Runtime Boundaries
Process Boundaries
Elixir/OTP Processes
Nixstasis.Applicationstarts the OTP supervision tree.NixstasisWeb.Endpointowns HTTP, WebSocket, LiveView, and Channel request handling.Nixstasis.Repoowns database connections.Phoenix.PubSubis supervised asNixstasis.PubSub.Nixstasis.Monitoring.OfflineCheckeris a named GenServer that schedules:checkmessages every 60 seconds.Nixstasis.E2E.RetentionWorkeris a named GenServer that schedules E2E retention pruning.Nixstasis.Devices.SshClientis a GenServer per terminal session and wraps an OSsshprocess through an Elixir Port.
Traceable references:
packages/server/lib/nixstasis/application.ex:10-29packages/server/lib/nixstasis/monitoring/offline_checker.ex:13-31packages/server/lib/nixstasis/e2e/retention_worker.ex:14-50packages/server/lib/nixstasis/devices/ssh_client.ex:9-94
Go Runtime
- The client binary entry point is
cmd/nixstasis/main.go. - The root command is a Cobra command named
nixstasis. - Client configuration is loaded during
PersistentPreRunE, except forscript testandscript replcommand paths. runMainstarts a Go runtime flight recorder before executing the root command.pollcreates a ticker from configured poll interval and repeatedly callspollOnce.script.Executorruns discovered scripts concurrently with goroutines and async.WaitGroup.commands.Handlerexecutes batches concurrently where command type allows it.frp.Managerlaunches anixstasis-frpctransient systemd unit withsystemd-run; that unit runs the hiddennixstasis frp-sessionsubcommand, which starts the bundledfrpcprocess with a one-hour timeout.
Traceable references:
packages/client/cmd/nixstasis/main.go:20-98packages/client/cmd/nixstasis/poll.go:35-83packages/client/internal/script/executor.go:23-48packages/client/internal/commands/handler.go:27-76packages/client/internal/frp/manager.gopackages/client/cmd/nixstasis/frp_session.go
Starlark Execution Environment
script.Runtimeexecutes Starlark scripts usinggo.starlark.net/starlark.- Runtime builtins include
pub_and_get,exec_cmd, andjson. Runtime.Executecreates a Starlark thread namedstaryand executes a parsed script body.- Scripts must define a callable
main(). main()output is converted from Starlark values to Go values and must be a dictionary when non-null.- Runtime execution is bounded by
RuntimeConfig.Timeout; timeout cancels the Starlark thread.
Traceable references:
packages/client/internal/script/runtime.go:20-47packages/client/internal/script/runtime.go:73-128packages/client/internal/script/runtime.go:130-179packages/client/internal/script/builtins_exec.gopackages/client/internal/script/builtins_mqtt.go
Trust Boundaries
User Input
- Browser form and event inputs enter through Phoenix LiveViews and controllers.
- Device API inputs enter through Phoenix JSON controllers under
/api/v1. - Ash JSON:API inputs enter through
/api/jsonforwarded toNixstasisWeb.AshJsonApiRouter. - E2E API inputs enter through
/e2eroutes when E2E is enabled. - Caddy on-demand TLS sends domain approval input to
GET /api/v1/check_domain.
Traceable references:
packages/server/lib/nixstasis_web/router.ex:22-79packages/server/lib/nixstasis_web/controllers/tls_controller.ex:7-27
Script Execution
- Stary/Starlark scripts are external script content read from configured script directories or installed command payloads.
- Script installation validates front matter and JSON schema before writing installed script files.
- Script execution runs with Starlark builtins that can interact with MQTT.
- OS command execution through
exec_cmdis deny-by-default and only available when the client runtime configuration maps a requested command name to an absolute allowlisted executable path. - Script results become telemetry payload fields sent to the server.
Traceable references:
packages/client/internal/script/executor.go:50-93packages/client/internal/script/runtime.go:40-44packages/client/internal/commands/handler.go:132-187packages/client/cmd/nixstasis/poll.go:105-126
External Access Through FRP
- FRPC runs on managed devices and connects to FRPS.
- FRPS exposes tunnel transport ports from the Compose deployment.
- Caddy proxies wildcard
*.{$BASE_DOMAIN}traffic to FRPS HTTP vhost port. - Caddy proxies
frp-admin.{$BASE_DOMAIN}to the FRPS dashboard port. - Server-side SSH terminal sessions use
sshwith anncatHTTP proxy command pointed at the configured FRP host and TCP mux port. - Development laptop mode uses the same Caddy, Phoenix, FRPS, FRPC, and SSH
process boundaries with
localhostas the base domain and Caddy internal/local certificates for TLS. - The
clientcontainer is a device simulator running systemd as PID 1 with sshd, frpc, and the Go client binary; FRPC connects through FRP and the browser terminal reaches SSH through FRPS TCP mux.
Traceable references:
deploy/compose/docker-compose.yml:33-66deploy/compose/frps/frps.toml:1-15deploy/compose/caddy/Caddyfile:59-75packages/server/lib/nixstasis/devices/ssh_client.ex:30-49
Network Boundaries
Caddy to Phoenix
- Public host
nixstasis.{$BASE_DOMAIN}terminates TLS at Caddy and reverse proxies tonixstasis:4000. - Caddy on-demand TLS asks Phoenix at
http://nixstasis:4000/api/v1/check_domain. - Compose publishes only Caddy ports
80and443for the main HTTP ingress. - Default laptop mode maps the same host pattern to
.localhostnames:nixstasis.localhost,auth.localhost,frp-admin.localhost, andatom-<normalized-device-id>.localhost. - Laptop mode also publishes Phoenix on
127.0.0.1:4000for local-only validation diagnostics; deployment-shaped browser access still goes through Caddy.
Traceable references:
deploy/compose/caddy/Caddyfile:8-10deploy/compose/caddy/Caddyfile:50-57deploy/compose/docker-compose.yml:14-31
Client to Server
- The Go client uses HTTP JSON requests to the configured
api.url. - Default client API URL is
http://localhost:4000. - Packaged configuration documentation uses
https://nixstasis.example.comas the public Caddy host.
Traceable references:
packages/client/internal/config/config.go:62-64packages/client/README.md:115-128packages/client/internal/transport/client.go:27-35
Internal Services
nixstasisservice listens onPORT=4000and publishes it to the host for dev-lab and CI access; Caddy is the production HTTP(S) ingress.postgresis always included; production can overrideDATABASE_URLto use an external managed database.frpsis reached by Caddy on internal service ports and by FRPC on published FRP ports.
Traceable references:
deploy/compose/docker-compose.yml:1-129deploy/compose/README.md:1-117