# Architecture Single Rust binary (axum) serving the API and the built Vue SPA; SQLite for state; host tools (`apt-get`, `dpkg-query`, `snap`, `microk8s kubectl`, `trivy`, `smbclient`, `curl`, `tar`, `openssl`) are invoked as subprocesses behind ports so every use case is testable with fakes. ``` backend/crates/ domain/ entities, validation, ports (traits) no I/O application/ use cases: auth, users, settings, jobs, depends on domain scheduler, inventory, upgrade, cluster, vulnerabilities, backups infrastructure/ SQLite repos, Argon2/JWT/AES-GCM, lettre, implements the ports Debian inspector/updater, kube-rs gateway, Trivy, smbclient/curl storage, collectors api/ axum routes, auth extractors, OpenAPI, wires everything security headers, config, main frontend/ Vue 3 + TypeScript + Tailwind, Pinia stores, Playwright e2e ``` Cross-cutting: a `JobRunner` executes long-running work (refresh, upgrade, scan, backup) as persisted job runs with live logs; a `Scheduler` ticks every 30 s and starts due jobs from cron expressions (settings) and backup strategies. Secrets at rest are AES-256-GCM encrypted with `MASTER_KEY`. Authentication: Argon2id passwords, 15-minute JWT access tokens, rotating refresh tokens in an HttpOnly, SameSite=Strict cookie scoped to `/api/auth`, reuse detection revokes the token family. `FAKE_HOST=true` swaps all host/cluster/scanner/storage adapters for fakes so the app runs on a developer machine and in the UI tests.