# Architecture

URL: https://docs.domainruntime.dev/docs/platform/architecture
Status: Verified
Reviewed: 2026-09-22



```text
                       auth.ekairos.ai          identity: people, organizations, keys
                                   ▲ validates every request
Browser / backend ──▶ <env>.domainruntime.cloud
                                   │
                        runtime (Rust): routing, identity, actions
                                    + data engine: queries, subscriptions, permissions
                          ├─ files, streams
                          │        ├─▶ PlanetScale Postgres   data, 1 primary + 2 replicas
                          │        └─▶ Amazon S3              files and stream parts
                          └─▶ your action code
                                 development: an isolated container per environment
                                 production: an immutable release on a managed runner
```

## The runtime [#the-runtime]

One Rust service serves every environment: it routes by hostname, checks the caller, runs queries and keeps subscriptions live, admits and records action executions, and stores files and streams. At the data layer it is Instant-compatible — the same query language and real-time protocol — and it adds environments, actions, executions and identity on top.

Live queries are refreshed from the database's own change log, so a write by any process — an action, a workflow, another runtime — refreshes every affected subscriber.

## Data [#data]

| What                                                                     | Where                                 | Protection                                                                                   |
| ------------------------------------------------------------------------ | ------------------------------------- | -------------------------------------------------------------------------------------------- |
| Entities, links, `$users`, `$files` records, executions, stream metadata | PlanetScale Postgres, AWS `sa-east-1` | encrypted at rest; TLS only; a primary and two replicas; automated backups                   |
| File contents and stream parts                                           | Amazon S3, `sa-east-1`                | private bucket, encrypted at rest (SSE-S3), versioned, TLS only; reached through signed URLs |
| Identity: people, organizations, keys                                    | DomainRuntime Auth                    | separate database; tokens validated on every request                                         |

Each environment is isolated inside the database by its own application id: queries, permissions and live subscriptions never cross environments.

## Your code [#your-code]

* **Development:** your action code runs in an isolated container per environment, with its own copy of the runtime, as an unprivileged user. Outbound internet is available.
* **Production:** your action code runs as an immutable build of your domain source on a managed runner in São Paulo. Workflows stay on the release they started on.

## Region [#region]

All data is stored in São Paulo (`sa-east-1`).
