Files
parking_solution/wiki/sources/parking-system-architecture.md
T
julian bfe64032d8 Initial scaffold: Turborepo monorepo + design wiki
Turborepo (pnpm workspaces) with all dependencies pinned to latest
mutually-compatible versions: turbo 2.9, TypeScript 6, Fastify 5,
React 19, Vite 8, better-sqlite3 12 + Drizzle ORM 0.45.

Layout:
- apps/server   Fastify backend (local JWT auth + role guard, /health)
- apps/web      React 19 + Vite 8 operator SPA
- packages/db   Drizzle schema on SQLite/WAL; append-only events + users
- packages/devices  reader/printer/relay adapter interfaces (intent-only relay)
- packages/shared   shared domain types

Architecture constraints from the design wiki are encoded in the scaffold:
append-only hash-chained + signed event log, device-agnostic adapters,
"a barrier is not a door" (relay expresses intent only), fully-local
offline-first auth.

wiki/ is an LLM-maintained Obsidian knowledge base (28 pages) ingested
from the architecture & design notes, with its own maintenance schema.

Verified: pnpm install, full turbo build (5/5), server boots and serves
/health, drizzle-kit generates the initial migration.
2026-06-14 00:34:11 +02:00

52 lines
3.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
type: source
tags: [parking, architecture, source]
sources: [parking-system-architecture]
updated: 2026-06-14
---
# Source: Parking Management System — Architecture & Design Notes
A working design reference (not a final spec) recording architectural decisions, the
reasoning behind them, and rejected alternatives for a parking-management system. Several
items are explicitly open. Raw file: `raw/parking-system-architecture.md`.
## Key takeaways
- The system is a **web app on Linux, deployed on-site**. Two forces shape every decision:
[[offline-first]] operation and the **physical-security reality** of a machine in an exposed booth.
- **Stack** ([[technology-stack]]): [[turborepo]] · [[fastify]] (Node) · [[react-vite-spa]] ·
[[sqlite]] + [[drizzle-orm]] · [[local-jwt-auth]]. All MIT/Apache/BSD — chosen for **no vendor
lock / no rug-pull risk** (the reason [[payload-cms]] was rejected).
- **The threat-model reframing** ([[threat-model]]): the primary adversary is the **legitimate
operator at the booth**, not an outsider stealing the machine. Encryption-at-rest defends the
wrong threat. The real controls are the [[append-only-event-chain]] (hash-chained,
[[atecc608]]-signed) plus [[reconciliation]] against an authority the operator can't alter.
- **Devices** go through a [[device-adapter-pattern]] so hardware swaps don't touch business logic.
Safety principle: [[barrier-not-a-door]] — physical safety lives in the barrier operator firmware.
- **Access control** today is the [[uhppote-controller]] on an isolated VLAN — tamper-*evident*,
not tamper-*proof*, because its [[uhppote-udp-protocol|UDP protocol]] is unauthenticated. The
[[esp32-custom-controller]] is documented as the prevention-grade upgrade (challenge–response
with asymmetric signatures).
- **Readers** split into two populations ([[entry-exit-readers]]): permit holders (best via
[[wiegand]] into the controller, autonomous) and casual/transient (host-side: [[lpr-camera]],
QR/ticket). Both can share one relay.
- A reference [[bom|BOM]] lists recommended devices; **6 open decisions** remain
([[open-questions]]) that drive procurement.
## Section map
| § | Topic | Wiki pages |
| --- | --- | --- |
| 1 | System context | [[offline-first]], [[threat-model]] |
| 2 | Technology stack | [[technology-stack]], [[fastify]], [[sqlite]], [[drizzle-orm]], [[turborepo]], [[react-vite-spa]], [[local-jwt-auth]], [[payload-cms]] |
| 3 | Data security & threat model | [[threat-model]], [[append-only-event-chain]], [[atecc608]], [[reconciliation]], [[disk-os-hardening]] |
| 4 | SQLite limits | [[sqlite]] |
| 5 | Device architecture | [[device-adapter-pattern]], [[barrier-not-a-door]], [[trust-boundary]] |
| 6 | UHPPOTE access control | [[uhppote-controller]], [[uhppote-udp-protocol]], [[network-isolation]], [[event-log-ingestion]] |
| 7 | Custom ESP32 controller | [[esp32-custom-controller]], [[challenge-response-auth]], [[atecc608]], [[fail-state-safety]] |
| 8 | Entry/exit readers | [[entry-exit-readers]], [[wiegand]], [[lpr-camera]] |
| 9 | Recommended devices (BOM) | [[bom]] |
| 10 | Open decisions / next steps | [[open-questions]] |
| — | Summary of standing decisions | [[standing-decisions]] |