Living Document Notice Published 2026-09-20. The evolving architecture and connected notes for this dispatch live in the Stax Digital Garden.

Why We’re Building Embers

Why We're Building Embers: Warm sepia-white phosphor P4/P20 vector CRT macro showing a protected central household sanctuary circle deflecting chaotic exterior noise vectors

Overview

Contemporary photo-sharing tools force an untenable trade-off: surrender private household media to multi-tenant cloud platforms, or operate complex self-hosted stacks that non-technical family members cannot navigate.

Embers resolves this division. It is a self-hosted photo and video sharing platform built specifically for trusted family circles, governed by a strict architectural constraint: zero unauthenticated public links.

Commercial cloud providers design their sharing primitives around global distribution and viral reach. Their default pattern is the unbounded bearer URL: generate an unauthenticated 64-character token that grants complete read access to anyone holding the link. These tokens leak into group chats, persist in browser histories across untrusted workstations, and get ingested by automated scrapers. When an exposure occurs, owners face a binary choice: leave the media exposed or destroy the link, severing access for every participant.

Embers eliminates that operational compromise by enforcing private-by-default access boundaries:

Standard Cloud Link Sharing:
[Private Album] ──> [Public Bearer URL] ──> Any User Agent (Unbounded Exposure)
 
Embers Explicit Access Control:
[Private Album] ──> [Authentication Gate] ──> [Named Account | Link + PIN | Guest Session]
DimensionMulti-Tenant Cloud Photo ServicesEmbers Self-Hosted Engine
Default AccessPublicly accessible bearer URLDeny-all; explicit credential challenge required
Identity SubstrateProprietary cloud platform accountLocal accounts, guest sessions, or PIN challenges
Revocation ControlAll-or-nothing link invalidationPer-session or per-user revocation
Storage ArchitectureVendor-managed object storageDirect POSIX filesystem or private S3 bucket
Compute DemandsOpaque server-side ML and facial indexingDeterministic thumbnailing and metadata extraction

Architectural Invariants

  • Deterministic Execution: Operations execute within deterministic memory bounds without external side effects.
  • Sovereignty: Storage and state replication guarantee zero unauthenticated telemetry or vendor lock-in.
Invariant PropertyOperational Guarantee
System InvariantEmbers rejects all public bearer links and automated facial indexing; access is strictly confined to authenticated household sessions and explicit PIN gates.
# Verify guest access PIN requirement and zero public bearer URLs
curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:3000/media/stream/circle_01

  • Directus Target: embers
  • Garden Source Reference: MOC - The Digital Necropolis and Cold Decadal Storage, MOC - Bosun PKM Tools
  • Garden Source Reference: [EMB-1011 - Why We’re Building Embers](EMB-1011 - Why We’re Building Embers), BSN-1001 - The Bosun Architecture Manifesto