TFD Backoffice Runtime Architecture

Modular monolith, durable data, realtime operations, and Zoom recording pipeline

TFD Backoffice Runtime Architecture Modular monolith, durable data, realtime operations, and Zoom recording pipeline TFD Staff · Backoffice users · Architecture component TFD Staff Backoffice users AWS Cognito · Hosted UI + PKCE · Architecture component · Authentication AWS Cognito Hosted UI + PKCE Authentication Backoffice Frontend · React staff application · Architecture component Backoffice Frontend React staff application Business Providers · Stripe · Outline · Slack · Airtable · Architecture component Business Providers Stripe · Outline · Slack · Airtable Backoffice API · NestJS modular monolith · Architecture component · Business source of truth Backoffice API NestJS modular monolith Business source of truth PostgreSQL · Durable application state · Architecture component PostgreSQL Durable application state Redis · Streams + desired/applied state · Architecture component · Control plane Redis Streams + desired/applied state Control plane Zoom · Webhooks + Meeting SDK · Architecture component Zoom Webhooks + Meeting SDK Meeting Recorder · Sharded media capture · Architecture component Meeting Recorder Sharded media capture Private S3 · Segments + final MP4 · Architecture component · Media plane Private S3 Segments + final MP4 Media plane Recording Finalizer · Remux + validation · Architecture component Recording Finalizer Remux + validation HTTPS PKCE JWT identity Prisma backend adapters signed webhooks validated MP4 Legend External Security Frontend Backend Database Message bus Cloud

Modular monolith

  • • Identity, VIP/CRM, Sales, Delivery, Engagement, Notifications, and Integrations remain explicit modules
  • • PostgreSQL owns durable business and audit state

Recorder control plane

  • • Redis Streams carries schema-versioned commands and events
  • • Leases, TTL renewal, and fencing tokens protect recorder ownership

Private media plane

  • • Media bytes never pass through Redis or the Backoffice API
  • • Recorder and finalizer upload directly to private S3

Trust boundaries

  • • Cognito authenticates; StaffUser and RBAC authorize backoffice access
  • • Provider credentials and meeting passwords remain backend-only