The system runs as 2 services: BackendBackend The main application: it runs the API and serves the website. and ProxyProxy The front door for web traffic: it receives requests from the internet and passes each one to the right service; it runs Traefik., with the database behind them.

16 August 2026The system as it stood at the end of this day.

01How the system is built

The system runs as 2 services: BackendBackend The main application: it runs the API and serves the website. and ProxyProxy The front door for web traffic: it receives requests from the internet and passes each one to the right service; it runs Traefik., with the database behind them. People use it through the website, which talks to an APIAPI The set of requests other software, including the website, can send to the application to read or change data. of 23 operations in 5 groups. Alongside them, AdminerAdminer Adminer, a web page for browsing and editing the database directly. also runs in production as an admin tool.

In production, the system runs in 2 places, both deployed automatically: Docker ComposeDocker Compose Docker Compose, a tool that starts a set of services together on one server; here it runs the system on a server the team manages itself. (Backend and Proxy) and FastAPI CloudFastAPI Cloud A hosting service that runs FastAPI applications. (Backend). Each place needs its own settings and secrets.

Exhibit 1How the parts fit together

WebsiteDatabaseAdminerBackendProxyFastAPI CloudLet's EncryptSentryEmail provider
↔ outside serviceServices run by other companies that the system depends on, drawn with a dashed border. hover a part or an arrowEvery box and arrow explains itself: hover over it, tab to it or tap it.

Source: deployment files, CI workflows and code at commit 75b4026. An arrow points from a part to what it calls, routes to or relies on; dotted arrows exist only on engineers' machines.

02What it offers

Exhibit 2What callers can do with each part of the API, and who may

Part of the APIWhat it lets callers doWho can use it
Items APIItems API The part of the API for items: 5 operations (5 for signed-in users).delete an item; list items; view an item; create an item; update an itemsigned-in users: 5Signed-in users: delete an item; list items; view an item; create an item; update an item.
Sign-in APISign-in API The part of the API for sign-in: 5 operations (3 open to anyone, 1 for signed-in users, 1 for administrators only).sign in and get an access token; check that an access token is valid; preview the password-reset email; start a password reset by email; set a new password after a resetanyone: 3, signed-in users: 1, administrators: 1Anyone: sign in and get an access token; start a password reset by email; set a new password after a reset. Signed-in users: check that an access token is valid. Administrators: preview the password-reset email.
Internal APIInternal API The part of the API for internal use: 1 operation (1 open to anyone); some are switched on only in development.create a useranyone: 1Anyone: create a user. Switched on only in development: create a user.
Users APIUsers API The part of the API for users: 10 operations (1 open to anyone, 5 for signed-in users, 4 for administrators only).delete your own account; delete a user; list users; view your own account; view a user; update your own account; change a password; update a user; create a user; sign up for an accountanyone: 1, signed-in users: 5, administrators: 4Anyone: sign up for an account. Signed-in users: delete your own account; view your own account; view a user; update your own account; change a password. Administrators: delete a user; list users; update a user; create a user.
Utilities APIUtilities API The part of the API for utilities: 2 operations (1 open to anyone, 1 for administrators only).check that the service is running; send a test emailanyone: 1, administrators: 1Anyone: check that the service is running. Administrators: send a test email.

Source: the application's route definitions and the access checks they declare, at commit 75b4026.

03What it is built with

Exhibit 3The main technologies, and what each one is for

TechnologyWhat it isVersionSupport
PythonPython Python, the programming language the application is written in.Python, the programming language the application is written in3.14The language version the project declares, when it declares one.
TypeScriptTypeScript TypeScript, the programming language the website is written in.TypeScript, the programming language the website is written in
BunBun Bun, a tool used here to build the website.Bun, a tool used here to build the website1The version the system's container images ask for.
Python runtimePython runtime The version of Python the application runs on.the version of Python the application runs on3.14The version the system's container images ask for.
FastAPIFastAPI FastAPI, a Python framework for building web APIs.FastAPI, a Python framework for building web APIs0.141.1The version in use, as recorded in the project's list of libraries.
ReactReact React, a library for building interactive web pages.React, a library for building interactive web pages19.2.8The version in use, as recorded in the project's list of libraries.
TanStack RouterTanStack Router TanStack Router, which handles navigation between pages of the website.TanStack Router, which handles navigation between pages of the website1.170.18The version in use, as recorded in the project's list of libraries.
SQLModelSQLModel SQLModel, a library that connects the application's code to the database.SQLModel, a library that connects the application's code to the database0.0.39The version in use, as recorded in the project's list of libraries.
AlembicAlembic Alembic, a tool that applies changes to the database's structure in a safe order.Alembic, a tool that applies changes to the database's structure in a safe order1.18.5The version in use, as recorded in the project's list of libraries.
PostgreSQLPostgreSQL PostgreSQL, a widely used open-source database.PostgreSQL, a widely used open-source database18The version the system's container images ask for.
Tailwind CSSTailwind CSS Tailwind CSS, a styling toolkit for web pages.Tailwind CSS, a styling toolkit for web pages4.3.3The version in use, as recorded in the project's list of libraries.
PydanticPydantic Pydantic, a library that checks that data and settings are well-formed.Pydantic, a library that checks that data and settings are well-formed2.13.4The version in use, as recorded in the project's list of libraries.
TanStack QueryTanStack Query TanStack Query, which fetches and caches data from the API in the website.TanStack Query, which fetches and caches data from the API in the website5.101.4The version in use, as recorded in the project's list of libraries.
ViteVite Vite, a tool that packages the website's code for browsers.Vite, a tool that packages the website's code for browsers8.2.0The version in use, as recorded in the project's list of libraries.
TraefikTraefik Traefik, software that receives web traffic and passes each request to the right service.Traefik, software that receives web traffic and passes each request to the right service3.6The version the system's container images ask for.
AdminerAdminer Adminer, a web page for browsing and editing the database directly.Adminer, a web page for browsing and editing the database directly

Source: dependency manifests, lock files and container images, at commit 75b4026.

