPS. Kubernetes exposes a WSS/Socket.IO route, but the shipped Release 1 browser does not use it and the API rejects flight commands without a production forwarder.
  • Osgiliath terminates public TLS for aerosim.apps.lego-cloud.eu; Kubernetes Ingress receives HTTP from Osgiliath and requires no Gondor TLS Secret.
  • Browser authentication uses OIDC/OAuth 2.0 Authorization Code with PKCE.
  • The API validates Keycloak JWTs through HTTPS/JWKS and authorizes every pilot-owned operation by subject.
  • The API is the only application container permitted to access PostgreSQL, using Prisma over the PostgreSQL protocol through a namespace NetworkPolicy boundary.
  • Workload delivery uses Git/HTTPS, OCI/HTTPS, and Gondor's governed GitOps path.

Infrastructure and deployment boundary​

HopProtocolResponsibility
Pilot browser → OsgiliathHTTPS and WSSPublic endpoint, ACME certificate lifecycle, and TLS termination
Osgiliath → Kubernetes IngressHTTPTrusted reverse-proxy hop into the Gondor cluster
Kubernetes Ingress → Web ApplicationHTTP /Route browser application traffic to the Nginx Service
Kubernetes Ingress → API ServiceHTTP /api and /socket.ioRoute API and WebSocket upgrade traffic to the Fastify Service

The AeroSim Helm chart supports optional in-cluster TLS for environments that need it. Gondor disables that option because Osgiliath owns the certificate and public TLS boundary. Enabling chart TLS requires a named, pre-existing Kubernetes TLS Secret; disabling it renders no Ingress spec.tls block and introduces no TLS Secret dependency.