Skip to main content

Overview

For a complete Release 1 reviewer path from Penpot and canonical relationships through rendering, tooling, physics, implementation anchors, and Delivery acknowledgement, use the Release 1 human review reference.

This C2 Container view documents AeroSim's deployed and integrated applications, data store, external systems, and communication protocols. It does not convert Proposed Features, requirements, ADR-0001, or ADR-0002 into approved decisions. The bottom supporting-governance zone publishes project documentation but is explicitly outside the runtime path required to operate AeroSim.

loading...

Runtime containers​

ContainerTechnologyResponsibility
Web ApplicationReact, Vite, TypeScript, React Three Fiber, Three.js, Rapier, NginxKeycloak session client, bundled governed catalogues, pre-flight configuration, full-screen flight experience, deterministic simulation, controls, cameras, warnings, outcomes, and pilot-data clients
API ServiceFastify, TypeScript, Socket.IO, PrismaJWT validation, pilot profile/preferences/progress, health endpoints, and an authenticated Socket.IO scaffold that rejects flight commands when no production forwarder is configured
Pilot Data StorePostgreSQL with Prisma migrationsPilot identity linkage, camera preference, resumable progress, outcomes, and attempt fields within progress records

Supporting governance container​

ContainerTechnologyResponsibilityRequired for AeroSim runtime?
Documentation SiteDocusaurus and editable Draw.ioProduct, architecture, delivery, and engineering documentationNo — it supports governance and delivery but is not required for the delivered application to operate

Communication protocols​

Required runtime path​

SourceDestinationProtocolPurpose
Pilot browserOsgiliathHTTPS and WSSReach the public AeroSim endpoint; Osgiliath terminates TLS
OsgiliathKubernetes IngressHTTPReverse-proxy trusted traffic into the cluster
Kubernetes IngressWeb ApplicationHTTP /Route browser application traffic
Kubernetes IngressAPI ServiceHTTP /api and /socket.ioRoute API calls and WebSocket upgrades
Web ApplicationKeycloakOIDC/OAuth 2.0 Authorization Code + PKCESign in and maintain the browser session
Web ApplicationAPI ServiceHTTPS/JSONProfile, preferences, progress, and outcomes
API ServiceKeycloakHTTPS/JWKSValidate JWT signatures and claims
API ServicePilot Data StorePostgreSQL through PrismaTransactional pilot-owned persistence within the namespace NetworkPolicy boundary

Exposed but inactive Release 1 surface​

Kubernetes Ingress routes /socket.io to the API Service, and the API authenticates the handshake and validates typed payloads. The production composition injects no flight-command forwarder, and the shipped Web Application does not connect this client into the flight path. Valid flight commands therefore fail closed with COMMAND_FORWARDER_UNAVAILABLE; WSS/Socket.IO is not a required Release 1 runtime relationship.

Supporting documentation path — not required at runtime​

SourceDestinationProtocolPurpose
GiteaDocumentation SiteGit/HTTPSSupply reviewed sources and trigger the documentation build
Documentation SiteProject PagesHTTPSPublish the generated static site
Documentation readerProject PagesHTTPSRead the published documentation

Implemented runtime choices awaiting architecture disposition​

  • Flight physics remains browser-local and advances with a deterministic fixed step.
  • The API is not the flight-physics authority.
  • Release 1 catalogues are compiled into the Web Application; no API catalogue route is registered.
  • The exposed Socket.IO route is authenticated fail-closed scaffolding, not an active browser flight path.
  • Keycloak is the sole identity provider; no AeroSim registration or local sign-in exists.
  • The browser never connects directly to PostgreSQL.
  • Every persisted pilot record is scoped to the authenticated Keycloak subject.
  • Osgiliath owns public certificate lifecycle and TLS termination; Gondor's Kubernetes Ingress uses HTTP for the internal proxy and Service hops.
  • The Helm chart keeps in-cluster Ingress TLS optional for portability and disables it by default for the Gondor contract.