04Outside services

The system relies on 6 outside services: FastAPI CloudFastAPI Cloud A hosting service that runs FastAPI applications., GitHub ActionsGitHub Actions GitHub's service for running automated builds, tests and deployments., Let's EncryptLet's Encrypt A free service that issues the certificates websites need for secure (HTTPS) connections., SentrySentry An error-monitoring service that records crashes and errors from the live system., SmokeshowSmokeshow A service that publishes test-coverage reports from automated builds. and Email providerEmail provider The service that delivers the application's emails; which company provides it is chosen when the system is deployed.. Each is a contract, a cost and a place the system's data may go.

Exhibit 4Every outside service the system depends on

Outside serviceWhat it doesUsed by
FastAPIFastAPI FastAPI, a Python framework for building web APIs. Clouda hosting service that runs FastAPI applicationsthe build and deployment pipelineThe build and deployment pipeline: the automated steps that test the system and put new versions into use.
GitHub ActionsGitHub's service for running automated builds, tests and deploymentsthe build and deployment pipelineThe build and deployment pipeline: the automated steps that test the system and put new versions into use.
Let's Encrypta free service that issues the certificates websites need for secure (HTTPS) connectionsProxyProxy: the front door for web traffic: it receives requests from the internet and passes each one to the right service; it runs Traefik.
Sentryan error-monitoring service that records crashes and errors from the live systemBackendBackend: the main application: it runs the API and serves the website.
Smokeshowa service that publishes test-coverage reports from automated buildsthe build and deployment pipelineThe build and deployment pipeline: the automated steps that test the system and put new versions into use.
Email providerthe service that delivers the application's emails; which company provides it is chosen when the system is deployedBackend, the build and deployment pipelineBackend: the main application: it runs the API and serves the website. The build and deployment pipeline: the automated steps that test the system and put new versions into use.

Source: dependencies, configuration names, container commands and CI workflows, at commit 75b4026.

05Things to keep an eye on

06How engineers work on it

Engineers also run MailcatcherMailcatcher A helper service for developers; used only during development. and PlaywrightPlaywright Playwright, a tool that tests the website automatically by clicking through it like a user; used only during development. while developing; these are not part of the live system.

07Key terms

access token
A temporary pass the application gives a user at sign-in, so they don't send their password with every request.
Adminer
Adminer, a web page for browsing and editing the database directly.
Alembic
Alembic, a tool that applies changes to the database's structure in a safe order.
API
The set of requests other software, including the website, can send to the application to read or change data.
Backend
The main application: it runs the API and serves the website.
Bun
Bun, a tool used here to build the website.
Database
The database where the application keeps its data, running PostgreSQL 18; its data survives restarts.
Docker Compose
Docker Compose, a tool that starts a set of services together on one server; here it runs the system on a server the team manages itself.
Email provider
The service that delivers the application's emails; which company provides it is chosen when the system is deployed.
FastAPI
FastAPI, a Python framework for building web APIs.
FastAPI Cloud
A hosting service that runs FastAPI applications.
GitHub Actions
GitHub's service for running automated builds, tests and deployments.
Internal API
The part of the API for internal use: 1 operation (1 open to anyone); some are switched on only in development.
Items API
The part of the API for items: 5 operations (5 for signed-in users).
Let's Encrypt
A free service that issues the certificates websites need for secure (HTTPS) connections.
Mailcatcher
A helper service for developers; used only during development.
operation
One thing the API lets a caller do, such as signing in or listing items.
Playwright
Playwright, a tool that tests the website automatically by clicking through it like a user; used only during development.
PostgreSQL
PostgreSQL, a widely used open-source database.
Proxy
The front door for web traffic: it receives requests from the internet and passes each one to the right service; it runs Traefik.
Pydantic
Pydantic, a library that checks that data and settings are well-formed.
Python
Python, the programming language the application is written in.
Python runtime
The version of Python the application runs on.
React
React, a library for building interactive web pages.
secret
A setting that must stay private, such as a password or a key to an outside service.
Sentry
An error-monitoring service that records crashes and errors from the live system.
service
A separately running program that is part of the system.
setting
A value the application is given when it starts, such as which database to use; it differs between places the system runs.
Sign-in API
The part of the API for sign-in: 5 operations (3 open to anyone, 1 for signed-in users, 1 for administrators only).
Smokeshow
A service that publishes test-coverage reports from automated builds.
SQLModel
SQLModel, a library that connects the application's code to the database.
Tailwind CSS
Tailwind CSS, a styling toolkit for web pages.
TanStack Query
TanStack Query, which fetches and caches data from the API in the website.
TanStack Router
TanStack Router, which handles navigation between pages of the website.
Traefik
Traefik, software that receives web traffic and passes each request to the right service.
TypeScript
TypeScript, the programming language the website is written in.
Users API
The part of the API for users: 10 operations (1 open to anyone, 5 for signed-in users, 4 for administrators only).
Utilities API
The part of the API for utilities: 2 operations (1 open to anyone, 1 for administrators only).
Vite
Vite, a tool that packages the website's code for browsers.
Website
The user interface people use in a web browser.