* docs(b3): Codex round 1 — keep the main-PR Docker term, checkout dev on schedule, profile numbers, hub built in api.NewRouter P1: the Docker verify condition keeps ref_name/base_ref main and adds the schedule term. P2: scheduled runs check out dev explicitly (the workflow file comes from main). P2: the alpha profile's dimensions are defined in the plan, not borrowed from load-baseline.yml (which has only users=100). P2: ws.NewHub is called in api/router.go:106 with setters split across router.go and main.go, so B3-4 follows B3-3, which moves construction into internal/app. Also: plan-index row and roadmap slice line for B3. * feat(b3-0): boundary inventory — dbinventory tool, db-import-boundary rule, server-boundaries.md 51 production files outside db/ and service/ import db (ws 17, admin 16, api 12, auth 2, root 2, cmd/seed 1, plugin 1); 14 are type-only. Each has a disposition (move 28 / adapter 17 / boundary 6) and, for moves, a target family, held in invariants.DBImportAllow so the generated document and the gate cannot drift. The rule fails any new importer without a row; the live test fails any stale row. Hub lifecycle (setters, locks, defer stack) and the auth before-graph are inventoried for B3-2/B3-3/B3-4. Closes the B3 entry gate's third item. * fix(b3-0): dbinventory exempts only top-level db/ and service/ (Codex P2) Skipping by directory name let a nested api/service/ escape the inventory while the rule would still catch it; the walker now exempts by root-relative path, with a test over a synthetic tree.
OwnCord Architecture Blueprints
Verified against: commit 5630aa1, 2026-08-04
Companion audits: docs/audit-2026-08-04-docs-and-coverage.md (docs & coverage),
docs/audit-2026-08-04.md (security),
docs/audit-2026-07-19.md (architecture)
This directory is the curated architectural map of OwnCord — the "blueprints" for the whole system. Every diagram is a Mermaid fenced block (GitHub renders these natively) followed by a prose explanation and a Source of truth file list.
Index
| Doc | Diagrams | Covers |
|---|---|---|
| system-overview.md | D1 System context, D8 Deployment topology | All processes, trust boundaries, ports, single-instance constraints |
| server.md | D2 Server package map, D3 REST request lifecycle | Go package structure, DB-access styles, middleware chain |
| websocket.md | D4 WS connect / replay / dispatch | Real-time engine: auth handshake, 3-tier reconnect replay, backpressure, typed dispatch |
| data-model.md | D5 Entity-relationship overview | All 26 tables from migrations 001–028, grouped by domain |
| voice-e2ee.md | D6 Voice + E2EE flow | LiveKit token flow, loopback TLS tunnel, ECDH key-holder relay |
| client.md | D7 Client module map | Tauri client: bootstrap, dispatcher, stores, Rust sidecars (structure, as-built) |
| ux/ | UX flow + state diagrams | Client behavior spec (target state): what every view does and how it reacts to events, permissions, and failure |
| platform-contracts.md | — | Desktop/browser seam (target state): where native dependencies will be isolated, and the three that have no browser equivalent |
| server-boundaries.md | — | B3-0 inventory: every file above the domain layer that imports db, with a disposition and target family; hub setters, locks and the start/stop defer stack; the auth slice's before-graph. Generated table, enforced by db-import-boundary |
| plugins.md | — | Experimental WASM plugin boundary: off twice and compiled out of releases, no API promise, post-beta candidates, core that never moves |
Structure vs. behavior
client.md maps the client as-built (modules, stores, wiring). The ux/ set is the complementary behavior spec — prescriptive (to-be) flows for every view, with per-view state matrices and event→reaction maps. Where today's code diverges from the target, the UX docs carry dated ⚠ Current gap callouts, so the set doubles as a UX improvement backlog.
platform-contracts.md is a third kind again: a target seam map. It records where the desktop/browser boundary will be drawn and what crosses it, measured against today's code. The seam does not exist yet — B7 builds it — so read that document as a decision record, not as structure.
Maintenance rule
These documents are curated, not generated. The rule that keeps them honest:
If a PR changes the structure of anything listed in a diagram's Source of truth list (new package, new table, new message type, changed flow), that PR updates the corresponding diagram in the same change.
Diagrams reference stable identifiers (package names, table names, message-type strings) rather than line numbers wherever possible. Line-number evidence lives in the dated audit reports, which are point-in-time snapshots by design.
Relationship to other docs
docs/api.md,docs/protocol.md,docs/schema.mdare the reference specs (request/response shapes, wire formats, DDL). These blueprints describe structure and flow, not payload shapes. Known drift between the specs and the code is catalogued in the dated audit reports (latest: audit-2026-08-04-docs-and-coverage.md).docs/client-architecture.mdis a redirect stub kept for old links; client.md is the client architecture document.