Living Document Notice Published 2026-09-23. The evolving architecture and connected notes for this dispatch live in the Stax Digital Garden.

What We’ve Implemented So Far

What We've Implemented So Far: Warm sepia-white phosphor P4/P20 vector CRT macro showing three arc progress dials, subsystem status matrices, and throughput step waveforms

Overview

Embers has transitioned from architectural specifications into an active, functional foundation. Development follows an iterative milestone strategy: stabilize core data storage, session security, and media ingestion before implementing client-side features.

[Monorepo & Scaffold] ──> [Schema & Auth] ──> [Ingestion & Processing] ──> [Sharing & Hardening]
        (Done)                  (Done)                   (Done)                 (Active Focus)

Core Subsystems Shipped

  • Build & Dev Tooling: Unified TypeScript monorepo combining the API server, database migration engine, and React web client under a shared build pipeline.
  • Authentication Infrastructure: User registration, password hashing via Argon2id key-derivation functions, database-backed session tables, and token-based email login routines backed by an internal SMTP client.
  • Relational Schema: SQLite schemas covering users, albums, media records, album shares, invite tokens, and guest sessions.
  • Album Management: Endpoints for complete CRUD operations on albums, covering metadata tags, sorting preferences, and cover asset references.
  • Media Processing Pipeline: Multipart file upload handling, non-destructive thumbnail generation, and background offloading to local storage adapters.
  • Client Interface: Responsive React views for user authentication, album grid navigation, masonry image viewing, and direct drag-and-drop upload queues.
  • Access Control Mechanisms: Password and PIN challenge routes with middleware enforcing Admin and Contributor tiers capabilities.

Implementation Matrix

SubsystemUnderlying TechnologyOperational Status
API ServerNode.js / TypeScriptDeployed; auth and upload pipelines endpoints verified
Relational StoreSQLite / Better-SQLite3Deployed; schema migrations passing regression checks
Image TransformerSharp (libvips wrapper)Deployed; generates WebP responsive thumbnails
Guest AuthScoped session tokensDeployed; password and PIN challenge flows active
Frontend FrameworkReact / ViteDeployed; album browsing and upload managers active
PackagingDocker multi-stage buildDeployed; single production container operational

Architectural Invariants

  • Deterministic Execution: Operations execute within deterministic memory bounds without external side effects.
  • Sovereignty: Storage and state replication guarantee zero unauthenticated telemetry or vendor lock-in.
Invariant PropertyOperational Guarantee
System InvariantEmbers rejects all public bearer links and automated facial indexing; access is strictly confined to authenticated household sessions and explicit PIN gates.
# Verify guest access PIN requirement and zero public bearer URLs
curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:3000/media/stream/circle_01

  • Directus Target: embers
  • Garden Source Reference: MOC - The Digital Necropolis and Cold Decadal Storage, MOC - Bosun PKM Tools
  • Garden Source Reference: [EMB-1014 - What We’ve Implemented So Far](EMB-1014 - What We’ve Implemented So Far), BSN-1001 - The Bosun Architecture Manifesto