For a complete Release 1 reviewer path from Penpot and canonical relationships through rendering, tooling, physics, implementation anchors, and Delivery acknowledgement, use the Release 1 human review reference.
This C2 Container view documents AeroSim's deployed and integrated applications, data store, external systems, and communication protocols. It does not convert Proposed Features, requirements, ADR-0001, or ADR-0002 into approved decisions. The bottom supporting-governance zone publishes project documentation but is explicitly outside the runtime path required to operate AeroSim.
loading...
Runtime containers
| Container | Technology | Responsibility |
|---|
| Web Application | React, Vite, TypeScript, React Three Fiber, Three.js, Rapier, Nginx | Keycloak session client, bundled governed catalogues, pre-flight configuration, full-screen flight experience, deterministic simulation, controls, cameras, warnings, outcomes, and pilot-data clients |
| API Service | Fastify, TypeScript, Socket.IO, Prisma | JWT validation, pilot profile/preferences/progress, health endpoints, and an authenticated Socket.IO scaffold that rejects flight commands when no production forwarder is configured |
| Pilot Data Store | PostgreSQL with Prisma migrations | Pilot identity linkage, camera preference, resumable progress, outcomes, and attempt fields within progress records |
Supporting governance container
| Container | Technology | Responsibility | Required for AeroSim runtime? |
|---|
| Documentation Site | Docusaurus and editable Draw.io | Product, architecture, delivery, and engineering documentation | No — it supports governance and delivery but is not required for the delivered application to operate |
Communication protocols
Required runtime path
| Source | Destination | Protocol | Purpose |
|---|
| Pilot browser | Osgiliath | HTTPS and WSS | Reach the public AeroSim endpoint; Osgiliath terminates TLS |
| Osgiliath | Kubernetes Ingress | HTTP | Reverse-proxy trusted traffic into the cluster |
| Kubernetes Ingress | Web Application | HTTP / | Route browser application traffic |
| Kubernetes Ingress | API Service | HTTP /api and /socket.io | Route API calls and WebSocket upgrades |
| Web Application | Keycloak | OIDC/OAuth 2.0 Authorization Code + PKCE | Sign in and maintain the browser session |
| Web Application | API Service | HTTPS/JSON | Profile, preferences, progress, and outcomes |
| API Service | Keycloak | HTTPS/JWKS | Validate JWT signatures and claims |
| API Service | Pilot Data Store | PostgreSQL through Prisma | Transactional pilot-owned persistence within the namespace NetworkPolicy boundary |
Exposed but inactive Release 1 surface
Kubernetes Ingress routes /socket.io to the API Service, and the API authenticates the handshake and validates typed payloads. The production composition injects no flight-command forwarder, and the shipped Web Application does not connect this client into the flight path. Valid flight commands therefore fail closed with COMMAND_FORWARDER_UNAVAILABLE; WSS/Socket.IO is not a required Release 1 runtime relationship.
Supporting documentation path — not required at runtime
| Source | Destination | Protocol | Purpose |
|---|
| Gitea | Documentation Site | Git/HTTPS | Supply reviewed sources and trigger the documentation build |
| Documentation Site | Project Pages | HTTPS | Publish the generated static site |
| Documentation reader | Project Pages | HTTPS | Read the published documentation |
Implemented runtime choices awaiting architecture disposition
- Flight physics remains browser-local and advances with a deterministic fixed step.
- The API is not the flight-physics authority.
- Release 1 catalogues are compiled into the Web Application; no API catalogue route is registered.
- The exposed Socket.IO route is authenticated fail-closed scaffolding, not an active browser flight path.
- Keycloak is the sole identity provider; no AeroSim registration or local sign-in exists.
- The browser never connects directly to PostgreSQL.
- Every persisted pilot record is scoped to the authenticated Keycloak subject.
- Osgiliath owns public certificate lifecycle and TLS termination; Gondor's Kubernetes Ingress uses HTTP for the internal proxy and Service hops.
- The Helm chart keeps in-cluster Ingress TLS optional for portability and disables it by default for the Gondor contract.