Context
This C1 System Context documents AeroSim's deployed and integrated structure as an authenticated browser flight-simulation system for pilots and learners. It is implementation evidence, not approval of the Proposed Features, requirements, ADR-0001, or ADR-0002.
People and external systems
| Element | Relationship with AeroSim |
|---|---|
| Pilot or learner | Opens AeroSim over HTTPS, configures a flight, flies the aircraft, observes flight state, and completes, aborts, retries, or restarts a session |
| Keycloak | Provides the only sign-in path through OpenID Connect and OAuth 2.0; AeroSim stores no password or local credential |
| Gitea | Hosts source and review evidence and runs governed build workflows |
| Harbor | Stores immutable Web and API container images over OCI/HTTPS |
| Gondor platform | Osgiliath terminates public TLS and reverse-proxies HTTP to Kubernetes Ingress; Kubernetes provides runtime, GitOps selection, networking, and workload-secret integration |
| Project Pages | Publishes the generated Documentation Site to readers over HTTPS |
System boundary
AeroSim owns the Web Application, API Service, Pilot Data Store, and Documentation Site. Keycloak, Gitea, Harbor, Osgiliath, Kubernetes Ingress, Kubernetes, and GitOps are external platform systems.
Flight rendering, deterministic physics, and the governed Release 1 aircraft/world/condition catalogues execute from the browser bundle. The API owns authenticated pilot data and exposes an authenticated Socket.IO surface whose production command forwarder is not configured; that surface is not part of the active Release 1 flight path. PostgreSQL owns durable pilot identity linkage, supported preferences, progress, outcomes, and attempt metadata.
Trust and protocol boundaries
- Browser traffic uses HTTPS. Kubernetes exposes a WSS/Socket.IO route, but the shipped Release 1 browser does not use it and the API rejects flight commands without a production forwarder.
- Osgiliath terminates public TLS for
aerosim.apps.lego-cloud.eu; Kubernetes Ingress receives HTTP from Osgiliath and requires no Gondor TLS Secret. - Browser authentication uses OIDC/OAuth 2.0 Authorization Code with PKCE.
- The API validates Keycloak JWTs through HTTPS/JWKS and authorizes every pilot-owned operation by subject.
- The API is the only application container permitted to access PostgreSQL, using Prisma over the PostgreSQL protocol through a namespace NetworkPolicy boundary.
- Workload delivery uses Git/HTTPS, OCI/HTTPS, and Gondor's governed GitOps path.
Infrastructure and deployment boundary
| Hop | Protocol | Responsibility |
|---|---|---|
| Pilot browser → Osgiliath | HTTPS and WSS | Public endpoint, ACME certificate lifecycle, and TLS termination |
| Osgiliath → Kubernetes Ingress | HTTP | Trusted reverse-proxy hop into the Gondor cluster |
| Kubernetes Ingress → Web Application | HTTP / | Route browser application traffic to the Nginx Service |
| Kubernetes Ingress → API Service | HTTP /api and /socket.io | Route API and WebSocket upgrade traffic to the Fastify Service |
The AeroSim Helm chart supports optional in-cluster TLS for environments that need it. Gondor disables that option because Osgiliath owns the certificate and public TLS boundary. Enabling chart TLS requires a named, pre-existing Kubernetes TLS Secret; disabling it renders no Ingress spec.tls block and introduces no TLS Secret dependency.
Related views
- Overview — C2 containers and communication protocols.
- Container Registry — one C3 Component view per container.
- Functional requirements and non-functional requirements — behavior and quality contracts.
- Release 1 architecture baseline — lifecycle truth, exact evidence references, risks, and decisions still required.